Haystack
← Back to Jobs
Administrative

W2 - Security Compliance Architect

ProhiresUnited States🇺🇸United StatesPosted 13 Aug 2026

Quick Overview

Work Type
Hybrid
Level
Mid Senior

Job Description

Security / Compliance Architect – DLP, CUI Boundary, and Secure Enclave

 

Note: One of the candidate has back-out recently, We need some who can join us by Aug 17 th

 

Position:  Security / Compliance Architect – DLP, CUI Boundary, and Secure Enclave

Location: remote

3 months Contract

 

 

“Need Hands-on Experience with MS SharePoint and DLP”

 

Role Summary

The Security / Compliance Architect is the primary security design authority for the engagement. This role is responsible for defining the controlled data boundary, translating compliance and business requirements into enforceable controls, shaping the secure enclave design, and ensuring the overall solution is defensible from a governance, audit, and risk-management standpoint.

This is a client-facing onshore role requiring strong experience in data protection, compliance-aligned architecture, information protection controls, and regulated collaboration environments.

Key Responsibilities

  • Lead the definition of the controlled data / CUI boundary, including in-scope users, repositories, workflows, endpoints, and approved handling paths.
  • Translate customer requirements into a target-state security architecture for a secure collaboration enclave.
  • Define the DLP and information protection strategy across collaboration, email, endpoint, and removable media channels.
  • Establish the control intent for classification, labeling, monitoring, restriction, blocking, exception handling, and audit evidence generation.
  • Drive alignment between business process requirements and security control design to ensure the solution is usable as well as compliant.
  • Lead design decisions related to:
    • approved vs non-approved storage locations
    • secure collaboration patterns
    • external sharing restrictions
    • exception governance
    • evidence and logging requirements
  • Review current-state data handling patterns and identify exposure points, control gaps, and architectural risks.
  • Produce client-facing security design artifacts, including boundary definitions, control strategies, architecture requirements, and decision packs.
  • Support design reviews, steering discussions, and executive readouts.
  • Work closely with the platform lead to ensure Microsoft control implementation aligns with security intent.
  • Support pilot validation by reviewing policy effectiveness, exception scenarios, usability impacts, and audit defensibility.
  • Provide oversight during deployment and handover to ensure the final state aligns with the approved security design.

Required Skills and Experience

  • 8+ years in cybersecurity architecture, security consulting, or security engineering roles.
  • Strong experience in one or more of the following:
    • Data Loss Prevention
    • Information Protection / Data Classification
    • Secure collaboration architecture
    • Microsoft Purview / MIP / DLP
    • Compliance-driven security design
  • Experience defining and operationalizing controls for sensitive or regulated data.
  • Strong understanding of:
    • secure data boundaries
    • access control and least privilege concepts
    • audit evidence requirements
    • policy exception governance
    • endpoint, email, and collaboration security controls
  • Experience working directly with business stakeholders, security leadership, and platform teams in regulated environments.
  • Strong workshop facilitation, requirements analysis, and executive communication skills.
  • Ability to convert ambiguous customer requirements into precise security architecture decisions.

Preferred Skills

  • Experience supporting environments involving CUI, ITAR-sensitive handling models, NIST 800-171 aligned controls, or regulated operations.
  • Familiarity with Microsoft Entra ID, SharePoint Online, Exchange Online, endpoint protection controls, and Microsoft-native security services.
  • Experience with control mapping, evidence design, and audit support for regulated programs.
  • Prior experience in DLP strategy and secure enclave design.

 

Education / Certifications

Preferred but not mandatory:

  • Bachelor’s degree in Cybersecurity, Information Security, Computer Science, or related discipline
  • CISSP, CISM, CCSP, or equivalent
  • Microsoft security certifications are a plus

 

 

  • Microsoft SharePoint Online – hands-on
  • Microsoft Purview
  • Data Loss Prevention (DLP)
  • Microsoft Information Protection (MIP)
  • Microsoft 365 security
  • Information Protection / Data Classification
  • Sensitivity Labels
  • DLP policy design and implementation
  • Secure collaboration
  • Data boundary / controlled data boundary
  • Security architecture
  • Compliance-driven security controls
  • Audit / evidence / logging
  • Policy exception management

Strong differentiators

  • CUI (Controlled Unclassified Information)
  • NIST 800-171
  • ITAR
  • Secure enclave
  • Entra ID / Azure AD
  • Exchange Online
  • Endpoint DLP
  • Defender for Endpoint
  • External sharing controls
  • Least privilege / access control
  • Control mapping
  • Risk assessment / gap analysis
  • Regulated environments

Similar jobs