Back to jobs
New

Senior Security Engineer

Remote
Build More Than Just a Career. Build Your Future.

At Vailexa, we’re not just hiring — we’re building thinkers, creators, and future leaders.

We believe in giving people the space to grow, the freedom to think, and the opportunity to create real impact from day one. If you’re someone who wants to learn fast, take ownership, and grow beyond limits, you’ll feel right at home here.

  • Client is seeking a Senior Security Engineer to support a broader enterprise data security program focused on identifying, classifying, labeling, and remediating sensitive data exposure across Microsoft 365 environments.
  • This role is not intended to participate directly in a proof-of-value or vendor evaluation effort. Instead, the resource will become part of the remediation workstream that follows discovery and classification, helping the client turn security findings into closed, documented outcomes.
  • The role will work alongside the client's internal security, DLP, and operations teams to triage findings, validate root cause, coordinate corrective action, and support closure of remediation items. The emphasis is on practical execution: understanding what data is exposed, how it should be classified or labeled, what risk it creates, and what action is needed to reduce that risk.
  • This is a core delivery resource for the overall project, with involvement beginning during data discovery, classification, tagging, labeling, and remediation planning, then increasing during remediation execution and post-deployment stabilization.
  • Program Context: This engagement supports the client's broader Enterprise Information Management and Data Security objectives. The work should be positioned as a reusable operating model for discovery, classification, labeling, policy alignment, remediation, and ongoing incident response across current and future data security channels.

 

Responsibilities

  • Support activities including data discovery, classification, tagging, labeling, risk prioritization, and remediation planning.
  • Partner with client security, DLP, SOC, and data governance teams to understand current workflows, ownership models, ticket volume, and remediation hand-offs.
  • Triage findings surfaced through data security tooling, monitoring, or validation activities and help determine the appropriate remediation path.
  • Drive remediation actions to closure, including access changes, policy adjustments, data handling updates, quarantine or containment steps, and coordination with the appropriate operational owners.
  • Coordinate with the SOC and response teams when findings indicate incident response, containment, or escalation requirements.
  • Document remediation decisions, closure evidence, recurring patterns, and operational lessons learned to support audit readiness and future-state process improvement.
  • Provide technical input into the remediation roadmap and target-state data security operating model based on findings encountered during the engagement. Ongoing / Post-Deployment
  • Continue as the primary hands-on remediation and incident-response resource — investigating false positives/negatives, adjusting behavioral baselines, and driving real findings to closure as the environment sees production traffic.
  • Remain the day-to-day working partner to Client's in-house DLP engineer for as long as the engagement continues, rather than handing remediation entirely back to the client after go-live.

 

Qualifications

  • 5+ years in security engineering, with direct hands-on experience configuring Microsoft 365 security tooling (Purview DLP, sensitivity labels, Insider Risk Management, Audit) and Entra ID.
  • Direct, hands-on remediation experience — not just detection or reporting. Able to take a Cyera or DLP finding and personally drive it to resolution: revoke access, adjust a policy, quarantine data, or take the equivalent corrective action. This is the client's top priority for this role.
  • Practical expertise in Cyera specifically (Client's enterprise-standard DSPM platform) and deep expertise in Microsoft Purview and the broader Microsoft 365 security stack.
  • Working knowledge of SIEM/SOC alerting pipelines and incident response processes — this role is a key hand-off point between DLP/DSPM detection and SOC-driven containment, so understanding both sides matters.
  • Comfort working as a peer alongside a client's existing in-house DLP engineer on shared remediation work, communicating clearly about who is handling what.
  • Demonstrated experience designing or executing controlled, purple-team-style validation exercises in an isolated test environment — not full red-team penetration testing.
  • Practical understanding of common SharePoint/OneDrive incident patterns: compromised-account exfiltration, oversharing/public-link exposure, insider data theft, ransomware via sync clients, malicious OAuth consent grants, and lateral movement via overprivileged access.
  • Ability to translate technical remediation work into clear documentation suitable for both technical and client-facing review.

 

Preferred:

  • Hands-on experience with both Cyera and Varonis — the client has indicated familiarity with both platforms is a plus, even though Cyera is the enterprise standard for this engagement.
  • Experience with UEBA/behavioral-baseline tooling specifically for insider-risk or departing-employee scenarios.
  • Familiarity with OneDrive sync-client behavior and endpoint EDR correlation for ransomware-pattern detection.
  • Relevant certifications such as GIAC/SANS (e.g., GCIA, GCIH), Microsoft SC-200, or vendor-specific DSPM certifications.
  • Prior experience embedded alongside a client's in-house security/DLP team on an ongoing remediation or hyper care basis, rather than a discrete assessment of engagement.

Ready to take the next step?

If you’re excited about this role and ready to grow with a team that values ambition, ideas, and impact — we’d love to hear from you.

👉 Apply now and start building your journey with Vailexa.

Apply for this job

*

indicates a required field

Phone
Resume/CV

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Vailexa ’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.