Alpha Omega logo
Alpha Omega

Creating New Possibilities

Security Manager

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 501-1,000Since 2016H1B SponsorCompany SiteLinkedIn

Location

Virginia

Posted

29 days ago

Salary

$130K - $170K / year

Seniority

Senior

Bachelor Degree3 yrs expEnglishAzureCloud

Job Description

Security Manager

Alpha Omega

• Lead end‑to‑end architecture, configuration, and deployment of Microsoft Purview solutions across Data Governance, Data Security, and Data Compliance pillars. • Facilitate requirements gathering sessions with business, legal, privacy, records, and security stakeholders to translate policy, regulatory, and operational needs into actionable Purview configurations. • Architect and implement Purview‑based controls including: Data Loss Prevention (endpoint, email, SharePoint/OneDrive, Teams, cloud apps) Sensitivity labels, labeling policies, and encryption workflows Insider Risk Management policies and analytics Information Barriers and data segregation controls Records Management, Retention/Deletion policies, File Plan mapping eDiscovery Standard/Premium workflows, holds, collections, and review sets Data Lifecycle Management and data residency enforcement. • Establish and maintain the Microsoft Purview Data Map and Data Catalog, ensuring appropriate metadata harvesting, scanning rules, classification schemas, and lineage tracking across cloud and on‑premises data sources. • Conduct data environment assessments, including ROT (redundant, obsolete, trivial) analysis, unclassified vs. controlled data assessments, and large‑scale mapping of file shares, repositories, and tenant‑wide content. • Design and maintain Data Classification frameworks using custom and out‑of‑the‑box classifiers, machine learning classifiers, and sensitive information types. • Implement governance guardrails, policy hierarchies, and compliance baselines to support federal mandates, OMB/NIST standards, agency‑specific directives, and Zero Trust requirements. • Support and lead tenant‑wide migrations, environment consolidation activities, and data cleanup initiatives, including after-hours migration windows when required. • Create technical documentation, architecture diagrams, SOPs, operational runbooks, and governance artifacts. • Monitor and respond to compliance alerts, policy violations, and security incidents, recommending remediation actions and driving issue resolution. • Partner with enterprise architecture, information security, data stewards, and M365 engineering to ensure alignment with broader data strategy and platform standards. • Provide guidance and enablement to teams across the organization, including training, knowledge transfer, and best practices for Purview adoption. • Continuously evaluate new Purview features, roadmap releases, and federal compliance requirements to optimize the agency’s data protection posture.

Job Requirements

  • Education: BA/BS in Computer Science, Engineering, Information Systems, or a related field.
  • Experience/Skills: U.S. Citizenship required by Federal client.
  • Minimum 3–5 years of hands‑on experience implementing, configuring, and operating Microsoft Purview solutions across: Data Governance: Data Map, Data Catalog, Scanning, Classification, Lineage, Data Estate Insights. Data Security: DLP (all workloads), Sensitivity Labels & Policies, Insider Risk, Information Barriers, Data Security Posture Management, Data Access Governance. Data Compliance: eDiscovery Standard/Premium, Audit, Records Management, Retention/Deletion, Data Lifecycle Management, Communication Compliance, Compliance Manager.
  • 5+ years delivering complex enterprise technology solutions including architecture design, configuration, testing, rollout, and operationalization.
  • Strong understanding of Microsoft 365, Azure AD/Entra ID, Exchange Online, SharePoint/OneDrive, Teams, and Azure data services.
  • Practical experience with enterprise metadata management, data classification design, scanning configurations, data mapping, and resolving governance/security issues across diverse data estates.
  • Ability to design reusable Purview patterns and workflows that incorporate automation, compliance guardrails, and alignment with enterprise architecture standards.
  • Proven ability to translate business, legal, and compliance requirements into technical policies and solutions.
  • Strong documentation, communication, and stakeholder engagement skills.
  • Certification(s): PL‑900 (required prior to start date). PL‑100, PL‑200, SC‑400, SC‑900, or Microsoft Copilot/Azure AI governance certifications preferred. Additional ideal certs: SC‑300 (Identity), MS‑700 (M365 Admin), AZ‑104/305 (Azure).

Benefits

  • 15 days PTO including paid parental, military, and bereavement leave
  • Eleven (11) paid Federal holidays, five of which are floating holidays (as designated by the company’s holiday schedule each year)
  • Health and Dental Insurance (including 100% employer paid premiums for employee coverage under the HDHP health plan)
  • Life Insurance, STD/LTD term disability coverage, with employer paid premiums
  • 401 (k) plan with a match that is 100% vested after you complete two years of service
  • FSA/DFSA/HSA flexible benefit plans
  • Annual Tuition & Professional Development Reimbursement benefit

Related Categories

Related Job Pages

More Security Engineer Jobs

Rapid7 logo

Senior Cybersecurity Advisor

Rapid7

At Rapid7, our vision is to create a secure digital world for our customers, our industry, and our communities. We do this by harnessing our collective expertise and passion to challenge what’s possible and drive extraordinary impact. We’re building a dynamic and collaborative workplace where new ideas are welcome. Protecting 11,000+ customers against bad actors and threats means we’re continuing to push the envelope - just like we’ve been doing for the past 20 years. If you’re ready to solve some of the toughest challenges in cybersecurity, we’re ready to help you take command of your career. Join us.

Full TimeRemoteTeam 1,001-5,000Since 2000H1B Sponsor

Senior Cybersecurity Advisor Rapid7 Cybersecurity Advisors partner with our customers above and beyond the tactical aspects of vulnerability management, application security, and threat detection and incident response. You will work with your customers to increase their resilience against threats through tailored mitigation recommendations, proactive threat awareness reporting, and regular touch-points to discuss IT security initiatives and associated best practices. About the Team Rapid7's Managed Services deliver world class, 24/7/365 threat detection, incident response, vulnerability management, and application security services for our customers. As a member of Rapid7's Cybersecurity Advisor team, you are on the front-lines helping clients defend against and respond to today's biggest threats. Our analysts and scanning operation teams keep a constant watch on our customers and provide guidance and strategies to help identify and remediate significant risks. Rapid7 Cybersecurity Advisors are fanatical about security and customer satisfaction, and are just as comfortable working in the weeds with engineers as we are briefing a CISO on a recent breach and security strategy. About the Role As a Senior Cybersecurity Advisor, you will be the key trusted advocate to our customers. Your valuable experience and in-depth understanding of the security landscape will be pivotal in shaping the customer perception of Managed Services and its exceptional service. Our Cybersecurity Advisors are responsible for leveraging their technical knowledge to guide customers in the successful usage of security product features and enhancements, and for positively impacting the overall success and maturity of customers' security programs. Specifically, your focus will be to: - Ensure that Rapid7 Platform technology is functional, and coordinate with Rapid7's Managed Services and Rapid7's Support team when needed - Work closely with Analysts and Scan Operators to convey recommendations to Rapid7 customers - Review and generate high-quality accurate and contextual customer deliverables for complex technical accounts - Acts as an expert in industry attack trends and defenses, advising clients on best practices and strategic solutions - Drive customer optimization and usage through an expert understanding of Rapid7 products - Develop and maintain strong, long-lasting advisory relationships with key stakeholders, including technical teams, project managers, and C-level executives on complex accounts - Operate as the escalation point for junior advisors, driving the revitalization of customer health and satisfaction on escalated accounts - Guide clients through findings and provide subject matter expertise for response activities - Provide expertise in technology deployment and client onboarding processes - Gather client input and requirements across the Managed Services client base to influence Managed Services service roadmap - Teach and mentor junior team members on technical concepts and service delivery best practices - Assist Managed Services Leadership with effective scaling strategies to face the challenge of an ever-expanding customer base - Anticipate potential risks and challenges in customer relationships and work proactively to address them before they escalate The skills and qualities you'll bring include: - Bachelors Degree in Information Technology, or two or more years of related experience - 5-6 years of experience in Information Security Consulting or related discipline - Industry-related certifications i.e. A+, Network+, Sec+, Cloud+, CCSP, etc. - Outstanding written and verbal skills in Japanese and English - Exceptional interpersonal and communication skills - Ability to collaborate with cross-functional teams to drive impact and positive customer outcomes - Adaptability and capability to navigate change and ambiguity - Prior technology deployment and configuration experience - Significant experience with security frameworks and concepts - Excellent project management and prioritization abilities - Significant experience in managed or enterprise information security services, vulnerability management, incident response, forensics, malware analysis, penetration testing, or network defense - Mastery of technical concepts and experience advising customers on how to best use and adopt the platform for faster Return on Investment (ROI) - Accountability for outcomes and meeting commitments that deliver value for customers - Problem-solving mentality with the ability to navigate complex situations independently - Core Value Embodiment: Embody our core values to foster a culture of excellence that drives meaningful impact and collective success. We know that the best ideas and solutions come from multi-dimensional teams. That's because these teams reflect a variety of backgrounds and professional experiences. If you are excited about this role and feel your experience can make an impact, please don't be shy - apply today. #LI-CG3 About Rapid7 At Rapid7, our vision is to create a secure digital world for our customers, our industry, and our communities. We do this by harnessing our collective expertise and passion to challenge what's possible and drive extraordinary impact. We're building a dynamic and collaborative workplace where new ideas are welcome. Protecting 11,000+ customers against bad actors and threats means we're continuing to push the envelope just like we' ve been doing for the past 20 years. If you 're ready to solve some of the toughest challenges in cybersecurity, we're ready to help you take command of your career. Join us.

Japan
Welltech logo

Staff Security Engineer

Welltech

Health & Fitness Mobile Apps Developer

Full TimeRemoteTeam 201-500Since 2017H1B No Sponsor

• Design and implement mid and long-term security strategies, aligning them with business goals and technology roadmaps to ensure robust protection of digital assets. • Identify, assess, and manage security risks, developing strategies to mitigate potential threats and vulnerabilities. • Lead the transition from managed detection and response services to an in-house capability, ensuring seamless operational change and continuity. • Establish and manage an on-call incident response protocol to ensure swift and effective response to security incidents. • Partner with the Privacy team to establish foundational data security practices and policies. • Provide hands-on expertise to achieve and maintain PCI DSS certification.

Cyprus
NavitasPartners logo

Tanium Endpoint Security Engineer

NavitasPartners

Navitas Partners, LLC is a certified WBENC and one of the fastest-growing Technical / IT staffing firms in the US providing services to numerous clients. We offer the most competitive pay for every position. We understand this is a partnership. You will not be blindsided and your salary will be discussed upfront.

Role Description We are looking for a Tanium Endpoint Security Engineer to join our team. The ideal candidate will have extensive experience designing, implementing, and managing endpoint security solutions using the Tanium platform. This role requires expertise in endpoint protection, vulnerability management, incident response, and real-time threat detection across enterprise environments. As a Tanium Endpoint Security Engineer, you will be responsible for deploying, configuring, and maintaining Tanium's security modules to ensure that endpoint security is proactive and effective. The role involves monitoring, automating, and integrating security solutions while collaborating closely with security, IT, and compliance teams to improve overall endpoint security posture. Qualifications - Hands-on Experience with Tanium: Proven experience working with Tanium’s endpoint security platform. - Endpoint Security Expertise: Strong knowledge of endpoint detection and response (EDR) tools, particularly Tanium. - Operating System Knowledge: Experience working with Windows, Linux, and macOS endpoint environments. - Vulnerability Management: Deep understanding of vulnerability management and patching processes. - Scripting Skills: Familiarity with PowerShell, Python, or Bash scripting to automate tasks and improve workflows. - SIEM Integration: Experience with integrating Tanium with SIEM platforms such as Splunk for enhanced threat visibility. - Security Frameworks: Familiarity with security frameworks and standards, such as NIST, ISO 27001, and CIS. Requirements - Endpoint Security Management: Deploy, configure, and manage Tanium modules including Threat Response, Patch, Asset, Deploy, and Comply to secure endpoints. - Incident Response & Monitoring: Monitor endpoint activity and swiftly respond to security incidents using Tanium's real-time capabilities. - Vulnerability Management: Perform vulnerability assessments, manage patches, and execute remediation tasks using Tanium Patch and Comply modules. - Security Visibility & Reporting: Develop and maintain dashboards, reports, and queries to provide security visibility and compliance status across endpoints. - SIEM Integration: Integrate Tanium with SIEM tools (such as Splunk or IBM QRadar) to enhance threat detection and security monitoring. - Automation of Endpoint Tasks: Automate endpoint management tasks including patching, software deployment, and configuration enforcement for streamlined security operations. - Collaboration with Teams: Work with SOC, IT, and Compliance teams to enhance the overall endpoint security posture across the organization. - Incident Support & Root Cause Analysis: Conduct root cause analysis during security incidents and support incident response activities to minimize threats and vulnerabilities. - Security Compliance & Audits: Ensure endpoint compliance with organizational and regulatory security policies. Provide support for audits and compliance initiatives (e.g., NIST, CIS benchmarks). Company Description For more details reach at resumes@navitassols.com

Worldwide
Job Closed
Aon Corporation logo

EMEA Information Security Officer - East region - Global Cybersecurity Services

Aon Corporation

Aon is in the business of better decisions. At Aon, we shape decisions for the better to protect and enrich the lives of people around the world. As an organization, we are united through trust as one inclusive team and we are passionate about helping our colleagues and clients succeed. Aon values an innovative and inclusive workplace where all colleagues feel empowered to be their authentic selves. Aon is proud to be an equal opportunity workplace. Aon provides equal employment opportunities to all employees and applicants for employment without regard to race, color, religion, creed, sex, sexual orientation, gender identity, national origin, age, disability, veteran, marital, domestic partner status, or other legally protected status. We are committed to providing equal employment opportunities and fostering an inclusive workplace. If you require accommodations during the application or interview process, please let us know.

Full TimeRemoteTeam 10,001

Role Description The Information Security Officer (ISO) – East region will support the Eastern part of Europe Middle East and Africa (EMEA) within the EMEA Regional Security Office (RSO). Reporting directly to the EMEA Regional Security Officer, this role is key in leading the regional and solution line operational security risk level to within acceptable levels via leading remediation programs and deployment of Global Cybersecurity Services (GCS) controls. The role will act as a key contact for all matters relating to Cybersecurity and requires a broad understanding of security controls and their effective implementation within corporate environments. As an Information Security Officer you will be accountable for service delivery to the assigned region / sub-region and solution lines. The role will need to have effective relationships with senior leadership to support the delivery of the regional / sub-regional business goals and operate an effective security risk management regime against an agreed security risk mitigation strategy. As the trusted security lead, this position requires presenting to local leaders, regulators and clients as needed. Prior experience of regulatory management is required. This is a highly visible role within Aon to be able to embed effective security controls at scale within the firm. We are looking for you to bring new insights and a dedication toward continual learning. You will stay actively engaged with business leaders, IT executives and external clients. The role requires gravitas and an ability to be influential and persuasive. Aon deeply values inclusiveness, collaboration and a "better together" approach to deliver distinctive value to colleagues and clients. Qualifications - Broad Cybersecurity knowledge and experience of implementing and operating an effective control regime in a large, complex corporate environment. - Solid knowledge and understanding of Cybersecurity domains, including: - Application security - Vulnerability management - Network and cloud security - Security operations (incident management) - Physical security - Supplier risk management - Cyber awareness - Experience of effective Cyber Risk Management within a large corporate environment. - Fostering strong partnerships by influencing and building effective relations with diverse stakeholders at a range of seniority, up to and including C-level. - Exceptional communication skills, with the ability to communicate to a diverse range and seniority of stakeholders, including technical and non-technical audiences. - Demonstrable regulatory management experience. - Experience of Compliance assurance and Audit practice is desirable. - Security certification (CISSP, CISM) is an advantage. - Understanding and experience of delivering compliance standards, including: - ISO27001 - DORA - Cyber Essentials+ Requirements - Provide Cybersecurity reporting to leadership committees and Boards. - Represent Cybersecurity to appropriate Regulatory bodies. - Own the Cybersecurity strategy for the assigned area, manage its delivery via leverage of GCS services and accelerate local control adoption. - Own the colleague security culture programme. - Represent the region / sub-region in the Security Incident Management process. - Manage remediation of Cybersecurity Audit and Compliance findings. - Manage a Cybersecurity Risk committee to support cyber risk management. - Track remediation of Cybersecurity Audit and Compliance findings. - Review Cybersecurity Metrics and lead remediation programs within the region / sub-region. - Lead or Sponsor Cybersecurity initiatives within area of accountability. - In conjunction with Data Privacy, ensure necessary security controls are in place. - Manage GCS Service delivery escalations. - Support GCS project implementation within the assigned area of accountability. - Contribute to the ‘voice of the Business’ in development of GCS service enhancements. - Represent Cybersecurity on Client calls or escalations. - Provide first line security advice, guidance and Policy and Standard support to Client teams. - Support the engagement of GCS services via the correct process. Company Description

EMEA