Design and implement enterprise-wide sensitivity labels, label policies, and auto-labeling rules tailored to financial data (e.g., client reports, investment models, trading strategies, deal documentation).
Use trainable classifiers and custom information types to detect and label unstructured sensitive content.
Ensure consistent application of labels across Microsoft 365 workloads (Exchange, SharePoint, OneDrive, Teams, Office apps).
Implement IRM policies to apply encryption, usage restrictions (e.g., read-only, no forwarding, expiration), and access controls that persist with the data.
Apply labels with IRM to high-risk data to control access even outside corporate boundaries (e.g., external sharing or mobile access).
Develop and manage Microsoft Purview Rights Management Templates aligned to business roles, sensitivity levels, and legal requirements.
Integrate BigID with Microsoft Purview to align and enforce classification across both structured (databases, CRM, data lakes) and unstructured data.
Enable metadata exchange and shared classification tagging to streamline protection across the enterprise.
Use BigID to discover dark data and extend classification capabilities to legacy or non-Microsoft repositories.
Automate label and IRM policy deployment using PowerShell, Microsoft Graph API, and Purview REST APIs.
Monitor labeling effectiveness, policy usage, and adoption using Microsoft compliance center insights and BigID dashboards.
Continuously optimize classification models and IRM configurations based on business feedback, incident data, and compliance findings.
Support audits, legal holds, and internal reviews with accurate data classification and rights enforcement reports.
Partner with compliance, legal, cybersecurity, and business teams to define classification taxonomies and labeling strategies.
Knowledge, Skill, Experience Required:
Required:
46 years of experience implementing data classification and rights management solutions in financial services environments.
Deep expertise in Microsoft Purview / MIP: sensitivity labels, auto-labeling, trainable classifiers, and IRM features.
Strong hands-on experience with BigID, including discovery, policy configuration, and tagging of structured/unstructured data.
Scripting knowledge in PowerShell, Graph API, or REST APIs for automation and reporting.
Knowledge of financial data types (client data, trade data, and regulatory reports) and associated risk levels.
Familiarity with compliance regulations impacting data (GDPR, CCPA, SEBI etc).
Experience with Microsoft Defender for Cloud Apps (MCAS), DLP, and related data protection solutions is a plus.
Beneficial:
Microsoft Certified: Information Protection Administrator Associate (SC-400)
BigID Administrator / Practitioner Certification
Data Privacy or Security Certifications: CIPP/E, CIPT, CDPSE, CISSP will be a bonus
Azure Security / Microsoft 365 Security certifications
Personal Characteristics:
Ability to work cross-functionally with compliance, security, legal, and business data owners
Excellent communication and documentation skills
Proactive, detail-oriented, and outcome-driven
Strong analytical and troubleshooting mindset
Job Classification
Industry: IT Services & ConsultingFunctional Area / Department: Engineering - Hardware & NetworksRole Category: IT NetworkRole: IT Network - OtherEmployement Type: Contract