The Data Security Specialist is responsible for protecting the confidentiality, integrity, and availability of the firm’s data assets across cloud and on-premises environments. This role designs, implements, and maintains controls that safeguard sensitive client, legal, and corporate information against unauthorized access, loss, and exfiltration — including emerging risks from generative AI and large language model (LLM) usage.
Responsibilities
Data Protection & Governance
Design and operate data loss prevention (DLP) policies across email, endpoints, and cloud services (Microsoft Purview, M365, Azure).
Implement and tune data classification, labeling, and encryption frameworks aligned with firm policy and regulatory requirements.
Manage rights management (IRM/MIP), tokenization, and key management solutions.
Design and enforce AI data leakage prevention controls — governing how sensitive data is used with Microsoft 365 Copilot, ChatGPT Enterprise, and other GenAI/LLM tools — including prompt and response monitoring, sensitivity-label enforcement, and blocking unsanctioned AI services.
Monitoring & Incident Response
Investigate data security incidents, perform root-cause analysis, lead containment and remediation.
Monitor SIEM, CASB, and DLP alerts; triage events and escalate per the incident response plan.
Partner with the SOC and forensics teams on insider threat and exfiltration investigations.
Detect and respond to AI-related data exposure events, including sensitive data submitted to public LLMs, prompt injection, and shadow AI usage.
Risk & Compliance
Support compliance with GDPR, CCPA, NYDFS Part 500, SOC 2, and client security obligations.
Conduct data risk assessments for new applications, vendors, and AI/LLM use cases.
Maintain evidence and artifacts for internal and external audits.
Contribute to the firm’s AI governance program, aligning controls with frameworks such as NIST AI RMF and ISO/IEC 42001.
Engineering & Automation
Develop scripts and automations (PowerShell, Python, KQL) to scale data security operations.
Integrate data security controls into CI/CD, SaaS onboarding, and identity workflows.
Maintain documentation, runbooks, and control mappings.
Compensation: -The anticipated base salary range offered for this role will be between $140,000 to 160,000 and represents the firm’s good faith and reasonable estimate of the range of possible base compensation. Actual base compensation will be dependent upon several factors, including but not limited to the candidate’s relevant experience, performance, qualifications, degrees, and location, well as the needs of the firm.