24 Aug
|
kanerika software
|
Hyderabad
24 Aug
kanerika software
Hyderabad
Role & responsibilities :-
What You'll Do
Information Protection
- Design, deploy, and tune sensitivity labels, label policies, and auto-labeling (client- and service-side) across Exchange, SharePoint, OneDrive, and Teams.
- Configure encryption, content marking, and access controls; troubleshoot labeling and decryption issues end to end.
Data Loss Prevention (DLP)
- Author and maintain DLP policies across Exchange, SharePoint/OneDrive, Teams, and Endpoint DLP (Intune-managed devices).
- Build and validate sensitive information types (SITs), exact data match (EDM), and trainable classifiers; reduce false positives through iterative tuning.
Data Lifecycle &
- Records Management
- Implement retention labels and policies, disposition review, and records management for regulatory and legal-hold requirements.
eDiscovery &
- Investigations
- Run eDiscovery (Standard and Premium), content search, and legal hold; support legal and HR on collections and exports.
Insider Risk &
- Communication Compliance
- Configure and triage Insider Risk Management policies and Communication Compliance reviews in partnership with HR and Legal.
Data Security Posture Management for AI (DSPM for AI)
- Deploy and operate Purview DSPM for AI to discover and monitor how sensitive data is exposed to Microsoft 365 Copilot, Copilot Studio agents, and third-party generative-AI apps.
- Run oversharing and data-risk assessments; identify SharePoint/OneDrive content over-accessible to Copilot and drive remediation (sensitivity labels, access reviews, SharePoint Advanced Management).
- Configure one-click and custom AI policies (DLP for Copilot, risky-AI-interaction detection); audit AI prompts and responses via Activity Explorer and Communication Compliance.
Structured Data Discovery &
- Classification (SQL Server)
- Register and scan SQL Server sources (on-prem via self-hosted integration runtime, and Azure SQL) in the Microsoft Purview Data Map; configure scan rule sets and schedules.
- Run classification scans to discover PII in structured data; tune built-in and custom classifiers (regex/dictionary) to accurately flag personal, financial, and health data at the column level.
- Profile and validate findings directly in SQL Server with T-SQL sampling columns, confirming true/false positives, and producing remediation and data-owner assignment lists.
- Bridge structured findings to M365 controls e.g., extract sensitive value sets from SQL Server to build Exact Data Match (EDM) schemas that power DLP and labeling.
- Maintain the data catalog, classifications, and lineage; surface PII posture into Data Security Posture Management (DSPM) views.
Operations &
- Governance
- Monitor alerts in the Purview portal and Microsoft Defender; investigate and remediate policy violations.
- Maintain Compliance Manager assessments and evidence; support audits.
- Automate recurring tasks via Security &
- Compliance PowerShell and Microsoft Graph.
- Document architecture, runbooks, and change records; participate in change management for production policy changes.
Preferred candidate profile :-
- 4+ years in security/compliance engineering, with 2+ years hands-on Microsoft Purview (compliance/information protection workloads).
- Demonstrated experience with sensitivity labels, DLP, and retention in a production M365 E5 tenant.
- Working knowledge of the broader M365 security stack: Entra ID, Intune, Microsoft Defender (Endpoint / Cloud Apps), and Exchange Online.
- Proficiency with Security &
- Compliance PowerShell; comfort scripting and automating policy operations.
- Solid grasp of data classification concepts (SITs, EDM, trainable classifiers) and how labeling/DLP behave across M365 services.
- Hands-on with the Microsoft Purview Data Map for structured sources — registering and scanning SQL Server (including self-hosted integration runtime for on-prem), scan rule sets, and classification of PII at the column level.
- Working SQL / T-SQL proficiency — able to profile tables and columns, sample data, and validate PII classification findings directly in SQL Server.
- Experience with, or demonstrable readiness to operate, DSPM for AI / Copilot data-security oversight (oversharing assessments, AI DLP, AI interaction auditing).
- Ability to investigate incidents independently and write explicit documentation.
- Reliable overlap with US business hours and strong written/verbal English for async and live collaboration with US teams.
Preferred Qualifications
- Endpoint DLP at scale and DLP for Defender for Cloud Apps (non-Microsoft SaaS).
- Microsoft 365 Copilot deployment/governance and SharePoint Advanced Management (restricted content discovery, site access reviews, restricted search).
- Insider Risk Management and Communication Compliance configuration.
- eDiscovery Premium workflows and legal-hold operations.
- Data Map scanning beyond SQL Server (Azure SQL, Azure Storage, Fabric, Snowflake, or other multicloud sources) and data lineage.
- Stronger data background — relational data modeling, profiling large tables for PII, and reasoning about classification accuracy at scale.
- Microsoft Graph (Security API) automation
- Logic Apps or Sentinel integration.
- Exposure to regulated environments (e.g., HIPAA, PCI-DSS, GLBA, or SEC/FINRA records requirements).
Certifications (a plus, not required)
- SC-400: Information Protection and Compliance Administrator
- SC-200: Security Operations Analyst
- SC-300: Identity and Access Administrator
- MS-102 / AZ-500 also valued
📌 Microsoft Purview Engineer (Hyderabad)
🏢 kanerika software
📍 Hyderabad