Security Engineer, Data

Applied Systems

Indiana (PA)

On-site

USD 120,000 - 170,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Applied Systems is seeking an Infrastructure Security Engineer to own and optimize data protection and endpoint security within the Microsoft security stack. You will deploy Purview data governance, DLP, and CASB capabilities across Microsoft 365, shaping data classification and breach prevention.

The role emphasizes collaboration with cross-functional teams, incident response, and regulatory compliance automation. Expect high-impact initiatives and on-call rotation in a fast-moving environment.

Qualifications

  • 3+ years in security engineering or data security with hands-on work with Microsoft security products.
  • Experience designing and implementing Microsoft Purview solutions for data governance and compliance.
  • Hands-on with modern DLP solutions and policy tuning across email, Teams, and endpoints.
  • Strong knowledge of data classification and sensitivity labeling in Microsoft 365 environments.
  • Experience with CASB technologies for SaaS visibility and control.
  • Familiarity with audit logging, threat intel integration, and advanced hunting in Defender platforms.

Responsibilities

  • Design, implement, and maintain security controls across the Defender suite and data protection platforms.
  • Deploy Microsoft Purview solutions including data classification, DLP, and records management.
  • Manage Purview Compliance Manager and audit logging for regulatory compliance.
  • Design and maintain data security controls including DLP, encryption, and labeling strategies.
  • Conduct security reviews and threat modeling of data flows and governance models.
  • Optimize CASB capabilities for SaaS security and visibility.
  • Develop runbooks for data breach procedures and incident response.
  • Contribute to security monitoring, alerting, and threat hunting across platforms.
  • Assist with POC builds for Defender and Purview capabilities.
  • Participate in on-call rotation with the Security Engineering Team.

Skills

Security engineering
Data security
DLP
Threat modeling
Incident response
Microsoft Defender
Microsoft Purview
CASB
PowerShell
Python
Encryption
Audit logging
Communication

Education

Bachelor's degree in CS/IS or related field

Tools

Microsoft Defender
Microsoft Purview
Azure AD
Terraform
ARM templates
Bicep
PowerShell

Job description

Infrastructure Security Engineer

Applied Systems is seeking an Infrastructure Security Engineer with deep expertise in the Microsoft Defender and Purview security ecosystems to design and operate our data protection and endpoint security infrastructure. You'll own the deployment and optimization of Microsoft Purview data governance and DLP, and Cloud App Security (CASB) capabilities across our Microsoft 365 environment. This role is perfect for an engineer who specializes in data security and has built real expertise with Microsoft's modern security stack; you'll work on high‑impact initiatives around data classification, breach prevention, compliance automation, and endpoint threat response. You'll have the autonomy to own specific security domains while collaborating with cross‑functional teams and incident response.

Responsibilities
  • Design, implement, and maintain security controls across the Microsoft Defender suite and data protection platforms
  • Design and deploy Microsoft Purview solutions including data classification, labeling, DLP, information barriers, and records management
  • Implement and manage Microsoft Purview Compliance Manager and audit logging for regulatory compliance
  • Design and maintain data security controls including Data Loss Prevention (DLP), encryption, and classification strategies
  • Conduct security reviews and threat modeling of data flows and information governance models
  • Implement and optimize Microsoft Cloud App Security (CASB) capabilities for SaaS application security and visibility
  • Develop and maintain runbooks for data breach procedures and incident response involving Defender and Purview solutions
  • Contribute to security monitoring, detection tuning, and alerting across Defender and Purview platforms
  • Assist with proof‑of‑concept builds for new Microsoft Defender and Purview capabilities
  • Participate in the Security Engineering Team on‑call rotation
Requirements
  • Minimum of 3 years' experience in security engineering or data security, with hands‑on work with Microsoft security products
  • Advanced hands‑on experience with modern DLP solutions
  • Demonstrated experience designing and implementing Microsoft Purview solutions for data governance and compliance
  • Working knowledge of Data Loss Prevention (DLP) design, policy creation, and tuning across email, Teams, and endpoints
  • Strong understanding of data classification and sensitivity labeling strategies in Microsoft 365 environments
  • Experience with Microsoft Cloud App Security (CASB) or equivalent CASB technologies for SaaS visibility and control
  • Advanced knowledge of Windows and/or macOS operating systems, particularly regarding Defender for Endpoint agent deployment and management
  • Experience with one or more scripting languages (PowerShell, Python, Bash, C#)
  • Knowledge of encryption technologies and key management in Microsoft 365 context
  • Understanding of audit logging, threat intelligence integration, and advanced hunting in Defender platforms
  • Knowledge of compliance frameworks and their application in cloud environments (SOC 2, HIPAA, GDPR, PCI‑DSS)
  • Demonstrated ability to work with systems at scale
  • Excellent written and verbal communication skills
  • Strong problem‑solving abilities and attention to detail
Preferred Qualifications
  • Hands‑on experience with Microsoft Purview Compliance Manager and regulatory compliance automation
  • Working knowledge of Microsoft Entra ID (formerly Azure AD) integration with Defender and Purview solutions
  • Familiarity with Azure infrastructure (Azure Firewall, Network Security Groups, etc.)
  • Experience with infrastructure‑as‑code technologies (Terraform, ARM templates, Bicep)
  • Microsoft security certifications (Security Engineer, Enterprise Administrator, or similar)
  • Experience with SIEM/SOAR integration with Microsoft Defender solutions
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Data Security Engineer: Microsoft Defender & Purview
Data Security Engineer: Microsoft Defender & Purview

Applied Systems • Indiana (PA)

On-site
USD 120,000 - 170,000
Microsoft Purview Engineer
Microsoft Purview Engineer

Ampcus Inc • Richmond (VA)

On-site
USD 90,000 - 120,000
Data Protection Consultant – Purview, DLP & AI Security
Data Protection Consultant – Purview, DLP & AI Security

Jobtailor • United States

On-site
USD 150,000 - 190,000
Data Security Principal Architect
Data Security Principal Architect

Compunnel, Inc. • Cumberland (RI)

On-site
USD 120,000 - 160,000
Data Security Analyst
Data Security Analyst

Clarivate • Philadelphia

Hybrid
USD 90,000 - 120,000
IT Security Operations & Engineering Specialist
IT Security Operations & Engineering Specialist

Tata Consultancy Services • New York (NY)

On-site
USD 100,000 - 120,000
Discretionary Annual Incentive
Medical Coverage
Dental & Vision Coverage
+6
Microsoft Defender & Purview Security Engineer
Microsoft Defender & Purview Security Engineer

EY • Town of Greece (NY)

Hybrid
USD 140,000 - 190,000
Education platforms
EY Badges & Degrees
Certifications support
+4
Security Engineer I
Security Engineer I

Jobtailor • United States

On-site
USD 85,000 - 130,000
Data Security Specialist
Data Security Specialist

Milbank LLP • New York (NY)

On-site
USD 140,000 - 160,000
Security Engineer
Security Engineer

Carex Consulting Group • Madison (WI)

On-site
USD 90,000 - 120,000