Senior Cyber Security Engineer Job at MARS Solutions Group, Milwaukee, WI

YythenZWOUZmVUxLckFjWGtlaWdqdUtRVXc9PQ==
  • MARS Solutions Group
  • Milwaukee, WI

Job Description

MARS Solutions Group is looking for a Senior Cyber Security Engineer. Our client is a (Technology/Financial Services) industry leader looking for high-quality talent to make a difference. They are known to respect a traditional work week and often extend contracts for added job security and stability

We're seeking a senior cybersecurity engineer to design, build, and operationalize enterprise grade data protection capabilities anchored in Microsoft E5 . You will lead engineering for Microsoft Purview (Information Protection & DLP, eDiscovery/Audit), Sensitivity Labels , and related guardrails-integrating telemetry and enforcement through Zscaler , CrowdStrike , and Splunk . This role bridges secure-by-default platform engineering with pragmatic automation to protect regulated data (e.g., PHI/PII) at scale. Senior leadership has prioritized accelerating Copilot and E5 controls adoption, creating a high impact opportunity to shape how we protect data across SaaS and AI workloads.

What You'll Do

Engineer secure-by-default E5 data protection

  • Design and implement Microsoft Purview DLP policies (endpoint, Exchange, SharePoint, OneDrive, Teams) and Sensitivity Label taxonomy with automated enforcement paths.

  • Build policy-as-code pipelines (CI/CD) to version, test, and deploy DLP rules, label configs, and governance artifacts in multiple environments.

Integrate Zscaler, CrowdStrike, and Splunk

  • Connect Zscaler SSE inspection with Purview controls; route events to Splunk for analytics, dashboards, and detections that close visibility and enforcement loops.
  • Leverage CrowdStrike telemetry (e.g., Falcon/Shield) to correlate endpoint behaviors with data movement signals for insider risk and exfiltration use cases.

Build automations & guardrails

  • Develop services and workflows (e.g., Azure Functions, Logic Apps, Graph API) to auto remediate mislabels, revoke risky shares, and notify data owners.
  • Implement secure-by-default configuration baselines and drift detection for E5 security controls (MCAS/Defender for Cloud Apps, Conditional Access, etc.).

Operate and continuously improve

  • Own reliability for data protection pipelines: SLIs/SLOs, runbooks, and incident playbooks in partnership with Insider Risk team.
  • Create Splunk content (data models, dashboards, correlation searches) aligned to exfiltration, anomalous access, and label violations.
  • Partner with Privacy and Compliance for audit ready controls (eDiscovery/Audit), evidence, and exception processes.

Collaborate across security & platform teams

  • Work with PSO, IAM, and Insider Risk to align label taxonomy and enforcement with business workflows and least privilege access.
  • Provide technical leadership and mentoring for engineers/analysts rolling out new E5 features and operational support.

Required Qualifications

  • 5+ years engineering experience in enterprise security or platform engineering; hands-on with Microsoft E5 security stack (Purview DLP, Information Protection, eDiscovery).
  • Proven expertise building policy as code for DLP/labels (GitHub/Azure DevOps), and automating Graph/PowerShell administration.
  • Demonstrated ability to design secure-by-default guardrails and support rapid SaaS/AI adoption (including Copilot) without compromising compliance.

Nice to Have

  • Strong background in data protection for regulated data (PII/PHI), insider risk detection, and evidence driven investigations.
  • Production experience with Zscaler (SSE/ZIA/ZPA), CrowdStrike (Falcon APIs/telemetry), and Splunk (TA configs, CIM, correlation searches).
  • Experience migrating from legacy DLP (e.g., Forcepoint ) to Microsoft DLP; building vendor neutral dictionaries and detection logic.
  • Familiarity with MCAS/Defender for Cloud Apps, conditional access policies, and SSPM evaluations.
  • Background in HIPAA/PHI audit support and exception governance workflows.

Success Metrics (first 6 12 months)

  • DLP policy efficacy: reduction in unauthorized shares/exports; mean time to remediate violations.
  • Label coverage & accuracy: % of sensitive content labeled; false positive/negative rate trends.
  • Telemetry integration: end-to-end event flow (Purview Zscaler/CrowdStrike Splunk) with actionable detections.
  • Secure-by-default adoption: # of guardrails implemented; drift detected/resolved; Copilot controls baselined.
  • Audit readiness: evidence completeness for eDiscovery/Audit; exception closure rates.

Tools & Technologies (primary)

  • Microsoft E5 / Purview: Information Protection, DLP, eDiscovery/Audit, Insider Risk
  • Zscaler (SSE/ZIA/ZPA), CrowdStrike (Falcon/Shield), Splunk (CIM, ES)
  • Automation: GitHub, Graph API, PowerShell, Azure Functions/Logic Apps
  • Data flows: Exchange/SharePoint/OneDrive/Slack, endpoints, web proxies, CASB/SSE

About MARS Solutions Group:
MARS Solutions Group provides a range of opportunities for meaningful work by understanding that employment fit is a combination of people, process, and technology. We leverage our experienced and compassionate team to bring humanity to matching you with the right advanced technology role, and stay connected with you to help you attain your professional goals.

Job Tags

Hourly pay,

Similar Jobs

Connecticut Institute for Communities, Inc.

Preschool Classroom Aid / CDA Specialist Job at Connecticut Institute for Communities, Inc.

 ...Exempt Directly Supervises: None Requirements: ~18+ years old, required. ~ Entry level position; ~ previous babysitting or childcare experience is preferred. ~ Basic computer experience is required (i.e. email, word processing, internet navigation). ~... 

Sentry Insurance

Data Analyst Job at Sentry Insurance

 ...Our team of Data Analysts leverages knowledge of Sentrys data systems and business processes to...  ...ensure all the best output is provided. Work closely with team members to analyze...  ...work model. Monday and Friday work from home if you choose to, Tuesday through Thursday... 

U.S. Army

92R Parachute Rigger Job at U.S. Army

 ...safety and repair of all parachute equipment before, during, and after an airdrop operation. You'll be responsible for assembling rigging components and securing all the supplies in the aircraft. Requirements * A U.S. Citizen or permanent resident with a valid Green Card... 

MetLife

Sr. Full Stack Software Engineer Job at MetLife

 ..., working in cross-functional teams, to develop software solutions. Work Arrangement: Hybrid - 3 days in office/2 days remote"At MetLife, we're leading the global transformation of an industry we've long defined. United in purpose, diverse in perspective, we're dedicated... 

YMCA of Virginia's Blue Ridge

Fitness & Wellness Staff - Salem Family YMCA Job at YMCA of Virginia's Blue Ridge

 ...related appointments with members. Provide continuous supervision, education and encouragement to all members in accordance with YMCA of the USA guidelines. Encourage YMCA members to meet their own determined wellness goals through regular contact, incentive programs...