| Applied Systems is seeking an Infrastructure Security Engineer with deep expertise in the Microsoft Defender and Purview security ecosystems to design and operate our data protection and endpoint security infrastructure. You'll own the deployment and optimization of Microsoft Purview data governance and DLP, and Cloud App Security (CASB) capabilities across our Microsoft 365 environment. This role is perfect for an engineer who specializes in data security and has built real expertise with Microsoft's modern security stack, you'll work on high-impact initiatives around data classification, breach prevention, compliance automation, and endpoint threat response. You'll have the autonomy to own specific security domains while collaborating with cross-functional teams and incident response. Responsibilities Design, implement, and maintain security controls across the Microsoft Defender suite and data protection platforms Design and deploy Microsoft Purview solutions including data classification, labeling, DLP, information barriers, and records management Implement and manage Microsoft Purview Compliance Manager and audit logging for regulatory compliance Design and maintain data security controls including Data Loss Prevention (DLP), encryption, and classification strategies Conduct security reviews and threat modeling of data flows and information governance models Implement and optimize Microsoft Cloud App Security (CASB) capabilities for SaaS application security and visibility Develop and maintain runbooks for data breach procedures and incident response involving Defender and Purview solutions Contribute to security monitoring, detection tuning, and alerting across Defender and Purview platforms Assist with proof-of-concept builds for new Microsoft Defender and Purview capabilities Participate in the Security Engineering Team on-call rotation Requirements Minimum of 3 years' experience in security engineering or data security, with hands-on work with Microsoft security products Advanced hands-on experience with modern DLP solutions Demonstrated experience designing and implementing Microsoft Purview solutions for data governance and compliance Working knowledge of Data Loss Prevention (DLP) design, policy creation, and tuning across email, Teams, and endpoints Strong understanding of data classification and sensitivity labeling strategies in Microsoft 365 environments Experience with Microsoft Cloud App Security (CASB) or equivalent CASB technologies for SaaS visibility and control Advanced knowledge of Windows and/or macOS operating systems, particularly regarding Defender for Endpoint agent deployment and management Experience with one or more scripting languages (PowerShell, Python, Bash, C#) Knowledge of encryption technologies and key management in Microsoft 365 context Understanding of audit logging, threat intelligence integration, and advanced hunting in Defender platforms Knowledge of compliance frameworks and their application in cloud environments (SOC 2, HIPAA, GDPR, PCI-DSS) Demonstrated ability to work with systems at scale Excellent written and verbal communication skills Strong problem-solving abilities and attention to detail Preferred Qualifications Hands-on experience with Microsoft Purview Compliance Manager and regulatory compliance automation Working knowledge of Microsoft Entra ID (formerly Azure AD) integration with Defender and Purview solutions Familiarity with Azure infrastructure (Azure Firewall, Network Security Groups, etc.) Experience with infrastructure-as-code technologies (Terraform, ARM templates, Bicep) Microsoft security certifications (Security Engineer, Enterprise Administrator, or similar) Experience with SIEM/SOAR integration with Microsoft Defender solutions |
Software Powered by ICIMS
www.icims.com