Required Qualifications
- 4+ years in security/compliance engineering, with 2+ years hands-on Microsoft Purview (compliance/information protection workloads).
- Demonstrated experience with sensitivity labels, DLP, and retention in a production M365 E5 tenant.
- Working knowledge of the broader M365 security stack: Entra ID, Intune, Microsoft Defender (Endpoint / Cloud Apps), and Exchange Online.
- Proficiency with Security & Compliance PowerShell; comfort scripting and automating policy operations.
- Solid grasp of data classification concepts (SITs, EDM, trainable classifiers) and how labeling/DLP behave across M365 services.
- Hands-on with the Microsoft Purview Data Map for structured sources — registering and scanning SQL Server (including self-hosted integration runtime for on-prem), scan rule sets, and classification of PII at the column level.
- Working SQL / T-SQL proficiency — able to profile tables and columns, sample data, and validate PII classification findings directly in SQL Server.
- Experience with, or demonstrable readiness to operate, DSPM for AI / Copilot data-security oversight (oversharing assessments, AI DLP, AI interaction auditing).
- Ability to investigate incidents independently and write clear documentation.
- Reliable overlap with US business hours and strong written/verbal English for async and live collaboration with US teams.
Preferred Qualifications
- Endpoint DLP at scale and DLP for Defender for Cloud Apps (non-Microsoft SaaS).
- Microsoft 365 Copilot deployment/governance and SharePoint Advanced Management (restricted content discovery, site access reviews, restricted search).
- Insider Risk Management and Communication Compliance configuration.
- eDiscovery Premium workflows and legal-hold operations.
- Data Map scanning beyond SQL Server (Azure SQL, Azure Storage, Fabric, Snowflake, or other multicloud sources) and data lineage.
- Stronger data background — relational data modeling, profiling large tables for PII, and reasoning about classification accuracy at scale.
- Microsoft Graph (Security API) automation; Logic Apps or Sentinel integration.
- Exposure to regulated environments (e.g., HIPAA, PCI-DSS, GLBA, or SEC/FINRA records requirements).
Certifications (a plus, not required)
- SC-400: Information Protection and Compliance Administrator
- SC-200: Security Operations Analyst
- SC-300: Identity and Access Administrator
- MS-102 / AZ-500 also valued
Pay: Up to ₹2,500,000.00 per year
Work Location: Remote