Milbank LLP logo
Milbank LLP
Posted 66 days agoVerified live 15h ago

Data Security Specialist

Brief overview

Remote
$140k–$160k/yrStated range
57 H-1B approvalsDept. of Labor
7 green cardsCertified filings
Data Loss Prevention (DLP)Microsoft Purview DLPMicrosoft 365 (M365)Azure Information Protection (AIP)Azure Rights Management Services (Azure RMS)Double Key Encryption (DKE)Customer KeyTrainable classifiersDefender for Cloud Apps (MCAS)Microsoft Purview Insider Risk ManagementCommunication ComplianceeDiscovery (Premium)Data Lifecycle ManagementAI data leakage preventionMicrosoft 365 Copilot controlsCASB/SSE tools Defender for Cloud AppsCASB/SSE tools Netskope

About the company

Milbank LLP logo
Milbank LLPmilbank.com

Milbank is a premier international law firm handling high-profile, complex cases and business transactions through 11 offices worldwide.

Visa sponsorship history

4 years sponsoring, last filed FY2026

Data powered by U.S. Department of Labor. This does not guarantee sponsorship for this specific role.
57H-1B approved
98%approval rate
30new H-1B hires
7PERM certified
$285,000median wage / yr
H-1B Petition ApprovalsVisas USCIS actually granted: the strongest sign the company sponsors.
202313
202417
202519
20268
LCA Certified ApplicationsAn early filing step, not a visa approval: it signals intent, not confirmed sponsorship.
20239
20249
202514
20262
Green Card (PERM) FilingsCertified green card filings: a long-term commitment to international hires.
20231
20243
20253
Top sponsored roles
AssociateLaw ClerkASSOCIATE
Sponsored employees from
AustraliaUruguaySwedenBelgium

Job description

Summary

Milbank LLP is a law firm seeking a Data Security Specialist responsible for protecting the confidentiality, integrity, and availability of the firm’s data assets. This role involves designing and implementing controls to safeguard sensitive information against unauthorized access and addressing emerging risks from generative AI.

Responsibilities

  • Design and operate data loss prevention (DLP) policies across email, endpoints, and cloud services (Microsoft Purview, M365, Azure)
  • Implement and tune data classification, labeling, and encryption frameworks aligned with firm policy and regulatory requirements
  • Manage rights management (IRM/MIP), tokenization, and key management solutions
  • Design and enforce AI data leakage prevention controls — governing how sensitive data is used with Microsoft 365 Copilot, ChatGPT Enterprise, and other GenAI/LLM tools — including prompt and response monitoring, sensitivity-label enforcement, and blocking unsanctioned AI services
  • Investigate data security incidents, perform root-cause analysis, lead containment and remediation
  • Monitor SIEM, CASB, and DLP alerts; triage events and escalate per the incident response plan
  • Partner with the SOC and forensics teams on insider threat and exfiltration investigations
  • Detect and respond to AI-related data exposure events, including sensitive data submitted to public LLMs, prompt injection, and shadow AI usage
  • Support compliance with GDPR, CCPA, NYDFS Part 500, SOC 2, and client security obligations
  • Conduct data risk assessments for new applications, vendors, and AI/LLM use cases
  • Maintain evidence and artifacts for internal and external audits
  • Contribute to the firm’s AI governance program, aligning controls with frameworks such as NIST AI RMF and ISO/IEC 42001
  • Develop scripts and automations (PowerShell, Python, KQL) to scale data security operations
  • Integrate data security controls into CI/CD, SaaS onboarding, and identity workflows
  • Maintain documentation, runbooks, and control mappings

Skills

  • Bachelor's degree in computer science, Information Security, or related field (equivalent experience accepted)
  • 4+ years in information security with at least 2 years focused on data protection, DLP, or data governance
  • In-depth, hands-on experience with a range of enterprise DLP and rights management platforms, with deep expertise in the Microsoft M365 stack — including Microsoft Purview DLP (Exchange Online, SharePoint, OneDrive, Teams, and Endpoint DLP), Microsoft Purview Information Protection (MIP) sensitivity labels, Azure Information Protection (AIP), Azure Rights Management Services (Azure RMS), Double Key Encryption (DKE), and Customer Key. Experience tuning policies, authoring custom sensitive information types (SITs), trainable classifiers, and integrating Purview with Defender for Cloud Apps (MCAS) is required
  • Experience with Microsoft Purview Insider Risk Management, Communication Compliance, eDiscovery (Premium), and Data Lifecycle Management
  • Demonstrated experience with AI data leakage prevention — protecting sensitive data from exposure to generative AI and LLM services. This includes hands-on work with Microsoft Purview controls for Microsoft 365 Copilot (DSPM for AI / AI Hub, Copilot interaction auditing, sensitivity-label enforcement on Copilot responses), CASB/SSE-based GenAI app discovery and blocking (Defender for Cloud Apps, Netskope, Zscaler), prompt and response inspection, and policies preventing the upload or pasting of sensitive content into public AI tools (ChatGPT, Gemini, Claude, etc.)
  • Working knowledge of third-party DLP/IRM tools (e.g., Symantec/Broadcom DLP, Forcepoint, Netskope, Zscaler, Digital Guardian) and how they complement or integrate with M365 controls
  • Hands-on experience with at least one major cloud (Azure, AWS, or GCP)
  • Working knowledge of encryption standards, PKI, IAM, and Zero Trust principles
  • Familiarity with regulatory frameworks: GDPR, CCPA, HIPAA, NYDFS, SOC 2, ISO 27001
  • Strong analytical, written, and verbal communication skills
  • Industry certifications: SC-400 (Microsoft Information Protection Administrator), CISSP, CIPP, CCSP, AZ-500, or GIAC equivalents
  • Experience in a law firm, financial services, or other highly regulated environment
  • Scripting/automation proficiency (PowerShell — including Exchange Online, Compliance Center, and Graph PowerShell modules — Python, KQL)

Qualifications

Must Haves

  • Bachelor's degree in computer science, Information Security, or related field (equivalent experience accepted)
  • 4+ years in information security with at least 2 years focused on data protection, DLP, or data governance
  • In-depth, hands-on experience with a range of enterprise DLP and rights management platforms, with deep expertise in the Microsoft M365 stack — including Microsoft Purview DLP (Exchange Online, SharePoint, OneDrive, Teams, and Endpoint DLP), Microsoft Purview Information Protection (MIP) sensitivity labels, Azure Information Protection (AIP), Azure Rights Management Services (Azure RMS), Double Key Encryption (DKE), and Customer Key. Experience tuning policies, authoring custom sensitive information types (SITs), trainable classifiers, and integrating Purview with Defender for Cloud Apps (MCAS) is required
  • Experience with Microsoft Purview Insider Risk Management, Communication Compliance, eDiscovery (Premium), and Data Lifecycle Management
  • Demonstrated experience with AI data leakage prevention — protecting sensitive data from exposure to generative AI and LLM services. This includes hands-on work with Microsoft Purview controls for Microsoft 365 Copilot (DSPM for AI / AI Hub, Copilot interaction auditing, sensitivity-label enforcement on Copilot responses), CASB/SSE-based GenAI app discovery and blocking (Defender for Cloud Apps, Netskope, Zscaler), prompt and response inspection, and policies preventing the upload or pasting of sensitive content into public AI tools (ChatGPT, Gemini, Claude, etc.)
  • Working knowledge of third-party DLP/IRM tools (e.g., Symantec/Broadcom DLP, Forcepoint, Netskope, Zscaler, Digital Guardian) and how they complement or integrate with M365 controls
  • Hands-on experience with at least one major cloud (Azure, AWS, or GCP)
  • Working knowledge of encryption standards, PKI, IAM, and Zero Trust principles
  • Familiarity with regulatory frameworks: GDPR, CCPA, HIPAA, NYDFS, SOC 2, ISO 27001
  • Strong analytical, written, and verbal communication skills

Nice to Haves

  • Industry certifications: SC-400 (Microsoft Information Protection Administrator), CISSP, CIPP, CCSP, AZ-500, or GIAC equivalents
  • Experience in a law firm, financial services, or other highly regulated environment
  • Scripting/automation proficiency (PowerShell — including Exchange Online, Compliance Center, and Graph PowerShell modules — Python, KQL)

More jobs like this