EDAT- Senior Data Security Engineer - Tampa, FL
Tampa, United States · On-site · Contract
- Posted 2w ago
- From Barbaricum’s careers page
- Location
- Tampa, United States
- Work mode
- On-site
- Type
- Contract
- Level
- Senior
- Experience
- 10+ years
- Department
- Information Technology
Apply on Barbaricum’s site
Opens the listing on job-boards.greenhouse.io
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.
About the role
Key Responsibilities
- Design, implement, and sustain enterprise Data Rights Management (DRM) solutions supporting the DoD Zero Trust Data Pillar.
- Engineer data-centric security controls that protect sensitive information regardless of location, device, or user.
- Configure and manage encryption, labeling, classification, access control, and persistent protection technologies for enterprise data.
- Implement Microsoft Purview Information Protection, Microsoft Purview Data Loss Prevention (DLP), Microsoft Purview Information Governance, Microsoft Purview Insider Risk Management, Microsoft Defender for Cloud Apps, and related Microsoft 365 security technologies.
- Develop and maintain enterprise data classification schemas, sensitivity labels, protection templates, and automated labeling policies.
- Integrate DRM capabilities with Identity, Credential, and Access Management (ICAM) solutions to enforce attribute-based and role-based access controls.
- Collaborate with Zero Trust architects to implement policy decision points (PDPs), policy enforcement points (PEPs), and continuous authorization mechanisms supporting secure data access.
- Develop data protection strategies supporting cloud, hybrid, and on-premises environments.
- Implement and maintain data loss prevention (DLP) policies for email, endpoints, cloud applications, collaboration platforms, and removable media.
- Support secure collaboration using Microsoft 365, SharePoint Online, Teams, Exchange Online, OneDrive, and Azure services.
- Evaluate enterprise data flows and recommend security controls that reduce organizational risk while supporting operational requirements.
- Perform security assessments, gap analyses, and technical evaluations of DRM and data protection technologies.
- Develop engineering documentation including system design documents, implementation plans, standard operating procedures (SOPs), technical reports, and architecture diagrams.
- Support Authority to Operate (ATO), RMF, and cybersecurity compliance activities.
- Participate in architecture reviews, security engineering working groups, technical interchange meetings, and Zero Trust planning sessions.
- Mentor junior engineers and provide technical leadership across the Data Team.
Required Qualifications
- Active Top Secret/SCI security clearance.
- Must be eligible to maintain access to USSOCOM systems and facilities.
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, Engineering, or a related technical field (or equivalent experience).
- Minimum of 10 years of progressively responsible cybersecurity or information security engineering experience.
- Experience implementing enterprise Data Rights Management (DRM), Information Rights Management (IRM), or Enterprise Digital Rights Management (EDRM) technologies.
- Strong understanding of DoD Zero Trust principles, architecture, and implementation guidance.
- Experience securing data across Microsoft 365, Azure, hybrid cloud, and enterprise environments.
- Experience implementing Microsoft Purview Information Protection, DLP, sensitivity labeling, and information governance capabilities.
- Experience with data classification, encryption, key management, and data lifecycle management.
- Experience integrating security solutions with Microsoft Entra ID (Azure AD), Conditional Access, Privileged Identity Management (PIM), and ICAM architectures.
- Knowledge of NIST SP 800-53, NIST SP 800-207 (Zero Trust Architecture), DoD Zero Trust Reference Architecture, RMF, and CMMC concepts.
- Strong knowledge of encryption technologies, PKI, certificate management, and secure information sharing.
- Experience troubleshooting complex enterprise security implementations.
- Excellent written and verbal communication skills.
Desired Qualifications
- Experience supporting USSOCOM or other DoD organizations.
- Experience implementing Microsoft Defender XDR security solutions.
- Experience with Microsoft Defender for Endpoint, Defender for Office 365, Defender for Identity, and Defender for Cloud Apps.
- Familiarity with cloud security technologies including Microsoft Azure, AWS, or Google Cloud Platform.
- Experience with Microsoft Graph API, PowerShell automation, and infrastructure-as-code.
- Experience integrating DRM with enterprise collaboration platforms.
- Knowledge of data discovery, insider risk, data governance, and privacy solutions.
- Experience supporting Agile software development and DevSecOps environments.
Certifications
Candidate must possess an active DoD 8140 baseline certification appropriate for the position (such as Security+ CE, CySA+, CASP+, CISSP, or equivalent) prior to start date. Preferred certifications include:
- Certified Information Systems Security Professional (CISSP)
- Microsoft Certified: Information Protection Administrator Associate (SC-400)
- Microsoft Certified: Cybersecurity Architect Expert (SC-100)
- Microsoft Certified: Security Operations Analyst (SC-200)
- Microsoft Certified: Identity and Access Administrator Associate (SC-300)
- Microsoft Certified: Security, Compliance, and Identity Fundamentals (SC-900)
- Certified Information Security Manager (CISM)
- GIAC Security Certifications (GSEC, GCIA, GCED, or similar)
Skills they ask for
Pick one to see other roles that ask for it.
- Rights management
- Information rights management
- Enterprise digital rights management
- Zero trust
- Microsoft purview information protection
- Microsoft purview data loss prevention
- Microsoft purview information governance
- Microsoft purview insider risk management
- Microsoft defender for cloud sentinel
- Microsoft 365 security technologies
- Nist sp 800 53
- Nist sp 800 207
- Do d zero trust reference architecture
- Rmf
- Cmmc
About Barbaricum
Technology-enabled solutions for national securityBarbaricum provides technology-enabled services for national security customers and partners, working through government contract vehicles.
See all 35 roles at BarbaricumMore roles at Barbaricum
See all 35- EDAT- Senior Palantir Foundry Engineer — Fort Bragg, NCFort Bragg · Senior · On-siteData and Analytics · Senior · On-siteFort Bragg, United States2d
- Intelligence Operations IntegratorKittery · On-siteOn-siteKittery, United States3d
- Intelligence Operations IntegratorDoral · On-siteOn-siteDoral, United States3d
- Pre-Award: APOLLO- Operations in the Information Environment (OIE) Journeyman Planner- Norfolk VANorfolk · On-siteOn-siteNorfolk, United States1w
Share this role
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.