Senior Information Security Engineer - Data Protection & Insider Risk

Cravath, Swaine & Moore LLP

New York (NY)

Hybrid

USD 160,000 - 200,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, dental, vision insurance
401(k) plan with company match
Paid time off and health club benefits
Hybrid work schedule

Job summary

Cravath, Swaine & Moore LLP in New York is seeking an experienced Senior Information Security Engineer focused on data leakage prevention, insider risk, and identity governance. The role covers securing endpoints, cloud, and SaaS while implementing robust controls and data labeling frameworks.

The candidate will lead AI security for Copilot in M365, collaborate with IT and Compliance, and drive governance, risk management, and security metrics.

Qualifications

  • 7+ years in information security focusing on data protection, insider risk, or identity governance.
  • Hands-on experience with one or more DLP and data classification platforms.
  • Experience with identity governance solutions (e.g., Entra ID Governance, SailPoint, Saviynt, Okta IGA).
  • Knowledge of Microsoft security ecosystem (Purview, Defender, Entra ID, Sentinel).
  • Understanding of data classification schemes and data handling controls.
  • Experience investigating security alerts involving user behavior and data misuse.
  • Familiarity with endpoint, cloud, and SaaS security architectures.
  • Strong documentation, communication, and cross-functional collaboration skills.

Responsibilities

  • Design, implement, and operate DLP controls across endpoints, email, cloud, and SaaS.
  • Lead data identification, classification, and labeling strategies for structured and unstructured data.
  • Monitor, investigate, and respond to data exfiltration and misuse events.
  • Tune detection policies to reduce false positives while maintaining risk coverage.
  • Operate insider risk detection and response programs with analytics.
  • Partner with IT/IS on insider risk investigations with governance and privacy controls.
  • Manage IAG platforms with access reviews, entitlement management, and lifecycle automation.
  • Support least-privilege access models, RBAC, and SoD initiatives.
  • Integrate identity signals with data protection and insider risk tooling.
  • Evaluate and onboard new security tools; maintain runbooks, dashboards, and metrics.
  • Support regulatory requirements (SOX, HIPAA, GDPR, CCPA).
  • Provide guidance on secure data handling and security awareness.
  • Implement AI/Generative AI security controls for Copilot with Purview/ Defender/ Entra ID.

Skills

Data protection
Insider risk
Identity governance
DLP
Data classification
Cross-functional collaboration
Documentation
Communication
Security incident investigation
Endpoint/cloud security

Education

Bachelor's degree in Information Security/related field

Tools

Microsoft Purview
Symantec
Forcepoint
Netskope
Microsoft Entra ID Governance
SailPoint
Saviynt
Okta IGA
Defender for Endpoint
Sentinel

Job description

OVERVIEW

We are seeking an experienced, dynamic Senior Information Security Engineer with expertise in data leakage prevention (DLP), insider risk management, and identity and access governance (IAG). This role is responsible for protecting sensitive data across endpoints, cloud services, and SaaS platforms by designing, implementing, and operating security controls that identify, classify, monitor, and govern access to enterprise data.

This position also plays a hands‑on role in securing Microsoft Copilot for M365 and other emerging AI‑enabled tools, focusing on technical controls, data protection enforcement, and security logging. The ideal candidate has experience managing data classification and labeling programs, insider risk detection, identity governance platforms, and modern security tooling, and is comfortable working across IT, security, and compliance functions to enable the business securely.

RESPONSIBILITIES

Data Protection & Leakage Prevention

  • Designs, implements, and operates Data Loss/Leakage Prevention (DLP) controls across endpoints, email, cloud services, and SaaS platforms;
  • Leads and maintains data identification, classification, and labeling strategies for structured and unstructured data;
  • Monitors, investigates, and responds to data exfiltration and misuse events, including both accidental and malicious activity;
  • Tunes detection policies to reduce false positives while maintaining effective risk coverage.

Insider Risk Management

  • Operates and enhances insider risk detection and response programs, including behavioral analytics and user activity monitoring;
  • Partners with IT/IS management on insider risk investigations, ensuring appropriate governance and privacy controls;
  • Develops workflows for escalation, evidence handling, and remediation of insider risk incidents.

Identity & Access Governance

  • Manages and optimizes identity and access governance (IAG) platforms, including access reviews, entitlement management, and lifecycle automation;
  • Supports least‑privilege access models, role‑based access control (RBAC), and segregation of duties (SoD) initiatives;
  • Integrates identity signals with data protection and insider risk tooling to enable contextual, risk‑based controls.

Security Tooling & Operations

  • Serves as a subject matter expert for security platforms related to DLP, insider risk, data classification, and identity governance;
  • Evaluates, onboards, and operationalizes new security tools and features;
  • Creates and maintains runbooks, procedures, dashboards, and metrics to demonstrate program effectiveness.

Governance, Risk, and Collaboration

  • Supports regulatory and compliance requirements related to data protection and access control (e.g., SOX, HIPAA, GDPR, CCPA, etc., as applicable);
  • Provides guidance to IT and business teams on secure data handling and access practices;
  • Contributes to security awareness efforts related to data handling, insider risk, and acceptable use.

AI & Generative AI Security (Technical Controls & Monitoring)

  • Implements and operates security controls for Microsoft Copilot for M365 using Purview, Defender, and Entra ID to enforce access boundaries and reduce data exposure;
  • Configures DLP, sensitivity labels, permissions, logging, and alerting to ensure AI‑assisted access aligns with data classification and authorization models;
  • Investigates and responds to data exposure or misuse involving Copilot or other AI‑enabled workflows, and support secure onboarding of additional AI/LLM tools; and
  • Performs additional duties as assigned.
QUALIFICATIONS

REQUIRED CANDIDATE QUALIFICATIONS:

  • At least 7+ years of experience in information security, with direct focus on data protection, insider risk, or identity governance;
  • Hands‑on experience with one or more DLP and data classification platforms (e.g., Microsoft Purview, Symantec, Forcepoint, Netskope, etc.);
  • Experience managing identity and access governance solutions (e.g., Microsoft Entra ID Governance, SailPoint, Saviynt, Okta IGA);
  • Working knowledge of Microsoft security ecosystem (Purview, Defender for Endpoint, Defender for Cloud Apps, Entra ID, Sentinel);
  • Strong understanding of data classification schemes, sensitive data types, and data handling controls;
  • Experience investigating security alerts and incidents involving user behavior and data misuse;
  • Familiarity with endpoint, cloud, and SaaS security architectures;
  • Strong documentation, communication, and cross‑functional collaboration skills; and
  • Ability to work additional hours as needed.

PREFERRED / NICE-TO-HAVE QUALIFICATIONS:

  • Experience with User and Entity Behavior Analytics (UEBA) or insider risk platforms;
  • Knowledge of privacy‑by‑design principles and employee monitoring considerations;
  • Scripting or automation experience (PowerShell, Python, KQL, etc.);
  • Security certifications such as CISSP, CISM, CCSP, GIAC, or vendor‑specific certifications;
  • Bachelor’s degree in Information Security, Computer Science, Information Technology, or a related technical field.

This position is located in our New York office, and currently has a hybrid work schedule, but that is subject to change. The estimated salary range for this position is $160,000 to $200,000. The actual salary offered will be based on a wide range of factors, including relevant skills, training, experience, education, and where applicable, licensure or certification obtained. Market and Firm factors are also considered. In addition to base salary and discretionary bonus(es), we offer a generous employee benefits package including, but not limited to, paid time off, medical, dental, vision care, 401(k) and substantial health club discounts.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Data Security Specialist
Data Security Specialist

Milbank LLP • New York (NY)

On-site
USD 140,000 - 160,000
Sr Data Protection & Governance Analyst
Sr Data Protection & Governance Analyst

Starkey Hearing Technologies • Eden Prairie (MN)

On-site
USD 86,000 - 117,000
Bonus eligible
Comprehensive benefits
Paid time off
Microsoft Purview and Data Protection Engineer
Microsoft Purview and Data Protection Engineer

The Carlyle Group • Washington

On-site
USD 160,000 - 180,000
Health insurance
Retirement benefits
Paid time off
Sr Data Protection & Governance Analyst
Sr Data Protection & Governance Analyst

Starkey Laboratories • Eden Prairie (MN)

On-site
USD 86,000 - 117,000
Medical Insurance
Dental & Vision Insurance
401(k) Matching
+4
DLP Engineer
DLP Engineer

First-Horizon-Bank • Memphis (TN)

On-site
USD 90,000 - 120,000
Microsoft Purview and Data Protection Engineer
Microsoft Purview and Data Protection Engineer

1P284 THE CARLYLE GROUP EMPLOYEE CO., LLC • Washington

Hybrid
USD 160,000 - 180,000
Sr Data Protection & Governance Analyst
Sr Data Protection & Governance Analyst

Starkey Hearing • Eden Prairie (MN)

On-site
USD 86,000 - 117,000
Medical insurance
Dental and vision insurance
401(k) with company match
+2
Information Protection Engineer
Information Protection Engineer

DeWinter Group • Boston (MA)

Hybrid
USD 120,000 - 180,000
Data Security Analyst
Data Security Analyst

Clarivate • Philadelphia

Hybrid
USD 90,000 - 120,000
Cybersecurity Administrator, Data Loss Prevention
Cybersecurity Administrator, Data Loss Prevention

CHAOS Industries • Washington

On-site
USD 110,000 - 190,000
Health benefits including medical, dental, and vision
401(k) with company match
Unlimited PTO
+1