Data Loss Prevention Analyst - Purview
Listed on 2026-09-09
-
IT/Tech
Information Security & Data Protection, Cybersecurity
Work Model: Hybrid – 3 days onsite / 2 days remote
About the organization
A global law firm headquartered in Chicago with more than 20 offices across the US, Europe, Asia, and Australia, advising many of the world's largest companies on their most complex legal matters. Protecting client and firm information is not a back-office function here — it is a contractual obligation and a competitive differentiator, audited directly by clients. The Information Security team operates in a Microsoft-first environment with meaningful investment behind its data protection roadmap.
About the role
This is a hands-on data security and compliance engineering role centered on Microsoft Purview, sitting at the intersection of cybersecurity, data governance, privacy, records, and legal compliance. Purview is still early in its maturity here, so you will help implement and shape the platform rather than maintain someone else's build — configuring DLP, information protection, retention, and insider risk controls, then tuning them as the environment grows.
You will translate real security, legal, and compliance requirements into working technical policies, and investigate Purview alerts pointing to potential data leakage or policy violations.
What you'll do
- Design, configure, and maintain Microsoft Purview solutions for classification, labeling, retention, and compliance
- Build and tune DLP, Information Protection, Insider Risk, and eDiscovery policies and workflows
- Protect sensitive data through classification, labeling, encryption, and access governance across Microsoft 365 and Azure
- Investigate Purview alerts related to data leakage, insider risk, and policy violations, and recommend remediation
- Partner with IT, Legal, Records, Privacy, and Compliance to turn regulatory and client requirements into technical controls
- Document standards and procedures, and support audits and risk assessments
What you need
- Bachelor's degree in Computer Science, Information Security, Information Governance, or a related field
- 5+ years in security engineering, compliance engineering, or data governance
- Hands-on Microsoft Purview experience — policies and controls you personally configured, implemented, tuned, and troubleshot
- Strong Microsoft 365 depth, including its security and compliance tooling
- Solid grounding in data governance principles and regulatory frameworks such as GDPR, CCPA, HIPAA, and ISO 27001
- Ability to translate legal, compliance, and data-handling requirements into technical policy
Nice to have
- SC-400, SC-401, AZ-500, SC-200, CISSP, CISM, or Security+
- Experience in legal, financial services, insurance, healthcare, or another highly regulated environment
- Exposure to Varonis, BigID, Digital Guardian, or Cyberhaven
- Large-scale legal hold, records management, or eDiscovery experience
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).