Data Protection Engineer

VistalTech Inc

United States

On-site

USD 95,000 - 140,000

Full time

8 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

VistalTech Inc. is seeking a cybersecurity professional to lead data governance, DLP, and access governance across cloud and on-prem environments in the United States. You will partner with compliance and IT teams to refine taxonomy, enforce least-privilege, and implement sustainable governance practices.

You will manage multiple projects, analyze data exposure risks, and develop policies for PHI/PII, financial data, and research data. Strong communication and documentation skills are essential.

Qualifications

  • 2+ years of experience in cybersecurity, data protection, identity/access governance, or healthcare IT.
  • Working knowledge of HIPAA, HITECH, and PHI/PII protection requirements.
  • Hands-on experience with data loss prevention (DLP), access governance, or data classification tools.
  • Ability to manage multiple projects, collaborate across IT and business teams, and drive remediation efforts.
  • Excellent analytical, documentation, and communication skills.

Responsibilities

  • Perform enterprise-wide data discovery using Varonis and Purview to identify PHI, PII, confidential data, and high-risk exposures.
  • Configure and maintain data classification and labeling policies across M365 (Outlook, OneDrive, SharePoint, Teams).
  • Partner with the Patient Safety and Compliance teams to refine classification taxonomy and retention requirements.
  • Identify and remediate excessive file permissions, global access, stale access, and vulnerable ACL structures.
  • Work with business units and system owners to document data flows and enforce least-privilege access models and sustainable governance practices.
  • Support automation workflows for secure data provisioning and permission change management.
  • Implement, monitor, and tune DLP controls across Purview, Zscaler, and endpoint channels.
  • Build policies for PHI/PII, financial data, research data, insider risk scenarios, and restricted data classes.
  • Investigate DLP alerts, analyze user behavior, and coordinate remediation or coaching sessions.
  • Maintain dashboards highlighting risk reduction, high-risk data sets, permission cleanup progress, and DLP control effectiveness.
  • Provide reports to leadership, Cybersecurity Governance Council, and the Architecture Review Board.
  • Track metrics such as open access reduction, stale data elimination, labeling adoption, and incident trends.
  • Investigate data exposure incidents, including misdirected communications, oversharing, or unauthorized access.
  • Work with Legal, Compliance, and IR teams to assemble evidence, timelines, and regulatory reports.
  • Identify control gaps and implement process improvements to prevent recurrence.
  • Evaluate data protection risks for AI use cases (e.g., data leakage, re-identification, prompt injection).
  • Validate that AI-connected systems follow TGH’s data minimization and PHI boundary rules.
  • Support readiness for audits and certification programs (HIPAA, NIST CSF, internal and external audits).

Skills

DLP tools
Access governance
Data classification
Analytical skills
Documentation skills
Communication skills
Project management
Cross-functional collaboration

Education

Bachelor’s degree in Information Security, Health Information Management, Computer Science, or related field

Tools

Varonis
Microsoft Purview Information Protection
Zscaler DLP
Epic

Job description

  • Perform enterprise-wide data discovery using Varonis and Purview to identify PHI, PII, confidential business data, and high-risk exposures
  • Configure and maintain data classification and labeling policies across M365 (Outlook, OneDrive, SharePoint, Teams)
  • Partner with the Patient Safety and Compliance teams to refine classification taxonomy and retention requirements
  • Identify and remediate excessive file permissions, global access, stale access, and vulnerable ACL structures
  • Work with business units and system owners to document data flows and enforce least-privilege access models and sustainable governance practices
  • Support automation workflows for secure data provisioning and permission change management
  • Implement, monitor, and tune DLP controls across Purview, Zscaler, and endpoint channels
  • Build policies for PHI/PII, financial data, research data, insider risk scenarios, and restricted data classes
  • Investigate DLP alerts, analyze user behavior, and coordinate remediation or coaching sessions
  • Maintain dashboards highlighting risk reduction, high-risk data sets, permission cleanup progress, and DLP control effectiveness
  • Provide reports to leadership, Cybersecurity Governance Council, and the Architecture Review Board
  • Track metrics such as open access reduction, stale data elimination, labeling adoption, and incident trends
  • Investigate data exposure incidents, including misdirected communications, oversharing, or unauthorized access
  • Work with Legal, Compliance, and IR teams to assemble evidence, timelines, and regulatory reports
  • Identify control gaps and implement process improvements to prevent recurrence
  • Evaluate data protection risks for AI use cases (e.g., data leakage, re-identification, prompt injection)
  • Validate that AI-connected systems follow TGH’s data minimization and PHI boundary rules
  • Support readiness for audits and certification programs (HIPAA, NIST CSF, internal and external audits)
Required Skills & Experience
  • Bachelor’s degree in Information Security, Health Information Management, Computer Science, or related field
  • 2+ years of experience in cybersecurity, data protection, identity/access governance, or healthcare IT
  • Working knowledge of HIPAA, HITECH, and PHI/PII protection requirements
  • Hands-on experience with data loss prevention (DLP), access governance, or data classification tools
  • Ability to manage multiple projects, collaborate across IT and business teams, and drive remediation efforts
  • Excellent analytical, documentation, and communication skills
Nice to Have Skills & Experience
  • Experience with Varonis, Microsoft Purview Information Protection/DLP, Zscaler DLP, or similar platforms
  • Familiarity with Epic, unstructured data repositories, clinical workflows, and PHI handling practices
  • Understanding of identity & access management (IAM), least-privilege principles, and shared-drive governance
  • Certifications such as HCISPP, CISSP, GIAC GSEC, COMPTIA Security+ or CySA+, or similar
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Data Protection Consultant – Purview, DLP & AI Security
Data Protection Consultant – Purview, DLP & AI Security

Jobtailor • United States

On-site
USD 150,000 - 190,000
Data Protection Analyst
Data Protection Analyst

PwC • United States

Hybrid
USD 120,000 - 180,000
Data Security Specialist
Data Security Specialist

Milbank LLP • New York (NY)

On-site
USD 140,000 - 160,000
Data Loss Prevention -DLP Analyst
Data Loss Prevention -DLP Analyst

Compunnel, Inc. • Quincy (MA)

On-site
USD 90,000 - 115,000
Senior Data Protection Specialist
Senior Data Protection Specialist

Security1stconsulting • Boston (MA)

On-site
USD 120,000 - 180,000
Mid-Level Data Protection, DLP Analyst
Mid-Level Data Protection, DLP Analyst

Jobtailor • United States

On-site
USD 90,000 - 120,000
Data Security Administrator
Data Security Administrator

Jobtailor • City of Syracuse (NY)

Hybrid
USD 90,000 - 120,000
Data Protection Leader
Data Protection Leader

Collective Insights Careers • Atlanta (GA)

On-site
USD 140,000 - 200,000
Data Security Analyst
Data Security Analyst

clarivate • Kansas City (MO)

Hybrid
USD 105,000 - 145,000
Senior Information Security Engineer - Data Protection & Insider Risk
Senior Information Security Engineer - Data Protection & Insider Risk

Cravath, Swaine & Moore LLP • New York (NY)

Hybrid
USD 160,000 - 200,000
Medical, dental, vision insurance
401(k) plan with company match
Paid time off and health club benefits
+1