Cyber Data Loss Prevention (DLP) Specialist - SC Cleared at CPS, Remote/London, 4 Months, £Contract Rate

Contract Description

Please note: An active SC Clearance is an essential requirement for this role, as a minimum you must be willing & eligible to undergo checks. (Please note, due to the exceptional requirements of this position (short-term nature of this role and speed at which we require a postholder in situ) preference may be given to candidates who meet all of the essential criteria and hold active security clearance.) 

 

The Cyber DLP Specialist will provide the specialist technical and advisory capability required to implement the outstanding GovAssure and Purple Team recommendations relating to data mapping, data discovery, data governance, classification, retention and Data Loss Prevention. The role will help the organisation establish the information and governance foundations needed to allow effective technical DLP controls to be designed, deployed and evidenced.

 

Working jointly with CKIM, Cyber Security, Operational Security, Data Protection, Information Management, service owners and technical teams, the specialist will assess the current position, define requirements, support data mapping and classification, implement and tune Microsoft Purview and related controls, strengthen detections on network shares and SharePoint, restrict unauthorised cloud-storage routes, and produce the evidence needed to close the recommendations

 

As a Cyber Data Loss Prevention (DLP) Specialist your main responsibilities will be:

 

  • Review GovAssure, Purple Team and DLP recommendations, existing plans and progress to date.
  • Develop a single remediation roadmap with defined owners, milestones, risks, dependencies and evidence requirements.
  • Identify quick wins and provide regular progress reporting to the Head of CKIM and Head of Cyber Security.
  • Support delivery of the organisation-wide data mapping and governance activities.
  • Identify, classify and validate sensitive information, ownership, access, retention and disposal requirements.
  • Advise on data discovery tooling and establish sustainable governance arrangements.
  • Finalise and implement the organisation classification and sensitivity labelling framework.
  • Configure Microsoft Purview labels, classifiers and policies.
  • Manage testing, deployment, governance and resolution of business or technical impacts.
  • Validate DLP requirements and implement Microsoft Purview DLP controls across key the organisation platforms and services.
  • Configure, test and optimise policies, alerts and reporting to reduce data loss risk.
  • Integrate DLP monitoring with SOC, SIEM, ITSM and incident management processes.
  • Define operational processes, playbooks, escalation routes and response procedures.
  • Monitor effectiveness, analyse trends, reduce false positives and support investigations.
  • Contribute to incident response and lessons learned activities.
  • Maintain documentation, evidence, standards, risk decisions and operational metrics.
  • Support audits, GovAssure evidence collection, DPIAs and assurance activities.
  • Report on control effectiveness, risks, exceptions and remediation progress.
  • Support user awareness, training and adoption of DLP and information handling controls.
  • Deliver knowledge transfer, operational documentation and handover arrangements.

 

Essential:

 

  • Proven experience delivering data mapping, governance, classification and DLP programmes within large, complex organisations.
  • Experience of Data Loss Prevention, data classification, sensitivity labelling and data discovery.
  • Hands-on experience implementing and optimising Microsoft Purview DLP and information protection capabilities, or equivalent platforms.
  • Ability to translate business, legal and privacy requirements into effective, risk-based technical controls.
  • Experience integrating DLP with SOC, SIEM, ITSM and incident response processes.
  • Strong stakeholder management across Cyber Security, Data Protection, Information Management, Legal, HR and operational teams.
  • Relevant certification or equivalent experience in cyber security, cloud security, information protection or compliance.

 

Desirable:

 

  • Public Sector experience.
  • Experience with CASB/SSE technologies, insider risk, eDiscovery, Defender, SharePoint monitoring or government security environments.