DLP Senior Analyst - Purview

Reposted 7 Days Ago
Be an Early Applicant
Chicago, IL, USA
Hybrid
98K-135K Annually
Senior level
Professional Services
The Role
Designs, implements, and manages Microsoft Purview data governance, information protection, DLP, insider risk, records management, and eDiscovery solutions. Protects sensitive data across Microsoft 365 and Azure through classification, labeling, encryption, access governance, monitoring, and compliance policies. Investigates alerts and data-related incidents, supports audits and risk assessments, develops governance workflows and documentation, and collaborates with IT, Security, Legal, and Compliance teams to strengthen the firm’s data security strategy.
Summary Generated by Built In

The DLP Senior Analyst - Purview is primarily responsible for designing, implementing, and managing the Firm’s data governance, compliance, and information protection solutions using Microsoft Purview. This individual will ensure that sensitive Client and Firm data is appropriately classified, labeled, monitored, and secured in alignment with regulatory requirements, contractual obligations, and Firm-specific policies. The Senior Analyst acts as a subject matter expert, collaborating with cross-functional teams — including our Applications Team, Records Management, Data and AI Team as well as Risk and Privacy —to establish robust data protection, lifecycle management, and eDiscovery processes. This role will also participate in incident response activities involving data loss prevention, insider risk, and compliance alerts, ensuring timely investigation, containment, and remediation. In addition, the Senior Microsoft Purview Engineer will contribute to the Firm’s overall Data Security and Compliance Strategy, driving the adoption of best practices and advanced capabilities within the Microsoft ecosystem.

Duties and Responsibilities:

  • Design, configure, and maintain Microsoft Purview solutions for data classification, labeling, retention, and compliance in alignment with Firm policies and regulatory requirements.

  • Implement and manage data security controls, including Information Protection policies, Data Loss Prevention (DLP), Insider Risk Management, and eDiscovery workflows.

  • Protect sensitive Client and Firm data through classification, labeling, encryption, access governance, and monitoring across Microsoft 365, Azure, and integrated environments.

  • Develop, enforce, and maintain compliance policies, ensuring consistent application of regulatory, contractual, and Firm-specific data protection requirements.

  • Build and optimize automated data governance workflows, enabling lifecycle management, secure data sharing, and defensible disposition of records.

  • Integrate Purview insights and alerts into Security Operations, incident response, and GRC processes to strengthen visibility, detection, and remediation of data-related risks.

  • Collaborate with IT, Security, Legal, and Compliance teams to design policies and processes that balance regulatory obligations, client requirements, and business operations.

  • Create and maintain documentation, standards, and procedures for data classification, retention, compliance reporting, and response to data-related incidents.

  • Monitor and respond to Purview compliance alerts, investigating potential risks such as data leakage, insider threats, or policy violations, and recommending remediation.

  • Participate in risk assessments, audits, and compliance efforts related to data governance and regulatory frameworks (e.g., ISO 27001, GDPR, CCPA, HIPAA).

  • Stay current with emerging data governance technologies, compliance regulations, and best practices, ensuring the Firm continues to mature its use of Microsoft Purview capabilities.

Education and/or Experience: 

Required:

  • Bachelor’s degree in Computer Science, Information Security, Information Governance, or a related field is required.

  • Minimum of 5 years of experience in security engineering, compliance engineering, or data governance, with a strong focus on Microsoft 365 and Microsoft Purview solutions.

  • Hands-on experience implementing and managing Microsoft Purview capabilities such as Information Protection, Data Loss Prevention (DLP), Insider Risk Management, Records Management, and eDiscovery.

  • Practical knowledge of Microsoft 365 security and compliance tools

  • Strong understanding of data governance principles, regulatory compliance requirements (e.g., GDPR, CCPA, HIPAA, ISO 27001), and information lifecycle management.

  • Demonstrated ability to assess, troubleshoot, and remediate data protection, compliance, and information governance issues in Microsoft 365 environments

Preferred:

  • Relevant Microsoft certifications such as Microsoft Certified: Information Protection Administrator Associate, Security Operations Analyst Associate, or Azure Security Engineer Associate (AZ-500).

  • Advanced security and compliance certifications such as CISSP, CISM, CCSP, or Security+.

  • Experience in the legal, financial services, or other highly regulated industries with strict client data governance and compliance requirements.

  • undefined

  • Hands-on experience with data security and insider risk tools such as Varonis, Digital Guardian, or Cyberhaven

  • undefined

  • Familiarity with SIEM/SOAR platforms for correlating and responding to Purview alerts.

  • undefined

  • Demonstrated ability to support large-scale legal hold, records management, and eDiscovery processes in global organizations.

  • Strong knowledge of regulatory compliance frameworks such as GDPR, CCPA, HIPAA, ISO   27001, and client-driven contractual requirements.

  • Ability to script or automat process and routine functions and tasks

Other Skills and Abilities:

The following will also be required of the successful candidate:

  • Strong organizational skills

  • Strong attention to detail

  • Good judgment and decision-making skills

  • Strong interpersonal and communication skills, both written and verbal

  • Strong analytical and problem-solving skills

  • Ability to work harmoniously and effectively with others

  • Ability to preserve confidentiality and exercise discretion

  • Ability to work under pressure in a fast-paced environment

  • Ability to manage multiple projects with competing deadlines and priorities

#LI-OE1

#LI-Hybrid

The target salary range for this role is:

$98,300 - $135,250 if located in Illinois.

Salaries vary by location and are based on numerous factors, including, but not limited to, the relevant market, skills, experience, and education of the selected candidate. Our compensation package also includes bonus eligibility and a comprehensive benefits program. Benefits information can be found at Sidley.com/Benefits.

To perform this job successfully, an individual must be able to perform the Duties and Responsibilities above satisfactorily and meet the requirements. The requirements listed above are representative of the minimum knowledge, skill, and/or ability required. Reasonable accommodations will be made to enable individuals with disabilities to perform the essential functions of the job. If you need such an accommodation, please email [email protected] (current employees should contact Human Resources).

Sidley Austin LLP is an Equal Opportunity Employer.

Skills Required

  • Bachelor's degree in Computer Science, Information Security, Information Governance, or a related field
  • At least 5 years of experience in security engineering, compliance engineering, or data governance
  • Strong focus on Microsoft 365 and Microsoft Purview solutions
  • Hands-on experience implementing and managing Microsoft Purview Information Protection, Data Loss Prevention, Insider Risk Management, Records Management, and eDiscovery
  • Practical knowledge of Microsoft 365 security and compliance tools
  • Strong understanding of data governance principles, regulatory compliance requirements, and information lifecycle management
  • Ability to assess, troubleshoot, and remediate data protection, compliance, and information governance issues in Microsoft 365 environments
  • Microsoft Information Protection Administrator Associate, Security Operations Analyst Associate, or Azure Security Engineer Associate certification
  • CISSP, CISM, CCSP, or Security+ certification
  • Experience in legal, financial services, or other highly regulated industries
  • Hands-on experience with Varonis, Digital Guardian, or Cyberhaven
  • Familiarity with SIEM/SOAR platforms
  • Experience supporting large-scale legal hold, records management, and eDiscovery processes in global organizations
  • Strong knowledge of GDPR, CCPA, HIPAA, ISO 27001, and client-driven contractual requirements
  • Ability to script or automate processes and routine tasks
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
5,100 Employees
Year Founded: 1866

What We Do

Sidley is an elite global law firm with approximately 2,300 lawyers and 21 offices worldwide. It advises clients on complex transactional, restructuring, crisis management, investigation, regulatory, and litigation matters. Its lawyers and business professionals work across commercial, regulatory, and financial centers, using cross-border legal expertise and cultural awareness to deliver innovative strategies and clarity for clients navigating a dynamic global business environment.

Similar Jobs

Sprout Social Logo Sprout Social

Lead GTM Financial Planning & Analysis Analyst

Marketing Tech • Social Media • Software • Analytics • Business Intelligence
Easy Apply
Remote or Hybrid
US
1400 Employees
114K-188K Annually

HiBob Logo HiBob

VP Payroll & Benefits (Services & Operations)

HR Tech • Information Technology • Professional Services • Sales • Software
Remote or Hybrid
US
1350 Employees
230K-290K Annually

Liberty Mutual Insurance Logo Liberty Mutual Insurance

Executive Underwriter, Liberty Mutual Mobility Solutions

Artificial Intelligence • Fintech • Insurance • Marketing Tech • Software • Analytics
Hybrid
6 Locations
40000 Employees
68K-278K Annually

Bectran, Inc Logo Bectran, Inc

Business Development Executive

Artificial Intelligence • Fintech • Information Technology • Machine Learning • Software • Automation
In-Office
Schaumburg, IL, USA
65 Employees
55K-58K Annually

Similar Companies Hiring

ABN AMRO Clearing USA LLC Thumbnail
Information Technology • Professional Services • Financial Services
Chicago, IL
215 Employees
Fora Thumbnail
Agency • On-Demand • Professional Services • Sales • Software • Travel • Hospitality
New York, NY
250 Employees
Energy CX Thumbnail
Greentech • Professional Services • Business Intelligence • Consulting • Energy • Financial Services • Utilities
Chicago, IL
108 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account