Job description
About the job Data Security & Compliance Lead
Company Overview:
Our client is a global Microsoft Cloud Solutions Partner delivering digital transformation, cybersecurity, data and managed services. The group is headquartered across the UAE (Dubai), with its largest and most technical team based in Lebanon, operations established in London over the past two years, and early-stage market entry underway in the US.
Job Summary:
Our client is seeking a skilled Data Security & Compliance Specialist to lead the implementation of data security, classification, retention, and governance policies using Microsoft Purview for customers across the MEA region. The ideal candidate will have at least 4 years of focused experience in the data security field, including a minimum of 2 years of hands-on experience with Microsoft Purview, specifically in Data Loss Prevention, Data Classification, Cloud Access Security Broker, and governance capabilities such as retention policies, Insider Risk Management, and Records Management.
This role involves overseeing at least one team member, with potential for expanded leadership responsibilities. Strong expertise in Microsoft Purview is required, and experience with third-party data security solutions is highly valued, making this an excellent opportunity for professionals with a diverse security background. Familiarity with MDM & MAM solutions, particularly Microsoft Intune, as well as conditional access policies is a plus. This position offers a dynamic environment with opportunities for growth and leadership in the data security domain.
Key Responsibilities:
1. Data Security & Governance Implementation:
- Design, implement, and optimize data security solutions using Microsoft Purview or other leading DLP and data governance tools.
- Develop and enforce DLP, Insider Risk Management, DSPM for AI and CASB policies to prevent unauthorized data access and ensure compliance.
- Implement data classification and labelling strategies to enhance data protection.
- Define and manage data retention policies in alignment with regulatory and business requirements.
- Deploy and manage AIP on-premises scanner to classify and protect on-premises data.
- Integrate CASB with on-premises firewalls to strengthen security controls and enhance visibility into both cloud and on-premises environments.
- Lead the implementation and configuration of Microsoft Priva and Microsoft Purview Data Map.
- Ensure compliance with industry regulations such as GDPR, NCA, and ISO 27001.
- Support Data Security Posture Management (DSPM) initiatives by assessing risks, monitoring data flows, and optimizing security policies to enhance data visibility, governance, and protection.
- Build templates and automation for Data Security & Governance Implementation, ensuring consistency and efficiency in deployments.
- Automate policy deployments and security configurations using available methods such as PowerShell, APIs, and Microsoft Security & Compliance tools.
- Deploy MDM, MAM, and Conditional Access policies to address security gaps and enhance access controls.
- Oversee the implementation of security-related projects, from initial scoping to post-deployment support, ensuring timely and budget-compliant execution.
- Develop High-Level Designs (HLD) and Low-Level Designs (LLD) for project implementation, assess customer environments, and create RFIs and IRLs as needed.
2. Monitoring, Incident Response, and Optimization:
- Monitor and respond to data security incidents, ensuring proper investigation and resolution.
- Analyze data security risks and implement best practices to mitigate threats.
- Optimize security policies and controls based on evolving business needs.
3. Team Supervision & Cross-Functional Collaboration:
- Supervise at least two team members, with potential for increased leadership responsibilities.
- Work closely with cross-functional teams and customers to align security policies with business objectives and ensure seamless implementation.
- Collaborate with stakeholders to continuously enhance security posture and governance policies in response to evolving business needs.
- Deliver end-user and administrator workshops to ensure proper understanding and adoption of data security, classification, governance policies, and compliance tools.
4. Documentation & Project Support:
- Contribute to Scope of Work (SOW) and project scoping, defining clear deliverables and implementation roadmaps.
- Develop and maintain implementation documentation, end-user guides, and administrative manuals to support technology adoption.
- Ensure the availability and functionality of a technical test environment for internal testing and experimentation with new technologies, coordinating maintenance, updates, and enhancements as needed.
Qualifications & Experience:
Education:
- Bachelor's degree in computer science, Information Technology, Cybersecurity, or a related field.
Experience:
- Minimum of 4 years of experience in implementing data security, compliance, and governance solutions, with a strong focus on Microsoft Purview.
- At least 2 years in a supervisory role, overseeing the implementation and delivery of data protection and compliance initiatives.
- Hands-on experience implementing Microsoft Purview Information Protection solutions, including DLP, data classification, retention policies, and regulatory compliance.
- Experience implementing data governance, risk management, and regulatory compliance requirements aligned with frameworks such as GDPR, NCA, and ISO 27001.
- Extensive experience working with Microsoft Purview Compliance Portal, Insider Risk Management, eDiscovery, and Audit.
- Experience with Microsoft Purview Data Loss Prevention (DLP) policies across Microsoft 365 services, including Teams, SharePoint, OneDrive, and Exchange Online.
- Strong understanding of Microsoft Information Protection (MIP)for labeling, encryption, and rights management.
- Familiarity with Microsoft Defender for Cloud Apps for data security monitoring and threat detection.
- Knowledge of Microsoft Intune for Mobile Device Management (MDM) & Mobile Application Management (MAM)and how it integrates with Conditional Access policies for secure access control.
- Ability to effectively communicate data protection strategies, compliance requirements, and risk management policies to both technical and non-technical stakeholders.
Certifications:
Required Certifications:
- GIAC Certified Data Protection or an equivalent certification.
- Vendor certifications in DLP, Data Classification, Litigation Holds, or governance tools.
- Preferred Certifications as below:
- Microsoft Certified: Information Protection Administrator Associate (SC-400)
- Cybersecurity Architect Expert (SC-100)
Skills:
- Strong leadership and team management capabilities.
- Excellent project management skills.
- Knowledge in security solution design and architecture.
- Proficiency in data security tools such as DLP, Data Classification, and CASB.
- Strong analytical and problem-solving abilities, with attention to detail and the ability to work under pressure.
- Effective communication and customer engagement skills.
- Thorough understanding of quality assurance practices and methodologies.
- Hands-on experience in implementing Microsoft Purview solutions.
- Proven experience in configuring and troubleshooting security solutions.
- Commitment to staying updated with emerging data security trends, risks, technologies, and best practices to enhance protection and compliance.
وصف الوظيفة
عن وظيفة قائد أمان البيانات والامتثال
نظرة عامة على الشركة:
عميلنا هو شريك عالمي في حلول Microsoft Cloud يوفر التحول الرقمي، الأمن السيبراني، البيانات والخدمات المُدارة. يقع مقر المجموعة عبر الإمارات العربية المتحدة (دبي)، مع وجود أكبر فريقها وأكثره تقنيًا في لبنان، وتأسيس عمليات في لندن خلال العامين الماضيين، وبدء دخول السوق مبكرًا في الولايات المتحدة.
ملخص الوظيفة:
يبحث عميلنا عن متخصص موهوب في أمان البيانات والامتثال لقيادة تنفيذ سياسات أمان البيانات والتصنيف والاحتفاظ والحوكمة باستخدام Microsoft Purview للعملاء عبر منطقة الشرق الأوسط وأفريقيا. يجب أن يمتلك المرشح المثالي خبرة مركزة لا تقل عن 4 سنوات في مجال أمان البيانات، بما في ذلك سنتين على الأقل من الخبرة العملية مع Microsoft Purview، وتحديدًا في منع فقدان البيانات، وتصنيف البيانات، ووسيط أمن وصول السحابة، وقدرات الحوكمة مثل سياسات الاحتفاظ، وإدارة مخاطر الداخل، وإدارة السجلات.
هذا الدور يتضمن إشرافًا على لاعب أو أكثر ضمن الفريق، مع إمكانية توسع المسؤوليات القيادية. مطلوب خبرة قوية في Microsoft Purview، وتُقدَّر الخبرة مع حلول أمان البيانات من طرف ثالث عاليًا، مما يجعل هذه فرصة ممتازة للمحترفين الذين لديهم خلفية أمان متنوعة. كما أن الإلمام بحلول MDM & MAM، خاصة Microsoft Intune، وسياسات الوصول الشرطي يعتبر إضافة. يوفر هذا المنصب بيئة ديناميكية مع فرص للنمو والقيادة في مجال أمان البيانات.
المسؤوليات الأساسية:
1. تطبيق أمان البيانات والحوكمة:
- تصميم وتطبيق وتحسين حلول أمان البيانات باستخدام Microsoft Purview أو أدوات الحوكمة والـ DLP الرائدة الأخرى.
- تطوير وتنفيذ سياسات DLP وإدارة مخاطر الداخل وDSPM لـ AI وCASB لمنع الوصول غير المصرح به إلى البيانات وضمان الامتثال.
- تنفيذ استراتيجيات التصنيف ووضع العلامات لتعزيز حماية البيانات.
- تحديد وإدارة سياسات الاحتفاظ بالبيانات بما يتماشى مع المتطلبات التنظيمية والتجارية.
- نشر وإدارة ماسح AIP في المواقع لتصنيف وحماية بيانات المؤسسة.
- دمج CASB مع الجدران النارية في المؤسسة لتعزيز الضوابط الأمنية وزيادة الرؤية في بيئات السحابة والمحلية.
- قيادة تنفيذ وتكوين Microsoft Priva وMicrosoft Purview Data Map.
- الامتثال للوائح الصناعة مثل GDPR، وNCA، وISO 27001.
- دعم مبادرات إدارة وضع أمان البيانات (DSPM) من خلال تقييم المخاطر، ورصد تدفقات البيانات، وتحسين سياسات الأمان لزيادة الرؤية والحوكمة والحماية.
- بناء قوالب وأتمتة لتنفيذ أمان البيانات والحوكمة، لضمان الاتساق والكفاءة في النشر.
- أتمتة نشر السياسات وتكوينات الأمان باستخدام الطرق المتاحة مثل PowerShell وواجهات برمجة التطبيقات وأدوات Microsoft Security & Compliance.
- نشر سياسات MDM و MAM والوصول الشرطي لمعالجة فجوات الأمان وتعزيز ضوابط الوصول.
- الإشراف على تنفيذ مشاريع متعلقة بالأمان من التحديد الأولي للنطاق حتى الدعم ما بعد النشر، مع ضمان التنفيذ ضمن الجدول والميزانية.
- تطوير تصاميم عالية المستوى (HLD) وتخطيطات منخفضة المستوى (LLD) لتنفيذ المشروع، وتقييم بيئات العملاء، وإنشاء RFIs وIRLs حسب الحاجة.
2. الرصد والاستجابة للحوادث والتحسين:
- رصد والاستجابة لحوادث أمان البيانات، وضمان التحقيق والحل السليم.
- تحليل مخاطر أمان البيانات وتنفيذ أفضل الممارسات للحد من التهديدات.
- تحسين سياسات وأنظمة الأمان بناءً على احتياجات العمل المتطورة.
3. الإشراف على الفريق والتعاون عبر الوظائف:
- الإشراف على ما لا يقل عن عضوين من الفريق، مع إمكانية زيادة المسؤوليات القيادية.
- العمل عن كثب مع فرق عبر وظائف والعملاء لمحاذاة سياسات الأمان مع أهداف الأعمال وضمان تنفيذ سلس.
- التعاون مع أصحاب المصلحة لتعزيز وضع الأمان والحوكمة باستمرار استجابة لاحتياجات الأعمال المتطورة.
- تنظيم ورش عمل للمستخدمين النهائيين والمسؤولين لضمان الفهم الصحيح وتبني سياسات أمان البيانات والتصنيف والحوكمة وأدوات الامتثال.
4. التوثيق ودعم المشروع:
- المساهمة في نطاق العمل وتحديد تسليمات وخطط تنفيذ واضحة.
- تطوير والحفاظ على وثائق التنفيذ، أدلة المستخدم النهائي، وكتيبات الإدارة لدعم اعتياد التقنية.
- ضمان توفر ووظائف بيئة اختبار تقنية للاختبار والتجربة الداخلية مع تقنيات جديدة، وتنسيق الصيانة والتحديثات والتحسينات حسب الحاجة.
المؤهلات والخبرة:
التعليم:
- درجة البكالوريوس في علوم الكمبيوتر، تكنولوجيا المعلومات، الأمن السيبراني، أو مجال ذي صلة.
الخبرة:
- الحد الأدنى من 4 سنوات من الخبرة في تنفيذ حلول أمان البيانات والامتثال والحوكمة، مع تركيز قوي على Microsoft Purview.
- ما لا يقل عن سنتين في دور إشرافي، overseeing تطبيق وتنفيذ مبادرات حماية البيانات والامتثال.
- خبرة عملية في تنفيذ حلول حماية المعلومات من Microsoft Purview، بما في ذلك DLP،تصنيف البيانات، سياسات الاحتفاظ، والامتثال التنظيمي.
- خبرة في تنفيذ الحوكمة والrisks والامتثال التنظيمي وفق أطر مثل GDPR وNCA وISO 27001.
- خبرة واسعة في العمل مع Microsoft Purview Compliance Portal وInsider Risk Management وeDiscovery وAudit.
- خبرة مع سياسات Microsoft Purview Data Loss Prevention (DLP) عبر خدمات Microsoft 365، بما في ذلك Teams وSharePoint وOneDrive وExchange Online.
- فهم قوي لـ Microsoft Information Protection (MIP) للتوسيم والتشفير وإدارة الحقوق.
- إلمام بـ Microsoft Defender for Cloud Apps لرصد أمان البيانات والكشف عن التهديدات.
- معرفة بـ Microsoft Intune لإدارة الأجهزة المحمولة (MDM) وإدارة تطبيقات المحمول (MAM) وكيفية تكامله مع سياسات الوصول المشروط للوصول الآمن.
- القدرة على التواصل بفاعلية لاستراتيجيات حماية البيانات ومتطلبات الامتثال وسياسات إدارة المخاطر مع كل من أصحاب المصلحة الفنيين وغير الفنيين.
الشهادات:
الشهادات المطلوبة:
- GIAC Certified Data Protection أو شهادة مكافئة.
- شهادات من البائعين في DLP، تصنيف البيانات، الاحتجاز القضائي، أو أدوات الحوكمة.
- الشهادات المفضلة كما يلي:
- Microsoft Certified: Information Protection Administrator Associate (SC-400)
- Cybersecurity Architect Expert (SC-100)
المهارات:
- قدرات قيادة وإدارة فريق قوية.
- مهارات إدارة المشاريع بشكل ممتازة.
- معرفة بتصميم وبناء حلول الأمان والهيكلة.
- إتقان أدوات أمان البيانات مثل DLP والتصنيف والتحكم في CASB.
- قدرات تحليلية وحل المشكلات مع الانتباه للتفاصيل والقدرة على العمل تحت الضغط.
- مهارات تواصل وتفاعل مع العملاء بشكل فعال.
- فهم شامل لممارسات منهجية ضمان الجودة وأساليبها.
- خبرة عملية في تنفيذ حلول Microsoft Purview.
- خبرة مثبتة في تكوين واستكشاف حلول الأمان.
- الالتزام بالبقاء على اطلاع باتجاهات أمان البيانات المتجددة والمخاطر والتقنيات وأفضل الممارسات لتعزيز الحماية والامتثال.