Job Title: Senior Data Security Engineer – Microsoft Purview
Location: Washington, DC (On-site)
Employment Type: Contract (W2 through ZipStaff — No C2C or 1099)
About the Opportunity:
ZipStaff is seeking a Senior Data Security Engineer with deep Microsoft Purview expertise to support a high-visibility enterprise security program at a major national passenger transportation organization.
This is a hands-on technical lead role. You will design, deploy, and govern data protection, compliance, and AI governance controls across Microsoft 365, Azure, endpoints, and multi-cloud environments. You will partner with Security Operations, Legal, Privacy, and executive risk stakeholders to turn regulatory requirements into scalable technical controls and protect sensitive data — including Microsoft 365 Copilot and other AI workloads — in a highly regulated environment.
What You’ll Do:
- Design, implement, administer, and optimize enterprise Microsoft Purview, including architecture standards, governance models, and operational health checks.
- Serve as the hands-on SME for Purview DLP, Information Protection, Sensitivity Labels, Insider Risk Management, Records Management, DSPM, eDiscovery, Audit, and Compliance Manager.
- Lead data-protection controls for Microsoft 365 Copilot and AI workloads across Exchange, SharePoint, Teams, endpoints, and multi-cloud.
- Map GDPR, NIST, ISO 27001, and related mandates into operational security controls with Legal, Privacy, Compliance, and Cloud Engineering.
- Automate Purview administration with PowerShell and integrate with Microsoft Defender XDR and Microsoft Sentinel.
- Deliver security-posture reporting and dashboards in Power BI.
- Support structured change control, deployment methodology, and operational governance.
Required Qualifications:
- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or equivalent practical experience.
- 5+ years of information security engineering experience.
- 3+ years of hands-on Microsoft Purview implementation and administration (not awareness-only).
- Proven deployment of Purview DLP, Sensitivity Labels, Sensitive Information Types (SITs), Exact Data Match (EDM), Trainable Classifiers, and Insider Risk controls.
- Hands-on experience with Microsoft Defender for Endpoint and Microsoft Intune.
- Strong PowerShell for administration and automation.
- Experience operating in compliance-driven environments with structured change control (GDPR, NIST, ISO 27001).
- Strong analytical, troubleshooting, and stakeholder skills.
- Ability to work on-site in Washington, DC.
- Must be legally authorized to work in the United States without sponsorship now or in the future.
Preferred Qualifications:
- Microsoft Purview Data Map, DSPM, and enterprise data scanning.
- Direct experience securing Microsoft 365 Copilot and AI-enabled workloads.
- Integration across Microsoft Sentinel, Defender XDR, and Power BI.
- Familiarity with Zero Trust and additional frameworks (HIPAA, PCI-DSS, SOX, CCPA).
About ZipStaff:
ZipStaff partners with leading organizations to connect skilled technology and security professionals with high-impact contract opportunities. We focus on quality matches, clear communication, and long-term success for candidates and clients.
To apply, submit your resume highlighting hands-on Microsoft Purview, DLP, Sensitivity Labels, and enterprise data-protection work.