Information Security Engineer - Microsoft Purview Specialist
The University of Chicago Medicine Information Security Engineer - Microsoft Purview Specialist
Join one of the nation’s most comprehensive academic medical centers, UChicago Medicine as an Information Security Engineer - Microsoft Purview Specialist for the Information Security department. This is a remote, work from home opportunity, and you may be based outside of the greater Chicagoland area.
The Microsoft Purview Specialist is responsible for the design, implementation, administration, monitoring, and continuous improvement of Microsoft Purview capabilities across the University of Chicago Medical Center Microsoft 365 environment.
This role serves as a technical subject matter expert for data protection, information governance, compliance, investigation, and data lifecycle capabilities within Microsoft Purview. The position works closely with Information Security, Privacy, Legal, Records Management, Microsoft 365 engineering, endpoint management, and application teams to translate organizational, regulatory, and business requirements into scalable technical controls.
The successful candidate will have hands-on experience administering Microsoft Purview in a complex enterprise environment and will understand how Purview capabilities interact with Microsoft 365 services including Exchange Online, SharePoint Online, OneDrive, Microsoft Teams, Microsoft 365 Apps, endpoints, and Microsoft Entra ID.
Essential Job Functions
- Administer and maintain Microsoft Purview capabilities across the Microsoft 365 environment.
- Design, configure, test, deploy, monitor, and tune Purview policies and controls.
- Develop standards, operational procedures, technical documentation, and governance documentation for Purview services.
- Information Protection and Classification.
- Design and maintain the organization's Microsoft Purview Information Protection strategy.
- Develop and manage sensitivity labels, label policies, publishing policies, protection settings, encryption controls, and related classification standards.
- Configure and maintain Sensitive Information Types, Exact Data Match classifiers, trainable classifiers, keyword dictionaries, and other classification mechanisms where appropriate.
- Develop DLP controls for Exchange Online, SharePoint Online, OneDrive, Microsoft Teams, Microsoft 365 applications, endpoints, and other supported workloads.
- Configure policy tips, notifications, user overrides, incident reporting, auditing, restriction, and blocking actions.
- Manage retention across Exchange Online, SharePoint Online, OneDrive, Teams, and other supported Microsoft 365 workloads.
- Support evaluation, implementation, and administration of Microsoft Purview Insider Risk Management and Communication Compliance
- Develop operational metrics and reporting for Purview controls.
- Participate in development of enterprise information-protection and data-governance standards.
- Develop and maintain PowerShell and Microsoft Graph automation used to administer, report on, validate, and monitor Microsoft Purview configurations.
- Automate repetitive administrative and reporting processes where supported.
- Develop scripts and tooling for configuration assessment, policy validation, reporting, and operational support.
- Maintain source-controlled scripts and supporting technical documentation.
Required Qualifications
BS or BA degree in computer science, engineering, or equivalent education, training or work experience; master’s degree preferred
- Strong hands-on experience administering Microsoft Purview in a production Microsoft 365 environment
- Strong knowledge of Microsoft Purview Data Loss Prevention
- Strong knowledge of Microsoft Purview Information Protection, sensitivity labels, sensitive information types, and classification technologies
- Experience with Microsoft Purview Data Lifecycle Management and retention
- Experience supporting Microsoft Purview Audit and eDiscovery
- Strong understanding of Exchange Online, SharePoint Online, OneDrive, Microsoft Teams, and Microsoft 365 Apps
- Understanding of Microsoft Entra ID identity, groups, roles, and access-control concepts
- Experience administering Microsoft 365 using PowerShell
- Experience troubleshooting enterprise Microsoft 365 policy and configuration issues
- Experience creating technical documentation, operational procedures, and governance standards
- Ability to translate security, privacy, regulatory, legal, and business requirements into technical configurations
- Strong analytical and troubleshooting skills
Preferred Qualifications
- Experience supporting Microsoft 365 in a healthcare environment
- Experience implementing data-protection controls involving PHI and PII
- Knowledge of HIPAA and healthcare data-protection requirements
- Experience with Microsoft Purview Endpoint DLP
- Experience with Microsoft Purview Insider Risk Management
- Experience with Microsoft Purview Communication Compliance
- Experience with Microsoft Purview Records Management
- Experience with advanced Microsoft Purview eDiscovery workflows
- Experience with Exact Data Match, trainable classifiers, custom Sensitive Information Types, and advanced classification techniques
- Experience with Microsoft Graph and automation
- Experience with Microsoft Intune, Microsoft Defender, and Microsoft Entra ID
- Experience working within formal change-management and enterprise governance processes
- Experience operating Microsoft 365 in a large, regulated enterprise
Position Details
- Job Type/FTE: Full Time (1.0 FTE)
- Shift: Day
- Location: Remote
- Unit/Department: Information Security
- CBA Code: Non-Union