Job description
About the job Data Security & Compliance Team Lead
Company Overview:
Our client is a global Microsoft Cloud Solutions Partner delivering digital transformation, cybersecurity, data and managed services. The group is headquartered across the UAE (Dubai), with its largest and most technical team based in Lebanon, operations established in London over the past two years, and early-stage market entry underway in the US.
Job Summary:
Our client is seeking a skilled Data Security & Compliance Specialist to lead the implementation of data security, classification, retention, and governance policies using Microsoft Purview for customers across the MEA region. The ideal candidate will have at least 4 years of focused experience in the data security field, including a minimum of 2 years of hands-on experience with Microsoft Purview, specifically in Data Loss Prevention, Data Classification, Cloud Access Security Broker, and governance capabilities such as retention policies, Insider Risk Management, and Records Management.
This role involves overseeing at least one team member, with potential for expanded leadership responsibilities. Strong expertise in Microsoft Purview is required, and experience with third-party data security solutions is highly valued, making this an excellent opportunity for professionals with a diverse security background. Familiarity with MDM & MAM solutions, particularly Microsoft Intune, as well as conditional access policies is a plus. This position offers a dynamic environment with opportunities for growth and leadership in the data security domain.
Key Responsibilities:
1. Data Security & Governance Implementation:
- Design, implement, and optimize data security solutions using Microsoft Purview or other leading DLP and data governance tools.
- Develop and enforce DLP, Insider Risk Management, DSPM for AI and CASB policies to prevent unauthorized data access and ensure compliance.
- Implement data classification and labelling strategies to enhance data protection.
- Define and manage data retention policies in alignment with regulatory and business requirements.
- Deploy and manage AIP on-premises scanner to classify and protect on-premises data.
- Integrate CASB with on-premises firewalls to strengthen security controls and enhance visibility into both cloud and on-premises environments.
- Lead the implementation and configuration of Microsoft Priva and Microsoft Purview Data Map.
- Ensure compliance with industry regulations such as GDPR, NCA, and ISO 27001.
- Support Data Security Posture Management (DSPM) initiatives by assessing risks, monitoring data flows, and optimizing security policies to enhance data visibility, governance, and protection.
- Build templates and automation for Data Security & Governance Implementation, ensuring consistency and efficiency in deployments.
- Automate policy deployments and security configurations using available methods such as PowerShell, APIs, and Microsoft Security & Compliance tools.
- Deploy MDM, MAM, and Conditional Access policies to address security gaps and enhance access controls.
- Oversee the implementation of security-related projects, from initial scoping to post-deployment support, ensuring timely and budget-compliant execution.
- Develop High-Level Designs (HLD) and Low-Level Designs (LLD) for project implementation, assess customer environments, and create RFIs and IRLs as needed.
2. Monitoring, Incident Response, and Optimization:
- Monitor and respond to data security incidents, ensuring proper investigation and resolution.
- Analyze data security risks and implement best practices to mitigate threats.
- Optimize security policies and controls based on evolving business needs.
3. Team Supervision & Cross-Functional Collaboration:
- Supervise at least two team members, with potential for increased leadership responsibilities.
- Work closely with cross-functional teams and customers to align security policies with business objectives and ensure seamless implementation.
- Collaborate with stakeholders to continuously enhance security posture and governance policies in response to evolving business needs.
- Deliver end-user and administrator workshops to ensure proper understanding and adoption of data security, classification, governance policies, and compliance tools.
4. Documentation & Project Support:
- Contribute to Scope of Work (SOW) and project scoping, defining clear deliverables and implementation roadmaps.
- Develop and maintain implementation documentation, end-user guides, and administrative manuals to support technology adoption.
- Ensure the availability and functionality of a technical test environment for internal testing and experimentation with new technologies, coordinating maintenance, updates, and enhancements as needed.
Qualifications & Experience:
Education:
- Bachelor's degree in computer science, Information Technology, Cybersecurity, or a related field.
Experience:
- Minimum of 4 years of experience in implementing data security, compliance, and governance solutions, with a strong focus on Microsoft Purview.
- At least 2 years in a supervisory role, overseeing the implementation and delivery of data protection and compliance initiatives.
- Hands-on experience implementing Microsoft Purview Information Protection solutions, including DLP, data classification, retention policies, and regulatory compliance.
- Experience implementing data governance, risk management, and regulatory compliance requirements aligned with frameworks such as GDPR, NCA, and ISO 27001.
- Extensive experience working with Microsoft Purview Compliance Portal, Insider Risk Management, eDiscovery, and Audit.
- Experience with Microsoft Purview Data Loss Prevention (DLP) policies across Microsoft 365 services, including Teams, SharePoint, OneDrive, and Exchange Online.
- Strong understanding of Microsoft Information Protection (MIP)for labeling, encryption, and rights management.
- Familiarity with Microsoft Defender for Cloud Apps for data security monitoring and threat detection.
- Knowledge of Microsoft Intune for Mobile Device Management (MDM) & Mobile Application Management (MAM)and how it integrates with Conditional Access policies for secure access control.
- Ability to effectively communicate data protection strategies, compliance requirements, and risk management policies to both technical and non-technical stakeholders.
Certifications:
Required Certifications:
- GIAC Certified Data Protection or an equivalent certification.
- Vendor certifications in DLP, Data Classification, Litigation Holds, or governance tools.
- Preferred Certifications as below:
- Microsoft Certified: Information Protection Administrator Associate (SC-400)
- Cybersecurity Architect Expert (SC-100)
Skills:
- Strong leadership and team management capabilities.
- Excellent project management skills.
- Knowledge in security solution design and architecture.
- Proficiency in data security tools such as DLP, Data Classification, and CASB.
- Strong analytical and problem-solving abilities, with attention to detail and the ability to work under pressure.
- Effective communication and customer engagement skills.
- Thorough understanding of quality assurance practices and methodologies.
- Hands-on experience in implementing Microsoft Purview solutions.
- Proven experience in configuring and troubleshooting security solutions.
- Commitment to staying updated with emerging data security trends, risks, technologies, and best practices to enhance protection and compliance.
وصف الوظيفة
حول وظيفة قائد فريق أمان البيانات والامتثال
نظرة عامة على الشركة:
عميلنا شريك عالمي في حلول سحابة مايكروسوفت يقدم التحول الرقمي، الأمن السيبراني، البيانات والخدمات المدارة. المجموعة تتخذ من الإمارات مقراً لها (دبي)، مع أكبر فريق تقني ومركز لها في لبنان، وتُدير عملياتها في لندن خلال العامين الماضيين، وتدخل سوق الولايات المتحدة في مراحل مبكرة.
ملخص الوظيفة:
يسعى عميلنا إلى متخصص متمرس في أمان البيانات والامتثال لقيادة تنفيذ سياسات أمان البيانات والتصنيف والاحتفاظ والحوكمة باستخدام مايكروسوفت بريفيو للعملاء عبر منطقة الشرق الأوسط وأفريقيا. يجب أن يتمتع المرشح المثالي بخبرة مركّزة لا تقل عن 4 سنوات في مجال أمان البيانات، بما في ذلك ما لا يقل عن سنتين من الخبرة العملية مع مايكروسوفت بريفيو، خاصة في منع فقدان البيانات (DLP)، وتصنيف البيانات، وموفِّر أمن الوصول إلى السحابة (CASB)، وقدرات الحوكمة مثل سياسات الاحتفاظ، وإدارة مخاطر الداخل، وإدارة السجلات.
هذه الوظيفة تتضمن الإشراف على على الأقل عضو فريق واحد، مع إمكانية توسيع المسؤوليات القيادية. مطلوب خبرة قوية في مايكروسوفت بريفيو، وتُقدَّر الخبرة مع حلول أمان البيانات من طرف ثالث بشكل كبير، مما يجعلها فرصة ممتازة للمحترفين ذوي الخلفيات الأمنية المتنوعة. كما أن الإلمام بحلول إدارة الأجهزة المحمولة (MDM) وMAM، وخاصة مايكروسوفت إنتون، بجانب سياسات الوصول الشرطي يعد ميزة. تقدم هذه الوظيفة بيئة ديناميكية مع فرص للنمو والقيادة في مجال أمان البيانات.
المسؤوليات الأساسية:
1. تنفيذ أمان البيانات والحوكمة:
- تصميم وتنفيذ وتحسين حلول أمان البيانات باستخدام مايكروسوفت بريفيو أو أدوات الحوكمة والـDLP الرائدة الأخرى.
- وضع القواعد وتنفيذ سياسات DLP وإدارة مخاطر الداخل وDSPM لـ AI وCASB لمنع الوصول غير المصرح به للبيانات وضمان الامتثال.
- تنفيذ استراتيجيات التصنيف والتسمية للبيانات لتعزيز حماية البيانات.
- تعريف وإدارة سياسات الاحتفاظ بالبيانات بما يتوافق مع المتطلبات التنظيمية والتجارية.
- نشر وإدارة ماسح AIP للمحليين لتصنيف وحماية البيانات المحلية.
- دمج CASB مع الجدران النارية المحلية لتعزيز ضوابط الأمان ووضوح الرؤية في البيئات السحابية والمحلية.
- قيادة تنفيذ وتكوين Microsoft Priva و Microsoft Purview Data Map.
- ضمان الامتثال للوائح الصناعة مثل GDPR وNCA وISO 27001.
- دعم مبادرات إدارة مواضع أمان البيانات (DSPM) من خلال تقييم المخاطر ومراقبة تدفقات البيانات وتحسين سياسات الأمان لتعزيز الرؤية والحوكمة والحماية.
- بناء القوالب والتشغيل الآلي لتنفيذ أمان البيانات والحوكمة، بما يضمن الاتساق والكفاءة في النُهج.
- أتمتة نشر السياسات وتكوينات الأمان باستخدام الطرق المتاحة مثل PowerShell وواجهات البرمجة وأدوات أمان وامتثال مايكروسوفت.
- نشر سياسات MDM وMAM والوصول الشرطي لمعالجة الثغرات الأمنية وتحسين ضوابط الوصول.
- الإشراف على تنفيذ مشاريع الأمن من التحديد الأولي حتى الدعم بعد النشر، مع الالتزام بالجدول الزمني والميزانية.
- تطوير التصاميم عالية المستوى (HLD) والتصاميم منخفضة المستوى (LLD) لمشروع التنفيذ، وتقييم بيئات العملاء، وإنشاء RFIs وIRLs عند الحاجة.
2. الرصد والاستجابة للحوادث والتحسين:
- رصد والاستجابة لحوادث أمان البيانات، والتأكد من التحقيق والحل الصحيح.
- تحليل مخاطر أمان البيانات وتبني أفضل الممارسات لتخفيف التهديدات.
- تحسين سياسات وأطر الأمان والتحكمات استناداً إلى احتياجات العمل المتغيرة.
3. الإشراف على الفريق والتعاون عبر الوظائف:
- إشراف على ما لا يقل عن عضوين في الفريق، مع إمكانية زيادة المسؤوليات القيادية.
- العمل بشكل وثيق مع فرق متعددة الوظائف والعملاء لتوافق سياسات الأمان مع أهداف العمل وضمان تنفيذ سلس.
- التعاون مع أصحاب المصلحة لتعزيز الوضع الأمني بصفة مستمرة وتحديث سياسات الحوكمة استجابةً لاحتياجات العمل المتطورة.
- تقديم ورش عمل للمستخدمين النهائيين والمسؤولين لضمان الفهم السليم وتبني سياسات أمان البيانات والتصنيف والحوكمة وأدوات الامتثال.
4. التوثيق ودعم المشروع:
- المساهمة في نطاق العمل (SOW) وتحديد نطاق المشروع وتحديد نتائج تنفيذ واضحة وخطط طريق.
- تطوير والحفاظ على وثائق التنفيذ ودليل المستخدم النهائي وأدلة الإدارة لدعم اعتماد التكنولوجيا.
- ضمان توافر ووظائف بيئة اختبار تقنية للاختبار الداخلي وتجربة التقنيات الجديدة، وتنسيق الصيانة والتحديثات والتحسينات حسب الحاجة.
المؤهلات والخبرة:
التعليم:
- درجة البكالوريوس في علوم الحاسوب أو تكنولوجيا المعلومات أو الأمن السيبراني أو مجال ذي صلة.
الخبرة:
- خبرة لا تقل عن 4 سنوات في تطبيق أمان البيانات والامتثال وحلول الحوكمة، مع تركيز قوي على مايكروسوفت بريفيو.
- سنتان على الأقل في دور إشرافي، والإشراف على تنفيذ وتقديم مبادرات حماية البيانات والامتثال.
- خبرة عملية في تنفيذ حلول معلومات حماية مايكروسوفت (MIP) بما في ذلك DLP والتصنيف والاحتفاظ والامتثال التنظيمي.
- خبرة في تنفيذ الحوكمة وإدارة المخاطر والمتطلبات التنظيمية المتوافقة مع أطر GDPR وNCA وISO 27001.
- خبرة واسعة في العمل مع بوابة امتثال مايكروسوفت بريفيو، وإدارة مخاطر الداخل، وeDiscovery، والتدقيق.
- خبرة مع سياسات DLP في مايكروسوفت بريفيو عبر خدمات Microsoft 365 بما فيها Teams وSharePoint وOneDrive وExchange Online.
- فهم قوي لـ Microsoft Information Protection (MIP) للوسم والتشفير وإدارة الحقوق.
- الإلمام بـ Microsoft Defender for Cloud Apps لرصد أمان البيانات وكشف التهديدات.
- معرفة بـ Microsoft Intune لإدارة الأجهزة المحمولة (MDM) و(MAM) وكيفية تكامله مع سياسات الوصول الشرطي لضمان وصول آمن.
- القدرة على التواصل بشكل فعال لاستراتيجيات حماية البيانات ومتطلبات الامتثال وسياسات إدارة المخاطر مع أصحاب المصلحة التقنيين وغير التقنيين.
الشهادات:
الشهادات المطلوبة:
- شهادة GIAC لحماية البيانات أو ما يعادلها.
- شهادات من الشركات في DLP والتصنيف والحجز القضائي أو أدوات الحوكمة.
- الشهادات المفضلة كما يلي:
- Microsoft Certified: Information Protection Administrator Associate (SC-400)
- Cybersecurity Architect Expert (SC-100)
المهارات:
- قدرات قيادية قوية وإدارة فريق.
- مهارات إدارة المشاريع بشكل ممتازة.
- معرفة في تصميم حلول الأمان والهندسة المعمارية.
- الكفاءة في أدوات أمان البيانات مثل DLP والتصنيف وCASB.
- قدرات تحليلية وحل مشكلات قوية، مع الانتباه للتفاصيل والقدرة على العمل تحت الضغط.
- مهارات تواصل ومشاركة مع العملاء بشكل فعال.
- فهم دقيق لممارسات وضوابط ضمان الجودة والمنهجيات.
- خبرة عملية في تنفيذ حلول مايكروسوفت بريفيو.
- خبرة مثبتة في تكوين واستكشاف حلول الأمان.
- الالتزام بالبقاء على اطلاع باتجاهات أمان البيانات الناشئة والمخاطر والتقنيات وأفضل الممارسات لتعزيز الحماية والامتثال.