Data Security Specialist - Microsoft Purview
JMR Software (Pty) Ltd · JHB
Stop applying one at a time.
JobAlertsZA auto-applies to South African jobs like this one for you, overnight. Upload your CV once — we do the applying.
Start free — we apply for you →Introduction
Own and evolve the Client's data security and protection controls using Microsoft
Purview and related Microsoft capabilities, ensuring that sensitive healthcare and
financial data is classified, protected, monitored and governed in line with POPIA,
company standards and applicable regulatory requirements. This role sits at
the intersection of data security, compliance and risk, translating regulatory
obligations into practical, operational Purview controls.
Duties & Responsibilities
Design and maintain data security policies in Microsoft Purview: sensitivity
labels, data classification schemas, DLP policies, retention policies, records
management and insider risk management across M365 workloads and
endpoints.
- Perform data discovery and exposure assessments using a Data Security
Posture Management (DSPM) approach; identify sensitive data locations and
refine protection policies to reduce exposure.
- Configure, tune and monitor DLP, information protection and insider risk
policies; analyse alerts, drive remediation and manage exception processes
to minimise business disruption.
- Integrate Purview with Defender for Cloud Apps, Sentinel and Defender
suite to ensure data security events contribute to overall threat detection,
investigation and response.
- Collaborate with Privacy, Legal, Risk and business data owners to translate
POPIA, healthcare and financial sector regulatory requirements into
concrete Purview policies and data lifecycle rules.
- Define and report data security KPIs and metrics: classified data coverage,
DLP incident trends, sensitivity label adoption, high-risk data exposure, and
insider risk case metrics; support audits and Group cyber forums.
- Partner with the IAM Security Engineer and Senior M365/Azure Lead to
ensure AI/Copilot access, cloud data movement and identity-driven access
controls align with data classification and protection requirements.
- Develop user guidance, data handling training and DLP exception and
incident response playbooks for the business.
- Contribute to AI security governance by defining how classified and
regulated data may be used within AI-enabled tools and ensuring Purview
controls extend into AI workloads.
Desired Experience & Qualification
Skills & Experience
- 4–8+ years in data security, information protection, compliance or privacy in
a Microsoft 365/Azure environment.
- Hands-on experience designing and operating Purview DLP, sensitivity
labels and data classification in a regulated industry (financial services,
healthcare or equivalent).
- Strong knowledge of POPIA and its practical implications for data
classification, processing and breach notification in a South African context.
- Ability to analyse DLP and insider risk alerts, distinguish noise from genuine
risk, and design workable controls and exception processes in collaboration
with business teams.
Qualifications & Certifications
Required
- Relevant degree, diploma or equivalent practical experience in Information
Technology, Information Security, Compliance or a related discipline.
- SC-400 (Microsoft Information Protection and Compliance Administrator).
Preferred
- CIPP/E or equivalent privacy/data protection certification.
- ISO 27001 awareness or Lead Implementer advantageous.
- Continuous professional development in Microsoft Purview, DSPM and data
governance capabilities.
Reporting Line & Key Stakeholders
- Reports to: Senior Manager, Cyber Operations & SOC.
- Key internal stakeholders: Data Protection Officer/Privacy/Legal, Risk and
Compliance, business data owners, Senior M365/Azure Lead, IAM Security
Engineer, SOC, audit and Group cyber forums.
Success Measures
- Sensitivity label adoption coverage reaching and sustaining agreed targets
across M365 workloads and endpoints.
- Reduction in high-severity DLP incidents and high-risk insider risk cases.
- Timely and accurate data security evidence for audits, POPIA compliance
reviews and Group reporting.
- Effective integration of Purview controls into AI/Copilot governance, with no
material uncontrolled data exposure events.
- Clean audit findings across data classification, DLP and information
protection controls.