Security / Compliance Architect
- Lead the definition of the controlled data / CUI boundary, including in-scope users, repositories, workflows, endpoints, and approved handling paths.
- Translate customer requirements into a target-state security architecture for a secure collaboration enclave.
- Define the DLP and information protection strategy across collaboration, email, endpoint, and removable media channels.
- Establish the control intent for classification, labeling, monitoring, restriction, blocking, exception handling, and audit evidence generation.
- Drive alignment between business process requirements and security control design to ensure the solution is usable as well as compliant.
- Lead design decisions related to:
- approved vs non-approved storage locations
- secure collaboration patterns
- external sharing restrictions
- exception governance
- evidence and logging requirements
- Review current-state data handling patterns and identify exposure points, control gaps, and architectural risks.
- Produce client-facing security design artifacts, including boundary definitions, control strategies, architecture requirements, and decision packs.
- Support design reviews, steering discussions, and executive readouts.
- Work closely with the platform lead to ensure Microsoft control implementation aligns with security intent.
- Support pilot validation by reviewing policy effectiveness, exception scenarios, usability impacts, and audit defensibility.
- Provide oversight during deployment and handover to ensure the final state aligns with the approved security design.
- 8+ years in cybersecurity architecture, security consulting, or security engineering roles.
- Strong experience in one or more of the following:
- Data Loss Prevention
- Information Protection / Data Classification
- Secure collaboration architecture
- Microsoft Purview / MIP / DLP
- Compliance-driven security design
- Experience defining and operationalizing controls for sensitive or regulated data.
- Strong understanding of:
- secure data boundaries
- access control and least privilege concepts
- audit evidence requirements
- policy exception governance
- endpoint, email, and collaboration security controls
- Experience working directly with business stakeholders, security leadership, and platform teams in regulated environments.
- Strong workshop facilitation, requirements analysis, and executive communication skills.
- Ability to convert ambiguous customer requirements into precise security architecture decisions.
This is a remote position.