Data Security Specialist
New York City, NY - USA
Job Summary
The Data Security Specialist is responsible for protecting the confidentiality integrity and availability of the firms data assets across cloud and on-premises environments. This role designs implements and maintains controls that safeguard sensitive client legal and corporate information against unauthorized access loss and exfiltration including emerging risks from generative AI and large language model (LLM) usage.
- Design and operate data loss prevention (DLP) policies across email endpoints and cloud services (Microsoft Purview M365 Azure).
- Implement and tune data classification labeling and encryption frameworks aligned with firm policy and regulatory requirements.
- Manage rights management (IRM/MIP) tokenization and key management solutions.
- Design and enforce AI data leakage prevention controls governing how sensitive data is used with Microsoft 365 Copilot ChatGPT Enterprise and other GenAI/LLM tools including prompt and response monitoring sensitivity-label enforcement and blocking unsanctioned AI services.
- Investigate data security incidents perform root-cause analysis lead containment and remediation.
- Monitor SIEM CASB and DLP alerts; triage events and escalate per the incident response plan.
- Partner with the SOC and forensics teams on insider threat and exfiltration investigations.
- Detect and respond to AI-related data exposure events including sensitive data submitted to public LLMs prompt injection and shadow AI usage.
- Support compliance with GDPR CCPA NYDFS Part 500 SOC 2 and client security obligations.
- Conduct data risk assessments for new applications vendors and AI/LLM use cases.
- Maintain evidence and artifacts for internal and external audits.
- Contribute to the firms AI governance program aligning controls with frameworks such as NIST AI RMF and ISO/IEC 42001.
- Develop scripts and automations (PowerShell Python KQL) to scale data security operations.
- Integrate data security controls into CI/CD SaaS onboarding and identity workflows.
- Maintain documentation runbooks and control mappings.
Compensation: -The anticipated base salary range offered for this role will be between $140000 to 160000 and represents the firms good faith and reasonable estimate of the range of possible base compensation. Actual base compensation will be dependent upon several factors including but not limited to the candidates relevant experience performance qualifications degrees and location well as the needs of the firm.
- Bachelors degree in computer science Information Security or related field (equivalent experience accepted).
- 4 years in information security with at least 2 years focused on data protection DLP or data governance.
- In-depth hands-on experience with a range of enterprise DLP and rights management platforms with deep expertise in the Microsoft M365 stack including Microsoft Purview DLP (Exchange Online SharePoint OneDrive Teams and Endpoint DLP) Microsoft Purview Information Protection (MIP) sensitivity labels Azure Information Protection (AIP) Azure Rights Management Services (Azure RMS) Double Key Encryption (DKE) and Customer Key. Experience tuning policies authoring custom sensitive information types (SITs) trainable classifiers and integrating Purview with Defender for Cloud Apps (MCAS) is required.
- Experience with Microsoft Purview Insider Risk Management Communication Compliance eDiscovery (Premium) and Data Lifecycle Management.
- Demonstrated experience with AI data leakage prevention protecting sensitive data from exposure to generative AI and LLM services. This includes hands-on work with Microsoft Purview controls for Microsoft 365 Copilot (DSPM for AI / AI Hub Copilot interaction auditing sensitivity-label enforcement on Copilot responses) CASB/SSE-based GenAI app discovery and blocking (Defender for Cloud Apps Netskope Zscaler) prompt and response inspection and policies preventing the upload or pasting of sensitive content into public AI tools (ChatGPT Gemini Claude etc.).
- Working knowledge of third-party DLP/IRM tools (e.g. Symantec/Broadcom DLP Forcepoint Netskope Zscaler Digital Guardian) and how they complement or integrate with M365 controls.
- Hands-on experience with at least one major cloud (Azure AWS or GCP).
- Working knowledge of encryption standards PKI IAM and Zero Trust principles.
- Familiarity with regulatory frameworks: GDPR CCPA HIPAA NYDFS SOC 2 ISO 27001.
- Strong analytical written and verbal communication skills.
- Industry certifications: SC-400 (Microsoft Information Protection Administrator) CISSP CIPP CCSP AZ-500 or GIAC equivalents.
- Experience in a law firm financial services or other highly regulated environment.
- Scripting/automation proficiency (PowerShell including Exchange Online Compliance Center and Graph PowerShell modules Python KQL).
Required Experience:
IC
About Company
Milbank is a premier international law firm handling high-profile, complex cases and business transactions through 11 offices worldwide. Driven to deliver