Responsibilities
- Design and deploy enterprise-level Data Rights Management (DRM) systems aligned with the Department of Defense Zero Trust Data Pillar.
- Build and maintain data-centric security measures that safeguard classified information across devices, locations, and user roles.
- Configure encryption, data labeling, classification, access controls, and persistent protection mechanisms for organizational data assets.
- Deploy and manage Microsoft Purview Information Protection, Data Loss Prevention (DLP), Information Governance, Insider Risk Management, and Defender for Cloud Apps.
- Establish and maintain enterprise-wide data classification frameworks, sensitivity labels, protection templates, and automated labeling rules.
- Integrate DRM systems with Identity, Credential, and Access Management (ICAM) platforms to enable attribute- and role-based access enforcement.
- Work with Zero Trust architecture teams to implement policy decision and enforcement points, enabling continuous authorization for data access.
- Create data protection strategies applicable to cloud, on-premises, and hybrid infrastructure environments.
- Enforce data loss prevention policies across email systems, endpoints, cloud applications, collaboration tools, and removable storage devices.
- Enable secure data sharing and collaboration using Microsoft 365, SharePoint Online, Teams, Exchange Online, OneDrive, and Azure platforms.
- Analyze organizational data movement patterns and propose security controls that reduce risk without disrupting operations.
- Conduct technical evaluations, security assessments, and gap analyses on DRM and data protection technologies.
- Produce engineering documentation such as system designs, implementation plans, standard operating procedures, technical reports, and architecture diagrams.
- Support cybersecurity compliance efforts, including Authority to Operate (ATO) and Risk Management Framework (RMF) processes.
- Engage in architecture reviews, security engineering forums, technical meetings, and Zero Trust planning initiatives.
- Provide technical mentorship to junior engineers and lead initiatives within the Data Security team.
Work Arrangement
Hybrid
Other
- Active Top Secret/SCI security clearance is required.
- Candidate must be eligible to retain access to USSOCOM systems and facilities.
- An active DoD 8140 baseline certification (e.g., Security+ CE, CySA+, CASP+, CISSP, or equivalent) is required prior to start date.