1

Insider Risk Manager Jobs in Gaithersburg, MD (NOW HIRING)

As a Fortune 500 company and a leading AI platform for managing people, money, and agents, we're ... This role sits at the intersection of investigations, intelligence, and risk. You will help Workday ...

... risk patterns, and potential threats. * Utilize SIEM tools, including Splunk, to correlate cybersecurity alerts and identify indicators of insider activity. * Manage and oversee end-to-end case ...

Excellent project management and organizational skills with the ability to manage multiple client ... Preferred Qualifications * Experience working with economic security, insider risk ...

Showing results 21-40

Insider Risk Manager information

See Gaithersburg, MD salary details

$55.6K

$120.5K

$183.7K

How much do insider risk manager jobs pay per year?

As of Sep 2, 2026, the average yearly pay for insider risk manager in Gaithersburg, MD is $120,531.00, according to ZipRecruiter salary data. Most workers in this role earn between $97,200.00 and $139,400.00 per year, depending on experience, location, and employer.

What does an insider risk manager do?

An Insider Risk Manager is responsible for identifying, assessing, and mitigating risks posed by individuals within an organization, such as employees, contractors, or business partners. Their work focuses on preventing data breaches, intellectual property theft, and other security incidents caused by trusted insiders. They develop policies, conduct investigations, monitor employee activity for suspicious behavior, and collaborate with other departments to strengthen security measures. Ultimately, their goal is to protect the organization's assets and reputation from internal threats.

What are some common challenges faced by an insider risk manager, and how can they be addressed?

Insider Risk Managers often face challenges such as detecting subtle behavioral changes that may signal insider threats, balancing employee privacy with effective monitoring, and fostering a culture of security awareness. Addressing these challenges typically involves working closely with IT, HR, and legal teams to implement risk assessment tools, develop clear communication strategies, and provide regular training. Additionally, staying updated on the latest threat trends and maintaining transparent incident response protocols help Insider Risk Managers mitigate potential risks effectively.

What are the key skills and qualifications needed to thrive as an insider risk manager, and why are they important?

To thrive as an Insider Risk Manager, you need expertise in cybersecurity, risk assessment, and incident response, often supported by a degree in information security or a related field. Familiarity with SIEM tools, DLP systems, and certifications like CISSP or CISM are typically required. Strong analytical thinking, discretion, and communication skills help in identifying threats and collaborating with stakeholders. These skills ensure effective mitigation of insider threats, protecting organizational assets and sensitive information.

What is the difference between Insider Risk Manager vs Data Loss Prevention Specialist?

AspectInsider Risk ManagerData Loss Prevention Specialist
CredentialsSecurity certifications (CISSP, CISM), risk management experienceSecurity certifications, technical knowledge of DLP tools
Work EnvironmentCorporate security teams, risk assessment settingsIT security teams, technical implementation roles
Industry UsageFinancial, healthcare, government sectorsTech, finance, enterprise sectors
Primary FocusIdentifying and mitigating insider threatsPreventing data exfiltration and leaks

The Insider Risk Manager focuses on detecting and managing risks posed by internal employees, while the Data Loss Prevention Specialist concentrates on technical measures to prevent data leaks. Both roles require security certifications and are vital in protecting organizational assets, but they differ in scope and daily responsibilities.

What are popular job titles related to Insider Risk Manager jobs in Gaithersburg, MD?

For Insider Risk Manager jobs in Gaithersburg, MD, the most frequently searched job titles are:

What job categories do people searching Insider Risk Manager jobs in Gaithersburg, MD look for?

The top searched job categories for Insider Risk Manager jobs in Gaithersburg, MD are:

What cities near Gaithersburg, MD are hiring for Insider Risk Manager jobs?

Cities near Gaithersburg, MD with the most Insider Risk Manager job openings:

Microsoft Purview and Data Protection Engineer

Carlyle

Washington, DC • On-site

Full-time

Medical, Life, Retirement, PTO

Posted 27 days ago


Job description

Position Summary

The Microsoft Purview and Data Protection Engineer is a senior technical leader responsible for designing, implementing, and continuously enhancing the organization's enterprise data protection capabilities. This hands-on role serves as the technical authority for Microsoft Purview, leading the operational management of Data Loss Prevention (DLP), Insider Risk Management, Information Protection, Data Security Posture Management (DSPM), and related Microsoft security technologies. Working closely with Security Operations, Infrastructure, Cloud Engineering, Compliance, Legal, Risk, and business stakeholders, the engineer develops scalable solutions that protect the firm's most sensitive information while enabling secure business collaboration and innovation.

The successful candidate combines deep technical expertise with strategic thinking to build and mature enterprise data protection capabilities across Microsoft 365, Azure, endpoints, cloud applications, and emerging AI technologies. This role is responsible for translating security and regulatory requirements into effective technical controls, developing enterprise-wide policies and standards, leading complex implementations, and driving continuous improvements through automation, analytics, and operational excellence. The engineer serves as the technical lead for high-impact initiatives, providing architecture guidance, troubleshooting complex issues, mentoring engineers, and establishing best practices for protecting sensitive data throughout its lifecycle.

As a key member of the cybersecurity organization, the Microsoft Purview and Data Protection Engineer partners with cross-functional teams to identify and reduce data protection risks, investigate complex security events, and enhance the organization's overall security posture. The role requires a proactive, innovation-focused mindset with a strong emphasis on automation, operational efficiency, and emerging technologies, including AI-powered security capabilities. The ideal candidate is passionate about solving complex technical challenges, influencing enterprise security strategy through technical expertise, and delivering resilient, scalable data protection solutions that support business objectives while maintaining the highest standards of information security and regulatory compliance.

In-Office Requirement: 4 days per week

Primary Responsibilities

Core Responsibilities

  • Assessing firm data governance and compliance environments and developing recommendations for Microsoft Purview capabilities, including Data Loss Prevention, Compliance Manager, and Information Protection.
  • Designing and implementing Microsoft Purview solutions to support data classification, labeling, retention, investigation, and governance requirements across enterprise environments.
  • Performing technical health checks, discovery, and remediation activities for Microsoft Purview deployments, including audit, privileged access, and policy configuration reviews.
  • Supporting proof of concept, deployment, integration, and post-implementation activities for Microsoft Purview and adjacent Microsoft security and compliance technologies.

Microsoft Purview - 50%

  • Expert knowledge of Microsoft Purview Data Loss Prevention (DLP), Insider Risk Management, and Information Protection.
  • Experience designing, deploying, and administering Microsoft Purview policies across Microsoft 365, Windows endpoints, Exchange Online, SharePoint Online, OneDrive, Microsoft Teams, and supported cloud applications.
  • Strong understanding of Microsoft Purview architecture, licensing, role-based administration, and compliance portal configuration.
  • Experience integrating Microsoft Purview with Microsoft Defender, Microsoft Entra ID, Microsoft Sentinel, and other Microsoft security technologies.

Data Loss Prevention DLP - 30%

  • Design, implement, and maintain enterprise DLP policies to prevent unauthorized disclosure of sensitive information.
  • Develop DLP controls for email, endpoint devices, cloud applications, Microsoft Teams, SharePoint, OneDrive, and web uploads.
  • Configure policy tips, user notifications, incident reporting, and automated remediation workflows.
  • Tune DLP policies to reduce false positives while maintaining effective protection.
  • Experience using Sensitive Information Types (SITs), Exact Data Match (EDM), trainable classifiers, and custom classifiers.

Data Security Posture Management (DSPM) - 20%

  • Experience implementing or supporting Microsoft Purview Data Security Posture Management (DSPM).
  • Assess organizational data exposure and identify risks across Microsoft 365, Azure, and connected SaaS platforms.
  • Interpret DSPM recommendations and translate them into actionable DLP, Insider Risk, and Information Protection controls.
  • Monitor data security posture metrics and continuously improve policy coverage and risk reduction.

Requirements

Education & Certificates

  • Bachelor's degree, required
  • Concentration in cybersecurity, computer science, information systems, engineering or a related discipline, or equivalent relevant professional experience.
  • Advanced degree in a related discipline is preferred.

Preferred Qualifications

  • Microsoft SC-400: Information Protection Administrator Associate.
  • Microsoft SC-401: Information Security Administrator (or equivalent current certification).
  • Microsoft SC-100: Cybersecurity Architect Expert (preferred).
  • Experience with Microsoft Defender XDR, Microsoft Sentinel, Microsoft Entra ID, and Microsoft 365 E5 Security.
  • Experience implementing AI governance and protecting Microsoft 365 Copilot and other AI services using Microsoft Purview.

Competencies & Attributes

  • Data Protection Concepts
    • Strong understanding of enterprise data protection principles, including:
      • Data Loss Prevention (DLP)
      • Data Security Posture Management (DSPM)
      • Data Classification
      • Data Discovery
      • Data Governance
      • Information Protection
      • Sensitivity Labels
      • Data Lifecycle Management
      • Encryption technologies
      • Least Privilege and Zero Trust security models
    • Knowledge of structured and unstructured data protection strategies.
  • Information Protection
    • Design and Manage Microsoft Purview Sensitivity Labels and Label Policies.
    • Configure automatic and recommended labeling.
    • Implement encryption and rights management for sensitive corporate information.
    • Support secure collaboration while protecting confidential data.
  • Monitoring and Incident Response
    • Monitor DLP and Insider Risk alerts and perform root cause analysis.
    • Investigate policy violations and coordinate remediation efforts.
    • Develop dashboards and reports to measure program effectiveness.
    • Identify opportunities for automation and operational efficiency.
  • Compliance & Governance
    • Familiarity with regulatory and industry frameworks including:
      • GDPR
      • CCPA
      • HIPAA
      • PCI DSS
      • SOX
      • NIST
      • ISO 27001
    • Ability to align technical controls with compliance requirements.

Benefits/Compensation

The compensation range for this role is specific to Washington, DC and takes into account a wide range of factors including but not limited to the skill sets required/preferred; prior experience and training; licenses and/or certifications.

The anticipated base salary range for this role is $160,000 to $180,000.

In addition to the base salary, the hired professional will enjoy a comprehensive benefits package spanning retirement benefits, health insurance, life insurance and disability, paid time off, paid holidays, family planning benefits and various wellness programs. Additionally, the hired professional may also be eligible to participate in an annual discretionary incentive program, the award of which will be dependent on various factors, including, without limitation, individual and organizational performance.

Due to the high volume of candidates, please be advised that only candidates selected to interview will be contacted by Carlyle.


Who We Are


When people, ideas, and capital come together, opportunity expands across private markets. At Carlyle, this belief has shaped how we invest for decades, fueling growth for companies and delivering performance for investors.

Visit our website to learn more about our firm and the ways our platform is shaping private markets.