Information Protection Engineer

DeWinter Group

Boston (MA)

Hybrid

USD 120,000 - 180,000

Full time

42 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

DeWinter Investment Management Partner in Boston, MA is seeking an experienced Information Protection Engineer to design, implement, and govern enterprise data-protection capabilities with a focus on DLP and data classification, particularly within the Microsoft Purview ecosystem.

You will work with Information Security, Technology, Legal and Compliance to identify sensitive information, classify and protect it appropriately, and implement controls that reduce data risk without disrupting

Qualifications

  • 5+ years of experience in information security, information protection, data security, or related discipline.
  • Hands-on experience implementing, administering, and improving enterprise DLP and information-protection technologies.
  • Strong hands-on experience with Microsoft Purview DLP, Information Protection, sensitivity labels, and data-classification capabilities.
  • Experience designing or implementing enterprise data-classification and sensitivity-labeling strategies, including approaches for applying classification to existing content at scale.
  • Experience with Microsoft 365 security and compliance capabilities across Exchange, SharePoint, OneDrive, Teams, and endpoints.

Responsibilities

  • Design, administer, maintain, and enhance DLP policies and information-protection controls across supported platforms and data channels.
  • Configure, test, tune, and optimize DLP policies to improve detection and protection while reducing false positives and unnecessary business disruption.
  • Design, implement, and maintain Microsoft Purview sensitivity labels, information-classification policies, and associated protection controls.
  • Partner with business units, data owners, Legal/Compliance, and Information Security to identify sensitive information and determine classification and protection requirements.
  • Develop and implement approaches to discover, classify, and label sensitive content at scale using automated labeling, sensitive information types, trainable classifiers, and other techniques.

Skills

DLP
Information protection
Data classification
Microsoft Purview
Security engineering

Tools

PowerShell

Job description

This role is with a DeWinter Investment Management Partner

Boston, MA - Hybrid Role - We are targeting local candidates that can be in the Boston office 3 days per week.

12 Month + contract (or contract to hire, if desired)

Position Overview We are seeking an experienced Information Protection Engineer – DLP & Data Classification to support and enhance enterprise data-protection capabilities within a leading financial services organization.

This is a hands‑on engineering role focused on the design, implementation, administration, and continuous improvement of enterprise information‑protection capabilities, including data discovery and classification, sensitivity labeling, Data Loss Prevention (DLP), monitoring, and automated protection of sensitive information. The role will have a particular emphasis on the Microsoft Purview ecosystem.

The individual will work closely with Information Security, Technology, Legal and Compliance, and business stakeholders to identify sensitive information, classify and protect it appropriately, and implement controls that effectively reduce data risk without unnecessarily disrupting legitimate business activity.

Key Responsibilities

  • Design, administer, maintain, and enhance Data Loss Prevention (DLP) policies and information-protection controls across supported platforms and data channels.
  • Configure, test, tune, and optimize DLP policies to improve detection and protection while reducing false positives and unnecessary business disruption.
  • Design, implement, and maintain Microsoft Purview sensitivity labels, information‑classification policies, and associated protection controls.
  • Partner directly with business units, data owners, Legal/Compliance, and Information Security to identify sensitive information, understand how it is created, stored, shared, and used, and determine appropriate classification and protection requirements.
  • Develop and implement approaches to discover, classify, and label sensitive content at scale, leveraging automated and recommended labeling, sensitive information types, trainable classifiers, Exact Data Match, and other appropriate technologies and techniques.
  • Assess existing repositories and data sets to identify unlabeled, mislabeled, or inadequately protected sensitive information and work with business owners to remediate identified gaps.
  • Develop practical processes and guidance that enable business users and data owners to appropriately classify and protect information, including exception and escalation processes.
  • Integrate classification and sensitivity labels with DLP, encryption, access controls, endpoint controls, and other information-protection capabilities to provide appropriate protection based on the sensitivity of the information.
  • Investigate DLP alerts and events, determine appropriate disposition and escalation, and partner with Information Security, Compliance, Legal, and business stakeholders when additional investigation is required.
  • Analyze DLP and classification activity to identify control gaps, emerging risks, recurring behaviors, and opportunities to improve data-protection controls.
  • Develop metrics and reporting to measure classification and labeling coverage, DLP effectiveness, policy adoption, exceptions, and other information-protection trends.
  • Identify opportunities to use automation and AI-assisted capabilities to improve data discovery, classification, labeling, DLP monitoring, investigation, and response.
  • Partner with GRC and Compliance teams to provide technical expertise, evidence, metrics, and control documentation for audits, client due diligence, risk assessments, and regulatory requirements.

Qualifications

  • 5+ years of relevant experience in information security, information protection, data security, DLP, security engineering, or a related discipline.
  • Demonstrated hands‑on experience implementing, administering, and improving enterprise DLP and information-protection technologies.
  • Strong hands‑on experience with Microsoft Purview DLP, Information Protection, sensitivity labels, and data-classification capabilities is highly preferred.
  • Experience designing or implementing enterprise data-classification and sensitivity-labeling strategies, including approaches for applying classification to existing content at scale.
  • Experience with Microsoft 365 security and compliance capabilities across Exchange, SharePoint, OneDrive, Teams, and endpoints.
  • Strong understanding of data classification, sensitivity labeling, data handling, encryption, access controls, and information-protection concepts.
  • Experience investigating DLP alerts and working across security, compliance, legal, and business teams to assess potential data‑loss events.
  • Ability to analyze existing DLP and information-protection configurations and make practical recommendations to improve coverage, effectiveness, and usability.
  • Strong troubleshooting, analytical, documentation, and communication skills.
  • Ability to work independently, engage directly with business stakeholders, and drive technical and operational improvements with limited oversight.
  • Experience within financial services, asset management, or another regulated industry is preferred.

Preferred Qualifications

  • Experience with broader Microsoft Purview capabilities, including Data Explorer, Content Explorer, Insider Risk Management, or related functionality.
  • Experience developing custom sensitive information types, classifiers, or other methods for identifying organization-specific sensitive content.
  • Experience with Microsoft Defender for Endpoint and its integration with DLP and information-protection controls.
  • PowerShell or other scripting and automation experience.
  • Experience developing dashboards, metrics, and reporting for enterprise information-protection programs.
  • Familiarity with protecting data across cloud platforms, SaaS applications, and non‑Microsoft environments.
  • Relevant Microsoft security certifications or certifications such as CISSP, CISM, Security+, or similar credentials.

Candidate Profile We are looking for a hands‑on engineer who can move comfortably between technology and the business. The successful consultant should be able to review an existing information-protection environment, understand how controls are actually configured, identify gaps, implement and tune policies, troubleshoot issues, and drive improvements.

Just as importantly, this individual must be able to work directly with business teams to understand what information is sensitive and why, then translate those requirements into scalable classification, labeling, and protection controls.

The goal is not simply to deploy more DLP rules or require employees to manually label every document. The successful engineer will help establish a scalable, risk-based approach to discovering, classifying, labeling, and protecting sensitive information, using automation wherever practical while balancing strong information protection with business usability.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Microsoft Purview and Data Protection Engineer
Microsoft Purview and Data Protection Engineer

1P284 THE CARLYLE GROUP EMPLOYEE CO., LLC • Washington

Hybrid
USD 160,000 - 180,000
Microsoft Purview and Data Protection Engineer
Microsoft Purview and Data Protection Engineer

The Carlyle Group • Washington

On-site
USD 160,000 - 180,000
Health insurance
Retirement benefits
Paid time off
Senior DLP Analytic Rule Developer
Senior DLP Analytic Rule Developer

Peterson Technology Partners • Irving (TX)

On-site
Senior Information Security Engineer - Data Protection & Insider Risk
Senior Information Security Engineer - Data Protection & Insider Risk

Cravath, Swaine & Moore LLP • New York (NY)

Hybrid
USD 160,000 - 200,000
Medical, dental, vision insurance
401(k) plan with company match
Paid time off and health club benefits
+1
Data Protection Leader
Data Protection Leader

Collective Insights Careers • Atlanta (GA)

On-site
USD 140,000 - 200,000
Data Security Analyst
Data Security Analyst

clarivate • Kansas City (MO)

Hybrid
USD 105,000 - 145,000
Data Protection & Microsoft Purview Engineer
Data Protection & Microsoft Purview Engineer

6AM City, LLC • Minnesota

On-site
USD 120,000 - 150,000
Tech Risk - Associate - DLP Engineering - Dallas
Tech Risk - Associate - DLP Engineering - Dallas

Goldman Sachs • Dallas (TX)

On-site
USD 130,000 - 185,000
Data Protection Engineer
Data Protection Engineer

First Student • United States

Hybrid
USD 140,000 - 190,000
Data Loss Prevention -DLP Analyst
Data Loss Prevention -DLP Analyst

Compunnel, Inc. • Quincy (MA)

On-site
USD 90,000 - 115,000