Data Loss Protection (DLP) Specialist
$140,000–$160,000 year
On-siteNew York City, New York, United States
Job Summary
Design and operate data loss prevention policies across email, endpoints, and cloud services using Microsoft Purview, M365, and Azure. Implement data classification, labeling, and encryption frameworks aligned with regulatory requirements like GDPR, CCPA, and NYDFS Part 500. Investigate data security incidents, perform root-cause analysis, and lead containment efforts while partnering with SOC and forensics teams. Develop automation scripts in PowerShell, Python, and KQL to scale operations and integrate controls into CI/CD workflows. Monitor SIEM and CASB alerts for AI-related exposure events, including prompt injection and unauthorized LLM usage.
Required Qualifications
- Bachelor's degree in computer science, Information Security, or related field (equivalent experience accepted)
- 4+ years in information security with at least 2 years focused on data protection, DLP, or data governance
- In-depth, hands-on experience with a range of enterprise DLP and rights management platforms, with deep expertise in the Microsoft M365 stack — including Microsoft Purview DLP (Exchange Online, SharePoint, OneDrive, Teams, and Endpoint DLP), Microsoft Purview Information Protection (MIP) sensitivity labels, Azure Information Protection (AIP), Azure Rights Management Services (Azure RMS), Double Key Encryption (DKE), and Customer Key
- Experience tuning policies, authoring custom sensitive information types (SITs), trainable classifiers, and integrating Purview with Defender for Cloud Apps (MCAS)
- Experience with Microsoft Purview Insider Risk Management, Communication Compliance, eDiscovery (Premium), and Data Lifecycle Management
- Demonstrated experience with AI data leakage prevention — protecting sensitive data from exposure to generative AI and LLM services. This includes hands-on work with Microsoft Purview controls for Microsoft 365 Copilot (DSPM for AI / AI Hub, Copilot interaction auditing, sensitivity-label enforcement on Copilot responses), CASB/SSE-based GenAI app discovery and blocking (Defender for Cloud Apps, Netskope, Zscaler), prompt and response inspection, and policies preventing the upload or pastin...
- Working knowledge of third-party DLP/IRM tools (e.g., Symantec/Broadcom DLP, Forcepoint, Netskope, Zscaler, Digital Guardian) and how they complement or integrate with M365 controls
- Hands-on experience with at least one major cloud (Azure, AWS, or GCP)
- Working knowledge of encryption standards, PKI, IAM, and Zero Trust principles
- Familiarity with regulatory frameworks: GDPR, CCPA, HIPAA, NYDFS, SOC 2, ISO 27001
- Strong analytical, written, and verbal communication skills
Desired Qualifications
- Industry certifications: SC-400 (Microsoft Information Protection Administrator), CISSP, CIPP, CCSP, AZ-500, or GIAC equivalents
- Experience in a law firm, financial services, or other highly regulated environment
- Scripting/automation proficiency (PowerShell — including Exchange Online, Compliance Center, and Graph PowerShell modules — Python, KQL)
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.