remotely.living

Microsoft Purview Engineer

RSI Security · Remote - United States · 2026-09-04

Apply for this job

Job description

Role Title: Microsoft Purview Engineer

Department / Seat Name: TAC

Engagement Type: Independent Contractor (1099), project-scoped

Role Summary

The Microsoft Purview Engineer is a hands-on Microsoft 365 security engineer who owns the

technical execution of Purview data protection engagements for RSI Security clients. This role

assesses current-state Microsoft 365 and Purview configuration, designs the data classification

and sensitivity-labeling architecture, defines and implements DLP policies and use cases, and

works directly with client business departments to translate their data requirements into

working Purview controls. The role also performs Microsoft 365 / O365 security configuration

assessments across Exchange, Teams, SharePoint, OneDrive, Entra ID, and Defender for Office

365. This is an implementation and engineering seat, not an advisory one — the contractor is

expected to be in the tenant, building and testing configurations, not producing

recommendations for someone else to execute.

Role Purpose

The purpose of this role is to give RSI Security the depth of Microsoft platform expertise

required to take client Purview deployments past initial discovery and into production. Clients

engaging RSI for this work have typically completed baseline data scanning and begun testing

DLP policies on their own, and need a practitioner who can assess what they have built,

correct it, and carry the deployment to a validated, operational state. The contractor is

expected to hold the technical conversation directly with client IT and security staff on

implementation options, trade-offs, and Microsoft platform practices, and to defend the design

decisions made.

Core Responsibilities

● Assess current-state Microsoft Purview and Microsoft 365 configuration, including

existing data discovery results, scan coverage, label taxonomy, and in-flight DLP

policies, and document gaps against the client's data protection objectives.

● Develop a Purview implementation roadmap and phased deployment plan, sequenced

against client readiness, licensing, and business department availability.

● Design the data classification framework and sensitivity label structure, including label

scoping, publishing policies, auto-labeling rules, and encryption and access-control

settings.

● Define, configure, test, and tune DLP policies across Exchange Online, Teams,

SharePoint Online, OneDrive, and endpoint, including policy simulation, false-positive

reduction, and user-notification and override behavior.

● Configure and validate Microsoft Purview Information Protection, data lifecycle and

retention policies, and Insider Risk Management, matched to the client's

records-retention and regulatory obligations.

● Facilitate working sessions with client business departments to identify data types,

ownership, handling requirements, and acceptable friction, and translate those into

Purview policy configuration.

● Design and validate data protection controls for PII, PHI, and other sensitive

government data, including controls governing Microsoft Copilot access to sensitive

content where the client has Copilot deployed.

● Execute Microsoft 365 / O365 security configuration assessments covering tenant-level

security posture, Entra ID identity and conditional access, Exchange Online protection,

Defender for Office 365, SharePoint and OneDrive external sharing, Teams governance,

and audit and logging configuration.

● Produce technical findings, configuration evidence, and remediation guidance in RSI

report format, at delivery quality suitable for direct client release.

● Establish ongoing operational processes and handoff documentation so client staff can

administer, monitor, and extend the Purview deployment after the engagement closes.

● Participate in client technical meetings and answer implementation and

platform-practice questions directly, including trade-off discussion on licensing, scope,

phasing, and control strictness.

● Provide accurate time and activity documentation sufficient to support invoicing and

deliverable verification.

Required Technical Qualifications

● Strong hands-on Microsoft Purview implementation experience — deployments

carried to production, not pilots or assessments alone

● Data discovery and classification, including content scanning, sensitive

information types, exact data match, and trainable classifiers

● Sensitivity labels and Microsoft Purview Information Protection (formerly MIP),

including label policy design, auto-labeling, and encryption behavior

● DLP policy design, configuration, testing, and tuning across Microsoft 365

workloads

● Data governance, data lifecycle management, and retention policy configuration

● Insider Risk Management configuration and tuning

● Administration-level command of Microsoft 365 workloads: Exchange Online,

Teams, SharePoint Online, and OneDrive

● Demonstrated experience building data classification frameworks from the

ground up

● Demonstrated experience translating business requirements into working

Purview policy configuration

● Demonstrated experience facilitating requirements workshops across multiple

business departments

● Ability to produce an implementation roadmap and phased deployment plan and

execute against it

● Experience protecting PII, PHI, and other highly sensitive data in regulated

environments

● Microsoft 365 administrator or security engineer background, evidenced by

current or recent certification (MS-500 / SC-400 / SC-401, SC-200, SC-300, or

MS-102) or equivalent demonstrable production experience

Preferred Qualifications

● Microsoft 365 GCC or GCC High experience

● Government sector experience, including public agency, housing authority, or

state and local government environments

● Microsoft 365 G5 licensing experience and command of which Purview

capabilities each license tier unlocks

● Microsoft Copilot data protection and security experience

● PowerShell automation across Exchange Online, Security & Compliance, and

Graph

● Prior consulting or client-facing delivery experience in a professional services

environment Originally posted on Himalayas