About the role
The Data Security Engineer will own the operational delivery and management of data security tooling, including Microsoft Purview and DSPM capabilities. They will work across IT, Legal, and business teams to implement data classification, labelling, and protection controls to secure sensitive information.
What they look for
Requirements
Candidates must have strong hands-on experience with Microsoft Purview, DLP, and data classification within Microsoft 365 environments. A working knowledge of GDPR, risk-based security frameworks, and scripting automation with PowerShell is also required.
Benefits
Full description
Data Security Engineer
Application Deadline: 23 August 2026
Department: IT
Employment Type: Permanent - Full Time
Location: London, UK
Description
The Premier League is seeking a Data Security Engineer to help build and operate the organisation’s data security capability across Microsoft 365, SaaS, and cloud environments. This is a hands-on engineering role with significant scope for technical ownership and professional growth. The successful candidate will establish foundational data security capabilities from the ground up, a rare opportunity to own a greenfield capability at a high-profile organisation, supporting the Premier League's wider cloud, collaboration, and AI-enabled transformation programmes
This role will focus on implementing and managing data classification, labelling, Data Loss Prevention (DLP), and Data Security Posture Management (DSPM) capabilities to improve the visibility, protection, and control of sensitive data across the organisation.
Working within the Information Security team, the role will play a key part in operationalising the Premier League’s newly approved Data Classification Policy and supporting the rollout of modern data protection controls across the business. The successful candidate will work closely with Information Security, IT, Legal, and business stakeholders to translate policy and regulatory requirements into practical technical controls.
Who we are The Premier League is home to some of the most competitive and compelling football in the world. The League and its Clubs use the power and popularity of the competition to inspire fans, communities and partners in the UK and across the world. The Premier League brings people together from all backgrounds. It is a competition for everyone, everywhere and is available to watch in over 1.2 billion homes in 189 countries.
We have a wide variety of responsibilities. These include organising the competition and its Handbook as well as managing the centralised broadcast and commercial rights. The work we do in conjunction with the Clubs also goes far beyond the 90 minutes. We support and provide a framework for youth development, we protect the organisation’s intellectual property, support the wider game and community programmes, undertake international development work and liaise with governing bodies and other leagues.
The Premier League is an equal opportunities employer and strives to create an inclusive culture where talent can flourish. We believe in the potential of everyone and open our doors to those who share those values. All appointments will be made based on merit; however, we particularly encourage applications from women, people from minority ethnic communities, LGBTQ+ people and disabled people. Our hybrid-working model also allows you some variety on your place of work, offering you the chance to work from home on some days each week. Where possible, you will attend the office or site visits in line with our company policy. All staff liaise closely with their line manager to manage their time appropriately and according to their work and team requirements.
The role
Data security platform ownership
- Own the operational delivery and ongoing management of the Premier League’s data security tooling, including Microsoft Purview and Data Security Posture Management (DSPM) capabilities.
- Support the implementation and maturity of the organisation’s data classification, labelling, and data protection controls in line with Information Security standards and business requirements.
- Work closely with Information Security, IT, Legal, and business stakeholders to translate policy and regulatory requirements into practical technical controls.
Microsoft Purview & data protection
- Design, implement, and operate Microsoft Purview capabilities including Information Protection and Data Loss Prevention (DLP).
- Support the rollout and tuning of data classification and labelling across Microsoft 365 environments including SharePoint, OneDrive, Exchange, and Teams.
- Monitor and improve the effectiveness of DLP and data protection controls across endpoints, email, and cloud services.
- Support the secure adoption of collaboration and AI technologies by reducing data exposure risks and improving visibility of sensitive information.
DSPM & data visibility
- Own the technical implementation and day-to-day operational management of the organisation's DSPM platform.
- Build and maintain visibility of sensitive data across Microsoft 365, SaaS platforms, and cloud environments.
- Identify, investigate, and support remediation of data exposure risks, excessive permissions, and insecure data handling practices.
- Support integration of DSPM capabilities with the wider Microsoft security stack including Defender, Sentinel, and Purview.
Cloud & platform integration
- Work with Cloud Security and infrastructure teams to embed data protection controls into new and existing platforms and services.
- Support integration of data security tooling across Azure, AWS, SaaS, and other business systems.
- Contribute data security expertise to technical projects, cloud initiatives, and new technology deployments.
Incident support & operational security
- Provide subject matter expertise during investigations involving data loss, misuse, or exposure.
- Support monitoring, tuning, and operational response activities relating to data security alerts and incidents.
- Assist with continuous improvement of data security processes, workflows, and operational reporting.
Automation, reporting & engagement
- Develop and maintain reporting on data security metrics and control effectiveness.
- Automate operational and administrative tasks using PowerShell and native platform tooling where appropriate.
- Work collaboratively with technical and non-technical stakeholders to improve data handling practices and support adoption of security controls.
Requirements for the role
- Strong hands-on experience with Microsoft Purview, including Information Protection and DLP capabilities.
- Experience implementing or supporting data classification and labelling within Microsoft 365 environments.
- Experience operating or tuning DLP controls across endpoint, email, and cloud environments.
- Understanding of data security challenges relating to SaaS platforms, cloud services, large-scale collaboration, and AI adoption.
- Familiarity with DSPM concepts or data discovery tooling; hands-on implementation experience desirable.
- Ability to translate security and compliance requirements into practical technical controls.
- Experience supporting investigations involving data loss, misuse, or insider risk scenarios.
- Working knowledge of Microsoft security technologies including Defender and Entra ID.
- Experience with scripting or automation using PowerShell or similar tooling.
- Comfortable working independently and taking ownership of operational technical platforms.
- Strong communication skills with the ability to engage both technical and non-technical stakeholders.
- Working knowledge of GDPR principles and risk-based security frameworks such as NIST CSF.
Our commitment to safeguarding includes implementing robust safer recruitment procedures to assess the suitability of individuals applying for roles that involve work with children and adults who are or may be at risk of harm. For further information, please see our Safeguarding Policy and Safer Recruitment Guidance.
To apply please visit our careers page and apply with your CV and a cover letter. The closing date for applications is 23 August 2026.
We will remove barriers that prospective candidates might face at any stage of our recruitment process. If you have a disability and would like the advert in an alternative format, or would like to talk about how we can adjust the interview process to best support you, please contact recruitment@premierleague.com
Similar roles
-
GNMA IAISO Cybersecurity Program Manager
Crest Security Assurance $150K–$160K/yr
-
Cyber Security Engineer I
Durango Casino & Resort Las Vegas, Nevada, United States
-
IT Security Engineer / Penetration Tester 60% - 100% (m/w/d)
KastGroup GmbH Wallisellen, Zurich, Switzerland
-
Cybersecurity Compliance Analyst
RCG Suitland, Maryland, United States · $115K–$125K/yr
-
Security Engineer I
S.P. Richards Company Atlanta, Georgia, United States
-
Cybersecurity Analyst
Michigan Schools and Government Credit Union Troy, Michigan, United States · $79K/yr