Genesis10 ยท 3 weeks ago
MS E5 Data Protection Engineer
Genesis10 is seeking an MS E5 Data Protection Engineer to design, build, and operationalize enterprise-grade data protection capabilities anchored in Microsoft E5. This role will lead engineering efforts for Microsoft Purview and support a high-impact initiative focused on Insider Risk detection and data protection for regulated data.
Information ServicesInformation Technology
Responsibilities
Engineer Secure-by-Default E5 Data Protection
Design and implement Microsoft Purview DLP policies across endpoints, Exchange, SharePoint, OneDrive, and Teams
Define and manage Sensitivity Label taxonomy with automated enforcement paths
Build policy-as-code CI/CD pipelines to version, test, and deploy DLP rules, label configurations, and governance artifacts across environments
Integrate Security Tooling (Zscaler, CrowdStrike, Splunk)
Integrate Zscaler SSE inspection with Purview controls and route telemetry to Splunk for analytics and detections
Leverage CrowdStrike telemetry (Falcon/Shield) to correlate endpoint behavior with data movement signals for insider risk and exfiltration use cases
Develop Splunk dashboards, data models, and correlation searches aligned to data loss and anomalous access scenarios
Build Automation & Guardrails
Develop automation using Azure Functions, Logic Apps, Graph API, and PowerShell to remediate mislabels, revoke risky shares, and notify data owners
Implement secure-by-default configuration baselines and drift detection for E5 security controls, including MCAS/Defender for Cloud Apps and Conditional Access
Own reliability for data protection pipelines, including SLIs/SLOs, runbooks, and incident response playbooks
Partner with Privacy and Compliance teams to ensure audit-ready controls for eDiscovery, Audit, and exception management
Continuously improve insider risk detection and response workflows
Collaborate Across Security & Platform Teams
Work closely with IAM, Insider Risk, and Platform Security teams to align enforcement with business workflows and least-privilege access
Provide technical leadership and mentorship to engineers and analysts supporting Microsoft E5 tools and controls
Qualification
Required
3-5 years of engineering experience in enterprise security or platform engineering
Hands-on experience with Microsoft E5 security stack, including Purview DLP, Information Protection, and eDiscovery/Audit
Proven expertise in policy-as-code approaches using GitHub or Azure DevOps
Strong experience automating administration via Microsoft Graph API and PowerShell
Demonstrated ability to design secure-by-default guardrails while enabling rapid SaaS and AI adoption, including Microsoft Copilot
Preferred
Experience protecting regulated data (PII/PHI) and supporting insider risk investigations
Production experience with Zscaler (SSE/ZIA/ZPA), CrowdStrike (Falcon APIs/telemetry), and Splunk (CIM, ES)
Experience migrating from legacy DLP platforms (e.g., Forcepoint) to Microsoft Purview
Familiarity with MCAS/Defender for Cloud Apps, Conditional Access policies, and SSPM evaluations
Experience supporting HIPAA/PHI audits and exception governance workflows
Benefits
Behavioral Health Platform
Medical, Dental, Vision
Health Savings Account
Voluntary Hospital Indemnity (Critical Illness & Accident)
Voluntary Term Life Insurance
401K
Sick Pay (for applicable states/municipalities)
Commuter Benefits (Dallas, NYC, SF)
Remote opportunities available
Company
Genesis10
Information Technology and Services
H1B Sponsorship
Genesis10 has a track record of offering H1B sponsorships. Please note that this does not
guarantee sponsorship for this specific role. Below presents additional info for your
reference. (Data Powered by US Department of Labor)
Distribution of Different Job Fields Receiving Sponsorship
Represents job field similar to this job
Trends of Total Sponsorships
2025 (126)
2024 (68)
2023 (20)
2022 (2)
2021 (13)
2020 (29)
Funding
Current Stage
Late StageCompany data provided by crunchbase