

Insight Global
Data Protection Engineer
β - Featured Role | Apply direct with Data Freelance Hub
This role is for a Data Protection Engineer with a contract length of "unknown" and a pay rate of "unknown." Candidates should have a Bachelor's degree, 2+ years in cybersecurity or healthcare IT, and knowledge of HIPAA. Key skills include DLP, IAM, and compliance. Certifications like HCISPP or CISSP are preferred.
π - Country
United States
π± - Currency
$ USD
-
π° - Day rate
560
-
ποΈ - Date
January 10, 2026
π - Duration
Unknown
-
ποΈ - Location
Unknown
-
π - Contract
Unknown
-
π - Security
Unknown
-
π - Location detailed
Tampa, FL
-
π§ - Skills detailed
#AI (Artificial Intelligence) #Automation #Security #ChatGPT #Documentation #Compliance #Leadership #Cybersecurity #IAM (Identity and Access Management) #Data Loss Prevention #SharePoint #Computer Science #Classification
Role description
Minimum Qualifications & Experience Required
β’ Bachelorβs degree in Information Security, Health Information Management, Computer Science, or related field
β’ 2+ years of experience in cybersecurity, data protection, identity/access governance, or healthcare IT
β’ Working knowledge of HIPAA, HITECH, and PHI/PII protection requirements
β’ Hands-on experience with data loss prevention (DLP), access governance, or data classification tools
β’ Ability to manage multiple projects, collaborate across IT and business teams, and drive remediation efforts
β’ Excellent analytical, documentation, and communication skills
Nice To Have Qualifications & Experience
β’ Experience with Varonis, Microsoft Purview Information Protection/DLP, Zscaler DLP, or similar platforms
β’ Familiarity with Epic, unstructured data repositories, clinical workflows, and PHI handling practices
β’ Understanding of identity & access management (IAM), least-privilege principles, and shared-drive governance
β’ Certifications such as HCISPP, CISSP, GIAC GSEC, COMPTIA Security+ or CySA+, or similar
Day-to-Day Responsibilities
β’ Perform enterprise-wide data discovery using Varonis and Purview to identify PHI, PII, confidential business data, and high-risk exposures
β’ Configure and maintain data classification and labeling policies across M365 (Outlook, OneDrive, SharePoint, Teams)
β’ Partner with the Patient Safety and Compliance teams to refine classification taxonomy and retention requirements
β’ Identify and remediate excessive file permissions, global access, stale access, and vulnerable ACL structures
β’ Work with business units and system owners to document data flows and enforce least-privilege access models and sustainable governance practices
β’ Support automation workflows for secure data provisioning and permission change management
β’ Implement, monitor, and tune DLP controls across Purview, Zscaler, and endpoint channels
β’ Build policies for PHI/PII, financial data, research data, insider risk scenarios, and restricted data classes
β’ Investigate DLP alerts, analyze user behavior, and coordinate remediation or coaching sessions
β’ Develop detection rules for GenAI prompt protection, including PHI controls for ChatGPT, Copilot, Teams plugins, and browser-based AI use
β’ Maintain dashboards highlighting risk reduction, high-risk data sets, permission cleanup progress, and DLP control effectiveness
β’ Provide reports to leadership, Cybersecurity Governance Council, and the Architecture Review Board
β’ Track metrics such as open access reduction, stale data elimination, labeling adoption, and incident trends
β’ Investigate data exposure incidents, including misdirected communications, oversharing, or unauthorized access
β’ Work with Legal, Compliance, and IR teams to assemble evidence, timelines, and regulatory reports
β’ Identify control gaps and implement process improvements to prevent recurrence
β’ Evaluate data protection risks for AI use cases (e.g., data leakage, re-identification, prompt injection)
β’ Validate that AI-connected systems follow TGHβs data minimization and PHI boundary rules
β’ Support readiness for audits and certification programs (HIPAA, NIST CSF, internal and external audits)
Minimum Qualifications & Experience Required
β’ Bachelorβs degree in Information Security, Health Information Management, Computer Science, or related field
β’ 2+ years of experience in cybersecurity, data protection, identity/access governance, or healthcare IT
β’ Working knowledge of HIPAA, HITECH, and PHI/PII protection requirements
β’ Hands-on experience with data loss prevention (DLP), access governance, or data classification tools
β’ Ability to manage multiple projects, collaborate across IT and business teams, and drive remediation efforts
β’ Excellent analytical, documentation, and communication skills
Nice To Have Qualifications & Experience
β’ Experience with Varonis, Microsoft Purview Information Protection/DLP, Zscaler DLP, or similar platforms
β’ Familiarity with Epic, unstructured data repositories, clinical workflows, and PHI handling practices
β’ Understanding of identity & access management (IAM), least-privilege principles, and shared-drive governance
β’ Certifications such as HCISPP, CISSP, GIAC GSEC, COMPTIA Security+ or CySA+, or similar
Day-to-Day Responsibilities
β’ Perform enterprise-wide data discovery using Varonis and Purview to identify PHI, PII, confidential business data, and high-risk exposures
β’ Configure and maintain data classification and labeling policies across M365 (Outlook, OneDrive, SharePoint, Teams)
β’ Partner with the Patient Safety and Compliance teams to refine classification taxonomy and retention requirements
β’ Identify and remediate excessive file permissions, global access, stale access, and vulnerable ACL structures
β’ Work with business units and system owners to document data flows and enforce least-privilege access models and sustainable governance practices
β’ Support automation workflows for secure data provisioning and permission change management
β’ Implement, monitor, and tune DLP controls across Purview, Zscaler, and endpoint channels
β’ Build policies for PHI/PII, financial data, research data, insider risk scenarios, and restricted data classes
β’ Investigate DLP alerts, analyze user behavior, and coordinate remediation or coaching sessions
β’ Develop detection rules for GenAI prompt protection, including PHI controls for ChatGPT, Copilot, Teams plugins, and browser-based AI use
β’ Maintain dashboards highlighting risk reduction, high-risk data sets, permission cleanup progress, and DLP control effectiveness
β’ Provide reports to leadership, Cybersecurity Governance Council, and the Architecture Review Board
β’ Track metrics such as open access reduction, stale data elimination, labeling adoption, and incident trends
β’ Investigate data exposure incidents, including misdirected communications, oversharing, or unauthorized access
β’ Work with Legal, Compliance, and IR teams to assemble evidence, timelines, and regulatory reports
β’ Identify control gaps and implement process improvements to prevent recurrence
β’ Evaluate data protection risks for AI use cases (e.g., data leakage, re-identification, prompt injection)
β’ Validate that AI-connected systems follow TGHβs data minimization and PHI boundary rules
β’ Support readiness for audits and certification programs (HIPAA, NIST CSF, internal and external audits)






