Microsoft Purview Engineer (Data Protection & AI Security)

Computing Concepts Inc

United States

Remote

USD 140,000 - 190,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Computing Concepts Inc seeks a hands-on Microsoft Purview Engineer to build, operate, and harden data-protection and compliance controls across a comprehensive M365 estate. You will own sensitivity labeling, DLP, retention, and eDiscovery, and drive DSPM for AI across AI copilots and LLM interactions.

You will also govern structured data, register SQL Server sources in Purview Data Map, and implement policy-as-configuration controls with audit-ready documentation for compliance.

Qualifications

  • 4+ years in security or compliance engineering, including 2+ years hands-on with Microsoft Purview (compliance and information-protection workloads).
  • Production experience with sensitivity labels, DLP policies, and retention configurations in a Microsoft 365 E5 tenant.
  • Working knowledge of the broader M365 security stack: Entra ID, Intune, Defender for Endpoint, Defender for Cloud Apps, and Exchange Online.
  • Proficiency with Security & Compliance PowerShell for scripting and automating compliance operations.
  • Solid grasp of data-classification concepts SITs, EDM schemas, and trainable classifiers and how labeling and DLP behave across M365 services.
  • Hands-on experience with the Microsoft Purview Data Map: registering and scanning SQL Server sources (including self-hosted integration runtime for on-premises), configuring scan rule sets, and classifying PII at the column level.
  • Working T-SQL proficiency able to profile tables and columns, sample data, and validate PII findings directly in SQL Server.
  • Experience with, or demonstrated readiness to operate, DSPM for AI including oversharing assessments, AI DLP policies, and AI interaction auditing.
  • Ability to independently investigate compliance incidents and produce clear, audit-ready documentation.
  • Reliable daily overlap with US Eastern business hours and strong written and verbal English for async and live collaboration with US teams.

Responsibilities

  • Design, deploy, and tune sensitivity labels, label policies, auto-labeling, and encryption across Exchange, SharePoint, OneDrive, and Teams.
  • Author and maintain DLP policies (including Endpoint DLP on Intune-managed devices), build and validate SITs, EDM schemas, and trainable classifiers, and reduce false positives through iterative tuning.
  • Implement retention labels and policies, disposition-review workflows, and records-management controls aligned to regulatory and legal-hold obligations (HIPAA, PCI-DSS, GLBA, SEC/FINRA, or equivalent).
  • Run eDiscovery (Standard & Premium), content search, and legal-hold workflows, supporting Legal and HR teams with collections, exports, and case management.
  • Configure and triage Insider Risk Management policies in partnership with HR and Legal, and manage Communication Compliance reviews for policy and regulatory requirements.
  • Deploy and operate Microsoft Purview DSPM for AI to discover and monitor how sensitive data is exposed to Microsoft 365 Copilot, Copilot Studio agents, ChatGPT, Claude, and other generative-AI applications.
  • Register and scan SQL Server sources (on-premises via self-hosted integration runtime, and Azure SQL) in the Purview Data Map; classify PII at the column level; bridge structured findings into M365 controls; maintain the data catalog, classifications, and lineage.
  • Monitor compliance alerts across the Purview portal and Microsoft Defender; automate recurring operations via Security & Compliance PowerShell and Microsoft Graph; document architecture decisions, runbooks, and change records.

Skills

Security & compliance engineering
English communication
Documentation
Policy-driven mindset

Tools

Microsoft Purview
PowerShell
T-SQL
DSPM for AI

Job description

Note : Shift Timings (6:30pm To 3:30am IST)

About the Role

Looking for a hands-on Microsoft Purview Engineer to build, operate, and continuously harden data-protection and compliance controls across a well-resourced Microsoft 365 E5 estate and structured data sources. This is a build-and-run engineering role at the intersection of traditional M365 compliance and emerging AI data security.

You will own end-to-end sensitivity labeling, DLP, retention, and eDiscovery across Microsoft 365 workloads; deploy and operate Data Security Posture Management for AI (DSPM for AI) to govern how sensitive data is exposed to Copilot, ChatGPT, Claude, and other LLMs; and drive PII discovery and classification in SQL Server through the Microsoft Purview Data Map. If you can turn a compliance requirement directly into working, policy-as-configuration controls across both unstructured and structured data, with minimal hand-holding this role is for you.

What You'll Do
Information Protection & DLP

Design, deploy, and tune sensitivity labels, label policies, auto-labeling, and encryption across Exchange, SharePoint, OneDrive, and Teams. Author and maintain DLP policies (including Endpoint DLP on Intune-managed devices), build and validate SITs, EDM schemas, and trainable classifiers, and reduce false positives through iterative tuning.

Data Lifecycle, Records & eDiscovery

Implement retention labels and policies, disposition-review workflows, and records-management controls aligned to regulatory and legal-hold obligations (HIPAA, PCI-DSS, GLBA, SEC/FINRA, or equivalent). Run eDiscovery (Standard & Premium), content search, and legal-hold workflows, supporting Legal and HR teams with collections, exports, and case management.

Insider Risk & Communication Compliance

Configure and triage Insider Risk Management policies in partnership with HR and Legal, and manage Communication Compliance reviews for policy and regulatory requirements.

DSPM for AI AI Data Security

Deploy and operate Microsoft Purview DSPM for AI to discover and monitor how sensitive data is exposed to Microsoft 365 Copilot, Copilot Studio agents, ChatGPT, Claude, and other generative-AI applications. Run oversharing and data-risk assessments, drive remediation through sensitivity labels, access reviews, and SharePoint Advanced Management, configure AI DLP and risky-interaction detection policies, and audit AI prompts and responses producing risk-posture reports for leadership.

Structured Data Discovery & Classification (SQL Server)

Register and scan SQL Server sources (on-premises via self-hosted integration runtime, and Azure SQL) in the Purview Data Map. Configure scan rule sets and schedules, classify PII at the column level, and tune built-in and custom classifiers for personal, financial, and health data. Profile and validate findings directly in SQL Server using T-SQL, bridge structured findings into M365 controls (e.g., EDM schemas that power DLP and auto-labeling), and maintain the data catalog, classifications, and lineage.

Operations, Governance & Automation

Monitor compliance alerts across the Purview portal and Microsoft Defender, maintain Compliance Manager assessments and audit evidence, automate recurring operations via Security & Compliance PowerShell and Microsoft Graph (Security API), and document architecture decisions, runbooks, and change records.

What We're Looking For
  • 4+ years in security or compliance engineering, including 2+ years hands-on with Microsoft Purview (compliance and information-protection workloads).
  • Production experience with sensitivity labels, DLP policies, and retention configurations in a Microsoft 365 E5 tenant.
  • Working knowledge of the broader M365 security stack: Entra ID, Intune, Microsoft Defender for Endpoint, Defender for Cloud Apps, and Exchange Online.
  • Proficiency with Security & Compliance PowerShell for scripting and automating compliance operations.
  • Solid grasp of data-classification concepts SITs, EDM schemas, and trainable classifiers and how labeling and DLP behave across M365 services.
  • Hands-on experience with the Microsoft Purview Data Map: registering and scanning SQL Server sources (including self-hosted integration runtime for on-premises), configuring scan rule sets, and classifying PII at the column level.
  • Working T-SQL proficiency able to profile tables and columns, sample data, and validate PII findings directly in SQL Server.
  • Experience with, or demonstrated readiness to operate, DSPM for AI including oversharing assessments, AI DLP policies, and AI interaction auditing.
  • Ability to independently investigate compliance incidents and produce clear, audit-ready documentation.
  • Reliable daily overlap with US Eastern business hours and strong written and verbal English for async and live collaboration with US teams.
Nice to Have
Technical
  • Endpoint DLP at scale and DLP for Defender for Cloud Apps (non-Microsoft SaaS coverage).
  • Microsoft 365 Copilot deployment/governance and SharePoint Advanced Management (restricted content discovery, site access reviews, restricted search).
  • Insider Risk Management and Communication Compliance configuration.
  • eDiscovery Premium workflows and legal-hold lifecycle operations.
  • Data Map scanning beyond SQL Server: Azure SQL, Azure Storage, Microsoft Fabric, Snowflake, or multicloud sources.
Domain & Compliance
  • Stronger structured-data background relational data modeling and profiling large tables for PII at scale.
  • Microsoft Graph (Security API) automation; Logic Apps or Microsoft Sentinel integration.
  • Exposure to regulated environments (HIPAA, PCI-DSS, GLBA, SEC/FINRA records retention, or equivalent).
  • Data-lineage configuration and end-to-end Purview governance reporting.
  • Experience designing or hardening Zero Trust data-access architectures in M365.
Certifications (Advantageous Not Required)
  • SC-400 - Microsoft Information Protection and Compliance Administrator
  • SC-200 - Microsoft Security Operations Analyst
  • SC-300 - Microsoft Identity and Access Administrator
  • MS-102 - Microsoft 365 Administrator
  • AZ-500 - Microsoft Azure Security Engineer Associate
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Purview & DSPM AI Data Security Engineer
Purview & DSPM AI Data Security Engineer

Computing Concepts Inc • United States

Remote
USD 140,000 - 190,000
Senior Microsoft Purview Data Security Engineer
Senior Microsoft Purview Data Security Engineer

Veriipro • Washington

On-site
USD 140,000 - 180,000
Data Loss Prevention Analyst - Purview
Data Loss Prevention Analyst - Purview

1872 Consulting • Chicago (IL)

Hybrid
USD 120,000 - 180,000
Security Engineer, Data
Security Engineer, Data

Applied Systems • Indiana (PA)

On-site
USD 120,000 - 170,000
Data Protection Analyst Microsoft Purview
Data Protection Analyst Microsoft Purview

Tata Consultancy Services • Wilmington (MA)

On-site
USD 64,000 - 95,000
DLP Engineer, Purview
DLP Engineer, Purview

Jobtailor • San Antonio (TX)

On-site
USD 100,000 - 150,000
Collaboration Administrator, Purview
Collaboration Administrator, Purview

Darling Ingredients Inc. • Irving (TX)

On-site
USD 90,000 - 130,000
Microsoft Purview and Data Protection Engineer
Microsoft Purview and Data Protection Engineer

The Carlyle Group • Washington

On-site
USD 160,000 - 180,000
Health insurance
Retirement benefits
Paid time off
Data Security Specialist
Data Security Specialist

Milbank LLP • New York (NY)

On-site
USD 140,000 - 160,000
Senior Microsoft Purview Specialist
Senior Microsoft Purview Specialist

BlueVoyant • Northern (KY)

Hybrid
USD 140,000 - 180,000
Comprehensive benefits
Flexible remote work
Professional development
+1