An application made for this job — a tailored resume and cover letter that speak straight to the posting.
Cetera Financial Group Inc. is hiring a Senior Data Security Engineer to lead DSPM and DLP initiatives across cloud, SaaS, and on‑prem environments.
You will discover and classify sensitive data, continuously assess exposure, and design secure data handling patterns by default. Collaborating with cloud security, IAM, application security and infrastructure teams, you will reduce data exposure, tune alerts, and support audits and regulatory obligations including FINRA and SEC with robust
Lead the design, implementation, and day to day operation of DSPM and DLP solutions. oDiscover and classify sensitive, regulated, and business critical data oContinuously assess data exposure, access paths, and misconfigurations oIdentify and prioritize data security risks across cloud, SaaS, and enterprise systems oPolicy design aligned to data classification and regulatory obligations oIntegration with endpoint, email, cloud, and SaaS enforcement points oAlert tuning, investigation workflows, and response support
Partner closely with cloud security, IAM, application security, and infrastructure teams to: oReduce unnecessary data exposure oEliminate overly permissive access and legacy data paths oImplement secure data handling patterns by design
Support audit, compliance, and risk management efforts, including: oFINRA, SEC, and internal control requirements oEvidence collection and reporting related to data protection oValidation of data ownership, access controls, and classification accuracy
Develop and maintain: oData security standards, implementation patterns, and architecture diagrams oOperational runbooks, escalation paths, and support documentation oReference designs that support consistent data security controls across environments
Act as a data security subject matter expert, advising leadership on: oData exposure trends and systemic risks oControl effectiveness and gaps oDSPM and DLP roadmap enhancements
5+ years of experience in information security engineering, with a strong focus on data security, data protection, or cloud security
Hands on experience implementing or operating one or more modern DSPM, data discovery, or data classification platforms.
Experience implementing or supporting enterprise DLP solutions, including: oEndpoint, email, SaaS, and/or cloud data controls oPolicy tuning to reduce false positives while maintaining strong coverage
Solid understanding of: oStructured and unstructured data types oData classification schemes and sensitivity levels oData lifecycle risks (creation, access, sharing, storage, and deletion)
Experience securing data across: oPublic cloud platforms (AWS and/or Azure) oSaaS applications oEnterprise file systems and data repositories
Familiarity with security and regulatory frameworks, including: oNIST CSF and NIST 800-53 oFINRA and SEC requirements oData protection and privacy control expectations
Demonstrated ability to translate technical findings into risk-based remediation priorities
#LI- Hybrid