Systems Security Engineer
Listed on 2026-07-08
-
IT/Tech
Cybersecurity, Information Security, Data Security, IT Consultant
Systems Security Engineer
Location:
Lake Forest, Illinois
Posted:
July 2, 2026
Description:
Built on service. Powered by people. Impact was founded to correct the imbalance between margins and the people doing the work. Our focus on people-first values drives growth and service excellence. Employees grow alongside the business, helping shape our future.
Job OverviewImpact seeks a Systems Security Engineer to own governance of systems and data for security. The role focuses on the Microsoft security and compliance ecosystem, including Microsoft Purview, Microsoft Entra , and Microsoft Defender, to discover, classify, protect, and govern Impact’s most critical information across a hybrid environment. The engineer translates security, regulatory, and contractual requirements into enforceable technical controls and measures success through incidents avoided, audits passed, and risk reduced.
Responsibilities- Design, implement, and manage a comprehensive governance strategy across Impact’s environment using Microsoft Purview governance and compliance tools.
- Develop and enforce governance policies to discover, classify, and protect sensitive data and systems across Microsoft 365, Azure, on-premises infrastructure, and SaaS applications.
- Manage sensitivity labels, retention labels, records management, and disposition review to support the full information lifecycle.
- Create, tune, and monitor Data Loss Prevention policies across endpoints, email, Microsoft Teams, SharePoint, One Drive, and cloud applications.
- Govern identity and access using Microsoft Entra , aligning policies to Zero Trust architecture and least-privilege principles.
- Serve as a subject-matter expert for data- and system-related security incidents using Microsoft Purview and Microsoft Defender for investigation, forensics, and response.
- Participate in the security team’s on-call rotation and respond to critical incidents outside of regular business hours when needed.
- Configure Microsoft Purview Audit, audit-log retention, export pipelines, Azure Monitor, Log Analytics, KQL workbooks, and alert rules to monitor compliance and policy drift.
- Translate regulatory and contractual requirements, including CMMC, NIST 800-171, ISO 27001, HIPAA, GDPR, and CCPA, into technical policies and controls in partnership with compliance, legal, and business stakeholders.
- Manage Microsoft Compliance Manager assessments and improvement-action plans, and provide regular reporting on compliance, risk posture, and policy enforcement to leadership.
- Maintain technical documentation, architecture standards, and operational runbooks for governance and security controls.
- Coach and mentor IT and security team members on governance, data protection, and Microsoft security best practices.
- Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent work experience.
- Minimum of 5 years of experience in information security, including at least 3 years focused on data protection, data governance, or information lifecycle management.
- Deep hands‑on experience with the Microsoft Purview suite, including DLP, Microsoft Information Protection, data classification, Insider Risk Management, eDiscovery, Audit, and Compliance Manager.
- Strong experience with Microsoft Entra the Microsoft Azure ecosystem, including securing data within Azure services such as Azure Storage and Azure SQL.
- Proficiency with scripting languages, particularly Power Shell, for automating security and compliance tasks.
- Strong understanding of data privacy regulations and compliance frameworks, including NIST 800-171, CMMC, ISO 27001, HIPAA, GDPR, and CCPA.
- Excellent analytical, problem-solving, communication, and collaboration skills, including the ability to explain complex technical concepts to technical and non-technical audiences.
- Microsoft SC-400 certification strongly preferred; AZ-500, SC-200, SC-300, MS-102, CISSP, CCSP, or CCSK are a plus.
- Experience with Microsoft Defender for Microsoft 365, Zero Trust security architecture, Microsoft Purview Data Security Posture Management, AI/Copilot data governance, or MSP/multi‑tenant environments preferred.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).