About the Role
We are seeking a skilled SECOPS Engineer – M365 to strengthen our client’s cybersecurity framework and ensure end-to-end protection of digital assets. The ideal candidate will play a key role in implementing, monitoring, and enhancing data protection and security operations within Microsoft 365 environments.
Key Responsibilities
Configure and maintain email and endpoint DLP policies to prevent data leakage.
Identify sensitive data across endpoints and emails, enforcing appropriate protection controls.
Continuously assess and optimize DLP policies to minimize security risks.
Collaborate with business units to understand data protection needs and design tailored DLP controls.
Administer and enforce Microsoft Information Protection (MIP) including sensitivity labels, rights management, and classification tools.
Manage and configure M365 Defender to monitor, detect, and respond to incidents across Microsoft environments.
Lead or assist in incident investigations related to email, endpoint, and data breaches.
Work closely with cross-functional teams to improve organizational security posture.
Stay current with evolving cybersecurity trends, threats, and vulnerabilities within the Microsoft ecosystem.
Required Trainings & Skills
Microsoft Certified: Security, Compliance, and Identity Fundamentals
Microsoft Certified: Security Operations Analyst Associate
Proficiency with SIEMs, firewalls, VPNs, and encryption solutions.
Knowledge of scripting and automation (PowerShell, Python, etc.).
Strong analytical, problem-solving, and communication skills.
Qualifications & Experience
Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience).
Minimum 3+ years of experience in Security Operations or IT Security.
Hands-on experience with Microsoft 365 Defender (Defender for Endpoint, Defender for Office 365, etc.).
Expertise in MIP, sensitivity labels, rights management, and DLP configuration.
Strong understanding of information security frameworks (NIST, ISO 27001, GDPR, etc.).
Proven experience in incident response, troubleshooting, and root cause analysis.
Familiarity with EDR, SIEM, and endpoint protection technologies.