Data Protection and Security Engineer

InvoiceCloud

Hyderabad

On-site

INR 1,800,000 - 3,000,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

InvoiceCloud is seeking a Data Protection and Security Engineer to strengthen enterprise data security, privacy, and governance across corporate and cloud environments. You will lead data discovery, classification, DLP implementation, encryption, and key management while integrating tooling with SIEM/SOAR and incident response processes.

The role emphasizes automation, compliance with SOC 2 PCI, and privacy requirements, with a focus on scalable, auditable controls and documentation to support

Qualifications

  • Bachelor's degree in information security, computer engineering, or a related field (or equivalent experience).
  • 5+ years of experience in data security, privacy engineering, or security engineering roles.
  • Hands-on experience with data discovery, classification, and governance platforms (e.g. Microsoft Purview, OneTrust, or similar).
  • Experience implementing and tuning DLP controls across endpoints, email, collaboration platforms, and cloud storage environments.
  • Experience implementing encryption, tokenization, and key management controls.
  • Familiarity with compliance frameworks such as SOC 2 PCI, and privacy regulations.
  • Ability to automate workflows and integrations using scripting and APIs (PowerShell, Python, or similar).
  • Strong documentation and cross-functional collaboration skills.
  • Certifications such as CDPSE, CIPT, Security+, or similar are a plus.

Responsibilities

  • Leads Data Discovery, Classification, and DLP Implementation by deploying and tuning data discovery and classification tooling across corporate and cloud environments, expanding coverage of sensitive data repositories, and improving DLP signal quality.
  • Implements and strengthens encryption, tokenization, and key management controls, including key rotation, access control enforcement, and break-glass procedures, reducing exposure risk for sensitive corporate and customer data.
  • Drives measurable improvements in data lifecycle management and retention enforcement in partnership with system owners, ensuring appropriate storage patterns, retention schedules, and secure disposal of data assets.
  • Delivers documented 30-, 150-, and 210-day outcomes, including expanded classification coverage, reduced DLP false positives, improved encryption posture, and executive-ready reporting on data protection KPIs.
  • Integrates Data Protection Tooling with Governance and Incident Response Systems (e.g., SIEM/SOAR, ticketing) to ensure DLP alerts, misconfigurations, and exposure risks are investigated and resolved in a structured and auditable manner.
  • Partners with Compliance, Legal, and Privacy stakeholders to translate regulatory and contractual obligations into enforceable technical controls aligned to SOC 2 PCI, and privacy requirements.
  • Investigates and supports response to data protection incidents, including DLP events, accidental exposure, and misconfiguration scenarios, ensuring corrective actions are tracked to closure.
  • Develops and maintains documentation, operational standards, and runbooks that support audit readiness, evidence integrity, and repeatable control execution.
  • Automates audit evidence collection and continuous control validation workflows using scripting and APIs (PowerShell, Python), reducing manual effort and improving reliability of compliance reporting.
  • Standardizes data protection configurations, labeling models, and DLP policy structures to improve consistency across systems and reduce operational friction.
  • Establishes repeatable dashboards and metrics to measure data protection coverage, control effectiveness, false-positive rates, and remediation timelines.
  • Embeds privacy-by-design principles into product and engineering workflows by providing structured guidance on secure data flows, storage patterns, logging, and access controls.
  • Applies forward-looking data protection strategies to address evolving cloud, collaboration, and SaaS risks, ensuring controls adapt to modern work patterns and distributed environments.
  • Leverages AI and automation to enhance data classification accuracy, improve anomaly detection in DLP alerts, and generate actionable insights from data protection telemetry.
  • Continuously evaluates emerging data governance and privacy engineering capabilities, translating new tooling and best practices into scalable improvements across the enterprise.

Skills

Data discovery
Data classification
DLP
Encryption
Tokenization
Key management
Automation
Scripting (PowerShell, Python)
Documentation
Cross-functional collaboration
Regulatory compliance (SOC 2 PCI)
Security engineering

Education

Bachelor's degree in information security or related field

Tools

Microsoft Purview
OneTrust

Job description

We are looking for a Data Protection and Security Engineer to strengthen enterprise data security, privacy, and governance capabilities. The role will focus on data discovery and classification, DLP, encryption, key management, data lifecycle controls, compliance, and automation across corporate and cloud environments.

The core responsibilities for the job include the following:

Results-Driven:
  • Leads Data Discovery, Classification, and DLP Implementation by deploying and tuning data discovery and classification tooling across corporate and cloud environments, expanding coverage of sensitive data repositories, and improving DLP signal quality.
  • Implements and strengthens encryption, tokenization, and key management controls, including key rotation, access control enforcement, and break-glass procedures, reducing exposure risk for sensitive corporate and customer data.
  • Drives measurable improvements in data lifecycle management and retention Enforcement in partnership with system owners, ensuring appropriate storage patterns, retention schedules, and secure disposal of data assets.
  • Delivers documented 30-, 150-, and 210-day outcomes, including expanded classification coverage, reduced DLP false positives, improved encryption posture, and executive-ready reporting on data protection KPIs.
Takes Ownership:
  • Integrates Data Protection Tooling with Governance and Incident Response Systems (e. g., SIEM/SOAR, ticketing) to ensure DLP alerts, misconfigurations, and exposure risks are investigated and resolved in a structured and auditable manner.
  • Partners with Compliance, Legal, and Privacy stakeholders to translate regulatory and contractual obligations into enforceable technical controls aligned to SOC 2 PCI, and privacy requirements.
  • Investigates and supports response to data protection incidents, including DLP events, accidental exposure, and misconfiguration scenarios, ensuring corrective actions are tracked to closure.
  • Develops and maintains documentation, operational standards, and runbooks that support audit readiness, evidence integrity, and repeatable control execution.
Drives Efficiency:
  • Automates audit evidence collection and continuous control validation workflows using scripting and APIs (e. g., PowerShell, Python), reducing manual effort and improving reliability of compliance reporting.
  • Standardizes data protection configurations, labeling models, and DLP policy structures to improve consistency across systems and reduce operational friction.
  • Establishes repeatable dashboards and metrics to measure data protection coverage, control effectiveness, false-positive rates, and remediation timelines.
  • Embeds privacy-by-design principles into product and engineering workflows by providing structured guidance on secure data flows, storage patterns, logging, and access controls.
Innovative:
  • Applies forward-looking data protection strategies to address evolving cloud, collaboration, and SaaS risks, ensuring controls adapt to modern work patterns and distributed environments.
  • Leverages AI and automation to enhance data classification accuracy, improve anomaly detection in DLP alerts, and generate actionable insights from data protection telemetry.
  • Continuously evaluates emerging data governance and privacy engineering capabilities, translating new tooling and best practices into scalable improvements across the enterprise.
Requirements:
  • Bachelor's degree in information security, computer engineering, or a related field (or equivalent experience).
  • 5+ years of experience in data security, privacy engineering, or security engineering roles.
  • Hands‑on experience with data discovery, classification, and governance platforms (e. g., Microsoft Purview, OneTrust, or similar).
  • Experience implementing and tuning DLP controls across endpoints, email, collaboration platforms, and cloud storage environments.
  • Experience implementing encryption, tokenization, and key management controls.
  • Familiarity with compliance frameworks such as SOC 2 PCI, and privacy regulations.
  • Ability to automate workflows and integrations using scripting and APIs (PowerShell, Python, or similar).
  • Strong documentation and cross‑functional collaboration skills.
  • Certifications such as CDPSE, CIPT, Security+, or similar are a plus.
  • High integrity and sound judgment when handling sensitive and confidential information.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Data Security Engineer
Data Security Engineer

YASH Technologies • Bengaluru

On-site
INR 2,500,000 - 4,500,000
EY - Cyber Security - Data Protection and Privacy Platforms Engineering - Manager
EY - Cyber Security - Data Protection and Privacy Platforms Engineering - Manager

Ernst & Young Advisory Services Sdn Bhd • Ernakulam

On-site
INR 3,500,000 - 5,500,000
Data Security Consultant
Data Security Consultant

Paramount Computer System • Tamil Nadu

On-site
INR 1,000,000 - 1,500,000
Data Protection Engineer
Data Protection Engineer

UST • Bengaluru

On-site
INR 1,500,000 - 2,800,000
Data Protection and Security Analyst
Data Protection and Security Analyst

Isha Foundation, Inc. • Coimbatore District

On-site
INR 800,000 - 1,200,000
Senior Consultant - Data Protection
Senior Consultant - Data Protection

Meta Infotech • Mumbai

On-site
INR 1,200,000 - 1,800,000
DLP Engineer
DLP Engineer

Bristol Myers Squibb • Hyderabad

On-site
INR 1,400,000 - 2,000,000
GDS Cyber-DPP-Senior-AI Data Protection Engineer
GDS Cyber-DPP-Senior-AI Data Protection Engineer

EY • Bengaluru

On-site
INR 4,500,000 - 6,500,000
Data Protection Engineer
Data Protection Engineer

IntraEdge • Bengaluru

On-site
INR 1,500,000 - 2,800,000
Data Security Analyst
Data Security Analyst

Generac • Pune District

On-site
INR 800,000 - 1,200,000