1

Data Protection Manager Jobs in New York (NOW HIRING)

Data Loss Prevention Manager

Raritan, NJ ยท On-site

$53K - $72K/yr

Data Loss Prevention Manager - Monitor insider risk activities using Microsoft Purview Insider Risk ... protection initiatives. - Enhance and maintain auto-labelling policies to ensure automatic ...

Showing results 41-60

Data Protection Manager information

See New York salary details

$33.9K

$106.3K

$188.2K

How much do data protection manager jobs pay per year?

As of Aug 10, 2026, the average yearly pay for data protection manager in New York is $106,280.00, according to ZipRecruiter salary data. Most workers in this role earn between $72,200.00 and $137,300.00 per year, depending on experience, location, and employer.

What is the difference between Data Protection Manager vs Data Security Analyst?

AspectData Protection ManagerData Security Analyst
CertificationsISO 27001, CISM, CISSPCISSP, CompTIA Security+
Work EnvironmentOversees data protection policies, manages compliance, and implements data security strategiesMonitors security systems, analyzes threats, and responds to security incidents
Industry UsageUsed across industries to ensure data privacy and complianceFocuses on identifying vulnerabilities and securing data systems

The Data Protection Manager primarily develops and enforces data privacy policies, ensuring compliance with regulations. In contrast, the Data Security Analyst focuses on monitoring security threats and implementing technical safeguards. Both roles are essential for comprehensive data security but differ in scope and responsibilities.

What are the key skills and qualifications needed to thrive as a data protection manager?

To thrive as a Data Protection Manager, you need expertise in data privacy laws, risk management, and compliance frameworks, typically supported by a degree in law, IT, or information security and relevant certifications such as CIPP/E or CIPM. Familiarity with data mapping tools, data loss prevention (DLP) systems, and privacy management software is essential. Outstanding communication, attention to detail, and problem-solving abilities help navigate complex regulations and foster a culture of compliance across the organization. These skills ensure the organization's data is protected, legal obligations are met, and reputational risks are minimized.

How does a data protection manager typically collaborate with other departments to ensure compliance with data privacy regulations?

A Data Protection Manager works closely with departments such as IT, legal, HR, and operations to ensure that data handling practices comply with relevant privacy laws and company policies. They provide guidance and training to staff, review processes for potential data risks, and coordinate responses to data breaches or requests from regulatory authorities. Regular communication and collaboration are essential to identify potential issues early and implement effective data protection measures across the organization.

What does a data protection manager do?

A Data Protection Manager is responsible for ensuring that an organization complies with data protection laws and regulations, such as the GDPR. They develop and implement policies and procedures to safeguard personal and sensitive data, conduct risk assessments, and provide training to staff. Additionally, they handle data breach responses and act as the main point of contact for data protection authorities. Their work is crucial for minimizing data-related risks and maintaining customer trust.
What are the most commonly searched types of Data Protection jobs in New York? The most popular types of Data Protection jobs in New York are:
What are popular job titles related to Data Protection Manager jobs in New York? For Data Protection Manager jobs in New York, the most frequently searched job titles are:
What cities in New York are hiring for Data Protection Manager jobs? Cities in New York with the most Data Protection Manager job openings:
Infographic showing various Data Protection Manager job openings in New York as of August 2026, with employment types broken down into 88% Full Time, 11% Part Time, and 1% Contract. Highlights an 84% Physical, 3% Hybrid, and 13% Remote job distribution, with an average salary of $106,280 per year, or $51.1 per hour.

Senior Information Security Engineer - Data Protection & Insider Risk

Cravath, Swaine & Moore LLP

New York, NY โ€ข On-site

$116K - $158K/yr

Full-time

Medical, Dental, Vision, Retirement, PTO

Re-posted 8 days ago


Job description

OVERVIEW

We are seeking an experienced, dynamic Senior Information Security Engineer with expertise in data leakage prevention (DLP), insider risk management, and identity and access governance (IAG). This role is responsible for protecting sensitive data across endpoints, cloud services, and SaaS platforms by designing, implementing, and operating security controls that identify, classify, monitor, and govern access to enterprise data.

This position also plays a hands-on role in securing Microsoft Copilot for M365 and other emerging AI-enabled tools, focusing on technical controls, data protection enforcement, and security logging. The ideal candidate has experience managing data classification and labeling programs, insider risk detection, identity governance platforms, and modern security tooling, and is comfortable working across IT, security, and compliance functions to enable the business securely.

RESPONSIBILITIES

Data Protection & Leakage Prevention

  • Designs, implements, and operates Data Loss/Leakage Prevention (DLP) controls across endpoints, email, cloud services, and SaaS platforms;
  • Leads and maintains data identification, classification, and labeling strategies for structured and unstructured data;
  • Monitors, investigates, and responds to data exfiltration and misuse events, including both accidental and malicious activity;
  • Tunes detection policies to reduce false positives while maintaining effective risk coverage.

Insider Risk Management

  • Operates and enhances insider risk detection and response programs, including behavioral analytics and user activity monitoring;
  • Partners with IT/IS management on insider risk investigations, ensuring appropriate governance and privacy controls;
  • Develops workflows for escalation, evidence handling, and remediation of insider risk incidents.

Identity & Access Governance

  • Manages and optimizes identity and access governance (IAG) platforms, including access reviews, entitlement management, and lifecycle automation;
  • Supports least-privilege access models, role-based access control (RBAC), and segregation of duties (SoD) initiatives;
  • Integrates identity signals with data protection and insider risk tooling to enable contextual, risk-based controls.

Security Tooling & Operations

  • Serves as a subject matter expert for security platforms related to DLP, insider risk, data classification, and identity governance;
  • Evaluates, onboards, and operationalizes new security tools and features;
  • Creates and maintains runbooks, procedures, dashboards, and metrics to demonstrate program effectiveness.

Governance, Risk, and Collaboration

  • Supports regulatory and compliance requirements related to data protection and access control (e.g., SOX, HIPAA, GDPR, CCPA, etc., as applicable);
  • Provides guidance to IT and business teams on secure data handling and access practices;
  • Contributes to security awareness efforts related to data handling, insider risk, and acceptable use.

AI & Generative AI Security (Technical Controls & Monitoring)

  • Implements and operates security controls for Microsoft Copilot for M365 using Purview, Defender, and Entra ID to enforce access boundaries and reduce data exposure;
  • Configures DLP, sensitivity labels, permissions, logging, and alerting to ensure AI-assisted access aligns with data classification and authorization models;
  • Investigates and responds to data exposure or misuse involving Copilot or other AI-enabled workflows, and support secure onboarding of additional AI/LLM tools; and
  • Performs additional duties as assigned.
QUALIFICATIONS

REQUIRED CANDIDATE QUALIFICATIONS:

  • At least 7+ years of experience in information security, with direct focus on data protection, insider risk, or identity governance;
  • Hands-on experience with one or more DLP and data classification platforms (e.g., Microsoft Purview, Symantec, Forcepoint, Netskope, etc.);
  • Experience managing identity and access governance solutions (e.g., Microsoft Entra ID Governance, SailPoint, Saviynt, Okta IGA);
  • Working knowledge of Microsoft security ecosystem (Purview, Defender for Endpoint, Defender for Cloud Apps, Entra ID, Sentinel);
  • Strong understanding of data classification schemes, sensitive data types, and data handling controls;
  • Experience investigating security alerts and incidents involving user behavior and data misuse;
  • Familiarity with endpoint, cloud, and SaaS security architectures;
  • Strong documentation, communication, and cross-functional collaboration skills; and
  • Ability to work additional hours as needed.

PREFERRED / NICE-TO-HAVE QUALIFICATIONS:

  • Experience with User and Entity Behavior Analytics (UEBA) or insider risk platforms;
  • Knowledge of privacy-by-design principles and employee monitoring considerations;
  • Scripting or automation experience (PowerShell, Python, KQL, etc.);
  • Security certifications such as CISSP, CISM, CCSP, GIAC, or vendor-specific certifications;
  • Bachelor's degree in Information Security, Computer Science, Information Technology, or a related technical field.

This position is located in our New York office, and currently has a hybrid work schedule, but that is subject to change. The estimated salary range for this position is $160,000 to $200,000. The actual salary offered will be based on a wide range of factors, including relevant skills, training, experience, education, and where applicable, licensure or certification obtained. Market and Firm factors are also considered. In addition to base salary and discretionary bonus(es), we offer a generous employee benefits package including, but not limited to, paid time off, medical, dental, vision care, 401(k) and substantial health club discounts.

Employment Type: FULL_TIME