Skip to main content
Vailexa

Senior Security Engineer

RemoteUnited States only
Published
Role
Security
Experience
Senior
Salary not disclosed
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Senior security engineer with 5+ years in security engineering, hands-on Microsoft 365 security tooling, Entra ID, Microsoft Purview, Cyera, DLP/DSPM remediation, and incident-response handoffs. Must personally drive sensitive-data exposure findings to closure across Microsoft 365 environments.

Core skills

Microsoft 365CyeraMicrosoft Purview

Required skills

Microsoft Purview DLPMicrosoft Purview sensitivity labelsMicrosoft Purview Insider Risk ManagementMicrosoft Purview AuditEntra IDSIEMSOCSharePointOneDrive

Optional skills

VaronisUEBAOneDrive sync clientEDRGIAC GCIAGIAC GCIHMicrosoft SC-200DSPM certifications

What you'll do

  • Support activities including data discovery, classification, tagging, labeling, risk prioritization, and remediation planning.
  • Partner with client security, DLP, SOC, and data governance teams to understand current workflows, ownership models, ticket volume, and remediation hand-offs.
  • Triage findings surfaced through data security tooling, monitoring, or validation activities and help determine the appropriate remediation path.
  • Drive remediation actions to closure, including access changes, policy adjustments, data handling updates, quarantine or containment steps, and coordination with the appropriate operational owners.
  • Coordinate with the SOC and response teams when findings indicate incident response, containment, or escalation requirements.
  • Document remediation decisions, closure evidence, recurring patterns, and operational lessons learned to support audit readiness and future-state process improvement.
  • Provide technical input into the remediation roadmap and target-state data security operating model based on findings encountered during the engagement.
  • Continue as the primary hands-on remediation and incident-response resource — investigating false positives/negatives, adjusting behavioral baselines, and driving real findings to closure as the environment sees production traffic.
  • Remain the day-to-day working partner to Client's in-house DLP engineer for as long as the engagement continues, rather than handing remediation entirely back to the client after go-live.

What they require

  • 5+ years in security engineering, with direct hands-on experience configuring Microsoft 365 security tooling (Purview DLP, sensitivity labels, Insider Risk Management, Audit) and Entra ID.
  • Direct, hands-on remediation experience — not just detection or reporting.
  • Able to take a Cyera or DLP finding and personally drive it to resolution: revoke access, adjust a policy, quarantine data, or take the equivalent corrective action.
  • Practical expertise in Cyera specifically (Client's enterprise-standard DSPM platform) and deep expertise in Microsoft Purview and the broader Microsoft 365 security stack.
  • Working knowledge of SIEM/SOC alerting pipelines and incident response processes — this role is a key hand-off point between DLP/DSPM detection and SOC-driven containment, so understanding both sides matters.
  • Comfort working as a peer alongside a client's existing in-house DLP engineer on shared remediation work, communicating clearly about who is handling what.
  • Demonstrated experience designing or executing controlled, purple-team-style validation exercises in an isolated test environment — not full red-team penetration testing.
  • Practical understanding of common SharePoint/OneDrive incident patterns: compromised-account exfiltration, oversharing/public-link exposure, insider data theft, ransomware via sync clients, malicious OAuth consent grants, and lateral movement via overprivileged access.
  • Ability to translate technical remediation work into clear documentation suitable for both technical and client-facing review.
  • Preferred: Hands-on experience with both Cyera and Varonis — the client has indicated familiarity with both platforms is a plus, even though Cyera is the enterprise standard for this engagement.
  • Preferred: Experience with UEBA/behavioral-baseline tooling specifically for insider-risk or departing-employee scenarios.
  • Preferred: Familiarity with OneDrive sync-client behavior and endpoint EDR correlation for ransomware-pattern detection.
  • Preferred: Relevant certifications such as GIAC/SANS (e.g., GCIA, GCIH), Microsoft SC-200, or vendor-specific DSPM certifications.
  • Preferred: Prior experience embedded alongside a client's in-house security/DLP team on an ongoing remediation or hyper care basis, rather than a discrete assessment of engagement.

Benefits

  • Space to grow, freedom to think, and opportunity to create real impact from day one.

Vailexa says it is building thinkers, creators, and future leaders and giving people space to grow, think, and create impact from day one.

Cybersecurity

Details

Apply routeGreenhouse
Salary not disclosed