Our Client, the National leader in their industry, is seeking a talented DLP & Data Protection professional to help build and mature their enterprise DLP program with an early focus on implementing DLP controls for AI solutions. This is a full time permanent opportunity based in the west-end Greater Toronto Area (GTA) requiring onsite participation in a hybrid model 3 days per week. We have worked extensively with this Client for 18+ years and have received excellent feedback from those candidates whom we have successfully placed. Please contact us to learn more.
The Senior Advisor, Data Protection and Data Loss Prevention (DLP) will play a key contributor role in building and maturing the enterprise DLP program. The role will be primarily responsible in implementing and maturing DLP and DSPM capabilities to protect sensitive data across M365 and hybrid environment, including controls for emerging AI technologies. In addition to developing and optimizing data protection policies, the role will monitor, investigate, and respond to DLP events and alerts to continuously improve the effectiveness of the program.
Responsibilities:
- Contribute to the establishment and ongoing maturity of the enterprise Data Protection and DLP program.
- Manage day-to-day DLP operations, including developing and tuning policies/controls, monitoring alerts, and responding to DLP incidents.
- Evaluate data sensitivity, exposure paths, and policy violations to identify true risk, reduce false positives, and improve the effectiveness of DLP controls.
- Implement, configure, and optimize enterprise data protection capabilities using technologies such as Microsoft Purview, Palo Alto Enterprise DLP, and Palo Alto CASB across Microsoft 365 and hybrid environments.
- Design and enforce security protection controls and safeguards to reduce the risk of sensitive data exposure across AI systems, models and modern workflows.
- Develop operational playbooks, metrics and reporting to support operationalization, continuous improvement, and the ongoing effectiveness of the DLP program.
- Support data governance, business, and technology teams to improve and mature data classification, ensuring it is consistently applied and effectively supports DLP controls and compliance requirements.
Requirements:
- 5+ years of experience in cybersecurity, with at least 3+ years of practical experience in DLP, Data Protection, and Data Security Posture Management (DSPM).
- Practical hands-on experience implementing and managing DLP solutions to protect data in traditional enterprise channels (email, endpoints, cloud storage, file shares) and modern AI interfaces (e.g., Copilot, ChatGPT, Copilot Studio agents) where sensitive data may be prompted, processed, or exposed
- Strong understanding of data protection concepts, including data classification frameworks, information protection, and how data exposure risks manifest across modern organizations.
- Understanding of privacy and regulatory requirements (e.g., PIPEDA, PCI-DSS, SOC2, OSFI) and ability to apply them in designing and tuning data protection controls.
- Experience with cloud and SaaS environments (e.g., Microsoft 365, Azure), including an understanding of data security considerations on these platforms.
- Exposure to adjacent data security domains such as CASB, insider risk, and data governance programs.
- Understanding of AI security fundamentals and practical experience identifying data exposure risks in AI-driven or modern workflows.
- Self-motivated, with the ability to work independently and make practical decisions in a fast-paced, evolving environment.
Total Direct Compensation (base salary + bonus):
$98,000 - $118,000 CAD
We wish to thank all applicants for their interest and effort in applying for this position.
For a complete list of our current job openings, please visit our website at www.staffit.ca
Thank you for choosing Staff IT as your Information Technology Staffing Partner.