Information Security Engineer - Hybrid in NYC
REQUIRED CANDIDATE QUALIFICATIONS:
- 5+ years of experience in information security, with direct focus on data protection, insider risk, or identity governance;
- Hands-on experience with one or more DLP and data classification platforms (e.g., Microsoft Purview, Symantec, Forcepoint, Netskope, etc.);
- Experience managing identity and access governance solutions (e.g., Microsoft Entra ID Governance, SailPoint, Saviynt, Okta IGA);
- Strong understanding of data classification schemes, sensitive data types, and data handling controls;
- Experience investigating security alerts and incidents involving user behavior and data misuse;
- Familiarity with endpoint, cloud, and SaaS security architectures;
- Strong documentation, communication, and cross-functional collaboration skills; and
- Ability to work additional hours as needed.
PREFERRED / NICE-TO-HAVE QUALIFICATIONS:
- Experience with Microsoft security ecosystem (Purview, Defender for Endpoint, Defender for Cloud Apps, Entra ID, Sentinel);
- Experience with User and Entity Behavior Analytics (UEBA) or insider risk platforms;
- Knowledge of privacy-by-design principles and employee monitoring considerations;
- Security certifications such as CISSP, CISM, CCSP, GIAC, or vendor-specific certifications;
- Bachelor's degree in Information Security, Computer Science, Information Technology, or a related technical field.