Department / Seat Name: TAC
Engagement Type: Independent Contractor (1099), project-scoped
Role Summary
The Microsoft Purview Engineer is a hands-on Microsoft 365 security engineer who owns the
technical execution of Purview data protection engagements for RSI Security clients. This role
assesses current-state Microsoft 365 and Purview configuration, designs the data classification
and sensitivity-labeling architecture, defines and implements DLP policies and use cases, and
works directly with client business departments to translate their data requirements into
working Purview controls. The role also performs Microsoft 365 / O365 security configuration
assessments across Exchange, Teams, SharePoint, OneDrive, Entra ID, and Defender for Office
365. This is an implementation and engineering seat, not an advisory one — the contractor is
expected to be in the tenant, building and testing configurations, not producing
recommendations for someone else to execute.
Role Purpose
The purpose of this role is to give RSI Security the depth of Microsoft platform expertise
required to take client Purview deployments past initial discovery and into production. Clients
engaging RSI for this work have typically completed baseline data scanning and begun testing
DLP policies on their own, and need a practitioner who can assess what they have built,
correct it, and carry the deployment to a validated, operational state. The contractor is
expected to hold the technical conversation directly with client IT and security staff on
implementation options, trade-offs, and Microsoft platform practices, and to defend the design
decisions made.
Core Responsibilities
● Assess current-state Microsoft Purview and Microsoft 365 configuration, including
existing data discovery results, scan coverage, label taxonomy, and in-flight DLP
policies, and document gaps against the client's data protection objectives.
● Develop a Purview implementation roadmap and phased deployment plan, sequenced
against client readiness, licensing, and business department availability.
● Design the data classification framework and sensitivity label structure, including label
scoping, publishing policies, auto-labeling rules, and encryption and access-control
settings.
● Define, configure, test, and tune DLP policies across Exchange Online, Teams,
SharePoint Online, OneDrive, and endpoint, including policy simulation, false-positive
reduction, and user-notification and override behavior.
● Configure and validate Microsoft Purview Information Protection, data lifecycle and
retention policies, and Insider Risk Management, matched to the client's
records-retention and regulatory obligations.
● Facilitate working sessions with client business departments to identify data types,
ownership, handling requirements, and acceptable friction, and translate those into
Purview policy configuration.
● Design and validate data protection controls for PII, PHI, and other sensitive
government data, including controls governing Microsoft Copilot access to sensitive
content where the client has Copilot deployed.
● Execute Microsoft 365 / O365 security configuration assessments covering tenant-level
security posture, Entra ID identity and conditional access, Exchange Online protection,
Defender for Office 365, SharePoint and OneDrive external sharing, Teams governance,
and audit and logging configuration.
● Produce technical findings, configuration evidence, and remediation guidance in RSI
report format, at delivery quality suitable for direct client release.
● Establish ongoing operational processes and handoff documentation so client staff can
administer, monitor, and extend the Purview deployment after the engagement closes.
● Participate in client technical meetings and answer implementation and
platform-practice questions directly, including trade-off discussion on licensing, scope,
phasing, and control strictness.
● Provide accurate time and activity documentation sufficient to support invoicing and
deliverable verification.
Required Technical Qualifications
● Strong hands-on Microsoft Purview implementation experience — deployments
carried to production, not pilots or assessments alone
● Data discovery and classification, including content scanning, sensitive
information types, exact data match, and trainable classifiers
● Sensitivity labels and Microsoft Purview Information Protection (formerly MIP),
including label policy design, auto-labeling, and encryption behavior
● DLP policy design, configuration, testing, and tuning across Microsoft 365
workloads
● Data governance, data lifecycle management, and retention policy configuration
● Insider Risk Management configuration and tuning
● Administration-level command of Microsoft 365 workloads: Exchange Online,
Teams, SharePoint Online, and OneDrive
● Demonstrated experience building data classification frameworks from the
ground up
● Demonstrated experience translating business requirements into working
Purview policy configuration
● Demonstrated experience facilitating requirements workshops across multiple
business departments
● Ability to produce an implementation roadmap and phased deployment plan and
execute against it
● Experience protecting PII, PHI, and other highly sensitive data in regulated
environments
● Microsoft 365 administrator or security engineer background, evidenced by
current or recent certification (MS-500 / SC-400 / SC-401, SC-200, SC-300, or
MS-102) or equivalent demonstrable production experience
Preferred Qualifications
● Microsoft 365 GCC or GCC High experience
● Government sector experience, including public agency, housing authority, or
state and local government environments
● Microsoft 365 G5 licensing experience and command of which Purview
capabilities each license tier unlocks
● Microsoft Copilot data protection and security experience
● PowerShell automation across Exchange Online, Security & Compliance, and
Graph
● Prior consulting or client-facing delivery experience in a professional services
environment
Skills Required
- Strong hands-on Microsoft Purview implementation experience with deployments carried to production
- Experience with data discovery and classification, including content scanning, sensitive information types, exact data match, and trainable classifiers
- Experience designing sensitivity labels and Microsoft Purview Information Protection, including label policies, auto-labeling, and encryption behavior
- Experience designing, configuring, testing, and tuning DLP policies across Microsoft 365 workloads
- Experience configuring data governance, data lifecycle management, and retention policies
- Experience configuring and tuning Insider Risk Management
- Administration-level command of Exchange Online, Teams, SharePoint Online, and OneDrive
- Experience building data classification frameworks from the ground up
- Experience translating business requirements into working Purview policy configurations
- Experience facilitating requirements workshops across multiple business departments
- Ability to produce implementation roadmaps and phased deployment plans and execute against them
- Experience protecting PII, PHI, and highly sensitive data in regulated environments
- Microsoft 365 administrator or security engineer background demonstrated through current or recent MS-500, SC-400, SC-401, SC-200, SC-300, or MS-102 certification, or equivalent production experience
- Microsoft 365 GCC or GCC High experience
- Government sector experience, including public agency, housing authority, or state and local government environments
- Microsoft 365 G5 licensing experience and knowledge of Purview capabilities by license tier
- Microsoft Copilot data protection and security experience
- PowerShell automation across Exchange Online, Security and Compliance, and Graph
- Prior consulting or client-facing delivery experience in a professional services environment
What We Do
RSI Security is a cybersecurity-focused technology company that helps private and public sector organizations in highly regulated industries effectively manage risk. RSI Security provides cyber engineering, assessment, advisory services, and technical testing to amp up clients' security posture while mitigating business risk. We have experts for every cybersecurity and compliance need– PCIDSS, CMMC and NIST, MSSP, IT Security, HITRUST, HIPAA / HITECH, CCPA, GDPR, threat detection, security awareness training, and much more. Our team members come from diverse backgrounds and specialties. Our team members include published authors, open-source developers, industry researchers, and conference presenters. For more information, visit rsisecurity.com
%20copy.jpg)







