Data Security Specialist

DBI Staffing

New York (NY)

On-site

USD 130,000 - 180,000

Full time

45 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

DBI Staffing seeks a Data Security Specialist to protect data across cloud and on-prem environments, designing and maintaining controls for sensitive client, legal, and corporate information. You will work with Microsoft Purview, M365, Azure, and GenAI tools to prevent data leakage and ensure regulatory compliance.

You will lead DLP, classification, and encryption programs, monitor security alerts, and collaborate with SOC/forensics on incidents, audits, and AI governance initiatives.

Qualifications

  • Bachelor’s degree in computer science, information security, or related field.
  • 4+ years in information security with focus on data protection, DLP, or governance.
  • Hands-on experience with Microsoft Purview stack and enterprise DLP tools.

Responsibilities

  • Design and operate DLP policies across email, endpoints, and cloud.
  • Implement classification, labeling, and encryption aligned with policy.
  • Manage IRM, tokenization, and key management solutions.
  • Develop AI data leakage prevention controls for GenAI tools.
  • Investigate incidents and lead containment and remediation.
  • Monitor SIEM, CASB, and DLP alerts per incident plan.
  • Collaborate with SOC/forensics on insider threat investigations.
  • Align controls with GDPR, NYDFS, SOC 2, and audits.
  • Create scripts to scale data security operations.

Skills

Data security
DLP
AI data leakage prevention
Microsoft Purview stack
SIEM / CASB experience

Education

Bachelor’s degree in CS or InfoSec

Tools

Microsoft Purview DLP
Microsoft Purview Information Protection
Azure Information Protection
Defender for Cloud Apps
Netskope
Zscaler

Job description

The Data Security Specialist is responsible for protecting the confidentiality, integrity, and availability of the firm’s data assets across cloud and on-premises environments. This role designs, implements, and maintains controls that safeguard sensitive client, legal, and corporate information against unauthorized access, loss, and exfiltration — including emerging risks from generative AI and large language model (LLM) usage.

Responsibilities
Data Protection & Governance
  • Design and operate data loss prevention (DLP) policies across email, endpoints, and cloud services (Microsoft Purview, M365, Azure).
  • Implement and tune data classification, labeling, and encryption frameworks aligned with firm policy and regulatory requirements.
  • Manage rights management (IRM/MIP), tokenization, and key management solutions.
  • Design and enforce AI data leakage prevention controls — governing how sensitive data is used with Microsoft 365 Copilot, ChatGPT Enterprise, and other GenAI/LLM tools — including prompt and response monitoring, sensitivity-label enforcement, and blocking unsanctioned AI services.
  • Investigate data security incidents, perform root-cause analysis, lead containment and remediation.
  • Monitor SIEM, CASB, and DLP alerts; triage events and elevate per the incident response plan.
  • Partner with the SOC and forensics teams on insider threat and exfiltration investigations.
  • Detect and respond to AI-related data exposure events, including sensitive data submitted to public LLMs, prompt injection, and shadow AI usage.
  • Support compliance with GDPR, CCPA, NYDFS Part 500, SOC 2, and client security obligations.
  • Conduct data risk assessments for new applications, vendors, and AI/LLM use cases.
  • Maintain evidence and artifacts for internal and external audits.
  • Contribute to the firm’s AI governance program, aligning controls with frameworks such as NIST AI RMF and ISO/IEC 42001.
  • Develop scripts and automations (PowerShell, Python, KQL) to scale data security operations.
  • Integrate data security controls into CI/CD, SaaS onboarding, and identity workflows.
  • Maintain documentation, runbooks, and control mappings.
Qualifications
  • Bachelor’s degree in computer science, Information Security, or related field (equivalent experience accepted).
  • 4+ years in information security with at least 2 years focused on data protection, DLP, or data governance.
  • In-depth, hands‑on experience with a range of enterprise DLP and rights management platforms, with deep expertise in the Microsoft M365 stack — including Microsoft Purview DLP (Exchange Online, SharePoint, OneDrive, Teams, and Endpoint DLP), Microsoft Purview Information Protection (MIP) sensitivity labels, Azure Information Protection (AIP), Azure Rights Management Services (Azure RMS), Double Key Encryption (DKE), and Customer Key. Experience tuning policies, authoring custom sensitive information types (SITs), trainable classifiers, and integrating Purview with Defender for Cloud Apps (MCAS) is required.
  • Experience with Microsoft Purview Insider Risk Management, Communication Compliance, eDiscovery (Premium), and Data Lifecycle Management.
  • Demonstrated experience with AI data leakage prevention — protecting sensitive data from exposure to generative AI and LLM services. This includes hands‑on work with Microsoft Purview controls for Microsoft 365 Copilot (DSPM for AI / AI Hub, Copilot interaction auditing, sensitivity-label enforcement on Copilot responses), CASB/SSE‑based GenAI app discovery and blocking (Defender for Cloud Apps, Netskope, Zscaler), prompt and response inspection, and policies preventing the upload or pasting of sensitive content into public AI tools (ChatGPT, Gemini, Claude, etc.).
  • Working knowledge of third‑party DLP/IRM tools (e.g., Symantec/Broadcom DLP, Forcepoint, Netskope, Zscaler, Digital Guardian) and how they complement or integrate with M365 controls.
  • Hands‑on experience with at least one major cloud (Azure, AWS, or GCP).
  • Working knowledge of encryption standards, PKI, IAM, and Zero Trust principles.
  • Familiarity with regulatory frameworks: GDPR, CCPA, HIPAA, NYDFS, SOC 2, ISO 27001.
  • Strong analytical, written, and verbal communication skills.
Preferred Qualifications
  • Industry certifications: SC‑400 (Microsoft Information Protection Administrator), CISSP, CIPP, CCSP, AZ‑500, or GIAC equivalents.
  • Experience in a law firm, financial services, or other highly regulated environment.
  • Scripting/automation proficiency (PowerShell — including Exchange Online, Compliance Center, and Graph PowerShell modules — Python, KQL).
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Data Security Specialist
Data Security Specialist

Milbank LLP • New York (NY)

On-site
USD 140,000 - 160,000
Data Security Principal Architect
Data Security Principal Architect

Compunnel, Inc. • Cumberland (RI)

On-site
USD 120,000 - 160,000
DLP Engineer
DLP Engineer

First Horizon Bank • Memphis (TN)

On-site
USD 90,000 - 120,000
Data Security Architect: AI & DLP Defender
Data Security Architect: AI & DLP Defender

DBI Staffing • New York (NY)

On-site
USD 130,000 - 180,000
AI Security Specialist
AI Security Specialist

Milbank LLP • New York (NY)

On-site
USD 140,000 - 180,000
Microsoft Purview Engineer (Data Protection & AI Security)
Microsoft Purview Engineer (Data Protection & AI Security)

Computing Concepts Inc • United States

Remote
USD 140,000 - 190,000
Security Engineer, Data
Security Engineer, Data

Applied Systems • Indiana (PA)

On-site
USD 120,000 - 170,000
Lead AI and Data Security Engineer
Lead AI and Data Security Engineer

East West Bank • San Marino (CA)

On-site
USD 160,000 - 220,000
Data Protection Analyst Microsoft Purview
Data Protection Analyst Microsoft Purview

Tata Consultancy Services • Wilmington (MA)

On-site
USD 64,000 - 95,000
AI Security & AI Governance Specialist (Microsoft Solutions) 77/hr - Hybrid
AI Security & AI Governance Specialist (Microsoft Solutions) 77/hr - Hybrid

ContractStaffingRecruiters.com • Greenville (SC)

On-site
USD 80,000 - 110,000