Microsoft Purview and Data Protection Engineer
Washington, DC, USA
USD 160k-180k / year
Position Summary
The Microsoft Purview and Data Protection Engineer is a senior technical leader responsible for designing, implementing, and continuously enhancing the organization's enterprise data protection capabilities. This hands-on role serves as the technical authority for Microsoft Purview, leading the operational management of Data Loss Prevention (DLP), Insider Risk Management, Information Protection, Data Security Posture Management (DSPM), and related Microsoft security technologies. Working closely with Security Operations, Infrastructure, Cloud Engineering, Compliance, Legal, Risk, and business stakeholders, the engineer develops scalable solutions that protect the firm's most sensitive information while enabling secure business collaboration and innovation.
The successful candidate combines deep technical expertise with strategic thinking to build and mature enterprise data protection capabilities across Microsoft 365, Azure, endpoints, cloud applications, and emerging AI technologies. This role is responsible for translating security and regulatory requirements into effective technical controls, developing enterprise-wide policies and standards, leading complex implementations, and driving continuous improvements through automation, analytics, and operational excellence. The engineer serves as the technical lead for high-impact initiatives, providing architecture guidance, troubleshooting complex issues, mentoring engineers, and establishing best practices for protecting sensitive data throughout its lifecycle.
As a key member of the cybersecurity organization, the Microsoft Purview and Data Protection Engineer partners with cross-functional teams to identify and reduce data protection risks, investigate complex security events, and enhance the organization's overall security posture. The role requires a proactive, innovation-focused mindset with a strong emphasis on automation, operational efficiency, and emerging technologies, including AI-powered security capabilities. The ideal candidate is passionate about solving complex technical challenges, influencing enterprise security strategy through technical expertise, and delivering resilient, scalable data protection solutions that support business objectives while maintaining the highest standards of information security and regulatory compliance.
In-Office Requirement: 4 days per week
Primary Responsibilities
Core Responsibilities
- Assessing firm data governance and compliance environments and developing recommendations for Microsoft Purview capabilities, including Data Loss Prevention, Compliance Manager, and Information Protection.
- Designing and implementing Microsoft Purview solutions to support data classification, labeling, retention, investigation, and governance requirements across enterprise environments.
- Performing technical health checks, discovery, and remediation activities for Microsoft Purview deployments, including audit, privileged access, and policy configuration reviews.
- Supporting proof of concept, deployment, integration, and post-implementation activities for Microsoft Purview and adjacent Microsoft security and compliance technologies.
Microsoft Purview - 50%
- Expert knowledge of Microsoft Purview Data Loss Prevention (DLP), Insider Risk Management, and Information Protection.
- Experience designing, deploying, and administering Microsoft Purview policies across Microsoft 365, Windows endpoints, Exchange Online, SharePoint Online, OneDrive, Microsoft Teams, and supported cloud applications.
- Strong understanding of Microsoft Purview architecture, licensing, role-based administration, and compliance portal configuration.
- Experience integrating Microsoft Purview with Microsoft Defender, Microsoft Entra ID, Microsoft Sentinel, and other Microsoft security technologies.
Data Loss Prevention DLP - 30%
- Design, implement, and maintain enterprise DLP policies to prevent unauthorized disclosure of sensitive information.
- Develop DLP controls for email, endpoint devices, cloud applications, Microsoft Teams, SharePoint, OneDrive, and web uploads.
- Configure policy tips, user notifications, incident reporting, and automated remediation workflows.
- Tune DLP policies to reduce false positives while maintaining effective protection.
- Experience using Sensitive Information Types (SITs), Exact Data Match (EDM), trainable classifiers, and custom classifiers.
Data Security Posture Management (DSPM) - 20%
- Experience implementing or supporting Microsoft Purview Data Security Posture Management (DSPM).
- Assess organizational data exposure and identify risks across Microsoft 365, Azure, and connected SaaS platforms.
- Interpret DSPM recommendations and translate them into actionable DLP, Insider Risk, and Information Protection controls.
- Monitor data security posture metrics and continuously improve policy coverage and risk reduction.
Requirements
Education & Certificates
- Bachelor's degree, required
- Concentration in cybersecurity, computer science, information systems, engineering or a related discipline, or equivalent relevant professional experience.
- Advanced degree in a related discipline is preferred.
Preferred Qualifications
- Microsoft SC-400: Information Protection Administrator Associate.
- Microsoft SC-401: Information Security Administrator (or equivalent current certification).
- Microsoft SC-100: Cybersecurity Architect Expert (preferred).
- Experience with Microsoft Defender XDR, Microsoft Sentinel, Microsoft Entra ID, and Microsoft 365 E5 Security.
- Experience implementing AI governance and protecting Microsoft 365 Copilot and other AI services using Microsoft Purview.
Competencies & Attributes
- Data Protection Concepts
- Strong understanding of enterprise data protection principles, including:
- Data Loss Prevention (DLP)
- Data Security Posture Management (DSPM)
- Data Classification
- Data Discovery
- Data Governance
- Information Protection
- Sensitivity Labels
- Data Lifecycle Management
- Encryption technologies
- Least Privilege and Zero Trust security models
- Knowledge of structured and unstructured data protection strategies.
- Strong understanding of enterprise data protection principles, including:
- Information Protection
- Design and Manage Microsoft Purview Sensitivity Labels and Label Policies.
- Configure automatic and recommended labeling.
- Implement encryption and rights management for sensitive corporate information.
- Support secure collaboration while protecting confidential data.
- Monitoring and Incident Response
- Monitor DLP and Insider Risk alerts and perform root cause analysis.
- Investigate policy violations and coordinate remediation efforts.
- Develop dashboards and reports to measure program effectiveness.
- Identify opportunities for automation and operational efficiency.
- Compliance & Governance
- Familiarity with regulatory and industry frameworks including:
- GDPR
- CCPA
- HIPAA
- PCI DSS
- SOX
- NIST
- ISO 27001
- Ability to align technical controls with compliance requirements.
- Familiarity with regulatory and industry frameworks including:
Benefits/Compensation
The compensation range for this role is specific to Washington, DC and takes into account a wide range of factors including but not limited to the skill sets required/preferred; prior experience and training; licenses and/or certifications.
The anticipated base salary range for this role is $160,000 to $180,000.
In addition to the base salary, the hired professional will enjoy a comprehensive benefits package spanning retirement benefits, health insurance, life insurance and disability, paid time off, paid holidays, family planning benefits and various wellness programs. Additionally, the hired professional may also be eligible to participate in an annual discretionary incentive program, the award of which will be dependent on various factors, including, without limitation, individual and organizational performance.
Due to the high volume of candidates, please be advised that only candidates selected to interview will be contacted by Carlyle.
About Us:
The Carlyle Group (NASDAQ: CG) is a global investment firm with $475 billion of assets under management, across 678 investment vehicles as of March 31, 2026. Founded in 1987 in Washington, DC, Carlyle has grown into one of the world's largest and most successful investment firms, with more than 2,500 professionals operating in 28 offices in North America, Europe, the Middle East, Asia and Australia.
Carlyle’s purpose is to connect people, ideas, and capital to fuel growth for companies and performance for investors, which range from public and private pension funds to wealthy individuals and families to sovereign wealth funds, unions and corporations. Carlyle invests across three segments – Global Private Equity, Global Credit and Carlyle AlpInvest – and has deep expertise across industries, markets, and geographies.
At Carlyle, we believe that a wide spectrum of experiences and viewpoints drives performance and success. Our CEO, Harvey Schwartz, has stated that, "To build better businesses and create value for all of our stakeholders, we are focused on assembling leadership teams with the strongest insights from a range of perspectives." Reflecting this view, emphasis is placed on development, retention and inclusion through our internal processes and seven Employee Resource Groups (ERGs). We cultivate a culture where ideas are openly shared and challenged, connecting diverse expertise and perspectives to drive enduring value.