- Position: Security & Compliance / Information Governance Specialist
- Experience: 5+ Years
- Role: Managed IT Services / Infrastructure Support
- Employment Type: Full-time
- Location: Remote
Position Overview We are seeking an experienced Security & Compliance / Information Governance Specialist with 5+ years of experience in information security, Microsoft 365 security, compliance, and information governance.
The candidate will be responsible for designing, implementing, administering, and continuously improving Microsoft Purview capabilities covering Data Loss Prevention (DLP), Sensitivity Labels, Retention & Records Management, Archiving, eDiscovery, Insider Risk Management, and Audit.
The role requires a strong understanding of data protection principles, information lifecycle management, regulatory compliance, and Microsoft 365 security controls. The successful candidate will work closely with IT, Cybersecurity, Legal, HR, Risk, and business stakeholders to ensure that organizational data is appropriately classified, protected, retained, monitored, and disposed of in accordance with business and regulatory requirements.
Key Responsibilities
1. Microsoft Purview Administration
- Administer and manage Microsoft Purview compliance and information governance capabilities across the Microsoft 365 workplace.
- Design and implement governance policies based on business, security, legal, and regulatory requirements.
- Configure compliance controls and continuously monitor their effectiveness.
- Maintain Purview configurations, policies, alerts, reports, and supporting documentation.
- Troubleshoot policy and compliance-related issues and coordinate with Microsoft support where required.
2. Data Loss Prevention (DLP)
- Design, configure, and manage Microsoft Purview DLP policies for Exchange Online, SharePoint, OneDrive, Teams, endpoints, and other supported workloads.
- Define sensitive information types, conditions, exceptions, actions, and policy enforcement levels.
- Monitor DLP alerts and investigate potential data leakage or policy violations.
- Fine-tune policies to minimize false positives while maintaining appropriate data protection.
- Support endpoint DLP implementation and monitoring.
- Prepare DLP compliance reports and recommend improvements.
3. Sensitivity Labels & Information Protection
- Implement and manage Microsoft Purview Sensitivity Labels and label policies.
- Define data classification models aligned with organizational information-security requirements.
- Configure appropriate protection, encryption, access, and usage restrictions.
- Support automatic and recommended labeling where applicable.
- Monitor adoption and effectiveness of sensitivity-label policies.
- Work with business and data owners to define appropriate classification levels.
4. Retention, Records Management & Archiving
- Design and administer retention policies and retention labels across Microsoft 365.
- Implement records-management processes for business-critical and regulated information.
- Define retention and disposition requirements in collaboration with Legal, Compliance, and business stakeholders.
- Configure and manage archival policies in accordance with organizational requirements.
- Support information lifecycle management from creation through retention and secure disposition.
- Maintain appropriate documentation and evidence for audits.
5. eDiscovery & Legal Compliance
- Support Microsoft Purview eDiscovery activities for legal, regulatory, and internal investigations.
- Configure searches, collections, holds, review sets, and exports as required.
- Work with Legal and Compliance teams on data preservation and discovery requirements.
- Ensure appropriate handling and confidentiality of investigation-related information.
- Maintain processes and documentation for repeatable eDiscovery activities.
6. Insider Risk Management
- Configure and administer Microsoft Purview Insider Risk Management policies.
- Monitor alerts and risk indicators associated with potential data leakage or inappropriate data activity.
- Support investigation and escalation of insider-risk cases in coordination with authorized stakeholders.
- Maintain appropriate controls for privacy, access, case management, and investigation confidentiality.
- Recommend policy improvements based on observed risk patterns.
7. Audit & Compliance Monitoring
- Configure and manage Microsoft Purview Audit capabilities.
- Conduct audit searches to support security investigations, compliance reviews, and internal audits.
- Analyze user and administrative activities across Microsoft 365.
- Maintain audit evidence and generate reports for relevant stakeholders.
- Support internal, external, and regulatory audits by providing appropriate evidence and documentation.
8. Compliance & Governance
- Translate regulatory, contractual, and business requirements into practical Microsoft 365 security and compliance controls.
- Support compliance with applicable data protection, privacy, information-security, and records-management requirements.
- Conduct periodic reviews of compliance policies and configurations.
- Identify control gaps and recommend remediation measures.
- Maintain governance standards, operating procedures, and technical documentation.
9. Stakeholder & Cross-Functional Collaboration
- Work closely with Cybersecurity, IT Infrastructure, Microsoft 365, Legal, HR, Risk, Privacy, and business teams .
- Engage with data owners and application owners to understand information classification and retention requirements.
- Provide guidance and awareness to users regarding data protection and information governance.
- Participate in security and compliance projects, migrations, and technology initiatives.
Required Technical Skills
Microsoft Purview
Strong hands-on experience with:
- Microsoft Purview Data Loss Prevention
- Sensitivity Labels and Microsoft Information Protection
- Retention Policies and Retention Labels
- Records Management
- Information Lifecycle Management
- eDiscovery
- Insider Risk Management
- Microsoft Purview Audit
- Compliance Portal / Microsoft Purview portal
- Sensitive Information Types
- Data Classification
- Endpoint DLP
Microsoft 365
Good understanding of
- Exchange Online
- SharePoint Online
- OneDrive for Business
- Microsoft Teams
- Microsoft Entra ID
- Microsoft Defender ecosystem
- Microsoft 365 security and compliance architecture
Experience & Competencies
- 5+ years of experience in information security, compliance, information governance, Microsoft 365 security, or a related discipline.
- Strong hands-on experience administering Microsoft Purview in enterprise environments.
- Experience designing and implementing security and compliance policies.
- Good understanding of data classification and information lifecycle management.
- Experience investigating security/compliance alerts and policy violations.
- Ability to interpret business and regulatory requirements and convert them into technical controls.
- Strong analytical and problem-solving skills.
- Excellent documentation and communication skills.
- Ability to work independently as well as collaborate with cross-functional teams.
Certifications Preferred:
- Microsoft Certified: Information Security Administrator Associate (SC-401)
- SC-400: Microsoft Information Protection Administrator – legacy certification/experience is an advantage.
Additional security, compliance, privacy, or Microsoft certifications will be considered an advantage. Key Deliverables The successful candidate will be expected to contribute to:
- Effective implementation and administration of Microsoft Purview.
- DLP policy deployment and continuous optimization.
- Enterprise data classification and sensitivity-label adoption.
- Retention and records-management implementation.
- eDiscovery and investigation support.
- Insider Risk Management monitoring and case support.
- Audit readiness and compliance reporting.
- Reduction of data leakage and information-governance risks.
- Continuous improvement of Microsoft 365 security and compliance posture.
Key Performance Indicators
- DLP policy effectiveness and reduction of false positives.
- Sensitivity-label and classification adoption.
- Compliance with retention and records-management requirements.
- Timely response to compliance and insider-risk alerts.
- eDiscovery request turnaround and accuracy.
- Audit readiness and closure of identified compliance gaps.
- Quality and completeness of governance documentation.
- Continuous improvement of Microsoft 365 compliance controls.
Ideal Candidate Profile The ideal candidate is a hands-on Microsoft Purview specialist who combines technical expertise with a strong understanding of security, compliance, data governance, and risk management . The candidate should be capable of independently managing Purview implementations, troubleshooting complex policy issues, supporting investigations, and working with business and compliance stakeholders to establish effective information-governance practices. Interested candidates may send their resume to
[email protected].
📌 Security & Compliance / Information Governance Specialist (India)
🏢 RoboQuess Infotech Private
📍 India