We're looking for an experienced Data Protection & Identity Security Engineerto help strengthen enterprise security across identity, data protection, and cloud environments. This role is ideal for someone who enjoys solving complex security challenges, improving data governance, and building secure, scalable solutions.
You'll work alongside cybersecurity, privacy, infrastructure, and engineering teams to protect sensitive data, strengthen identity security, and automate security controls across modern cloud platforms.
What You'll Do
- Build and improve data discovery, classification, and data inventory processes across enterprise environments.
- Implement and support Data Security Posture Management (DSPM) solutions such as Securiti or BigID to identify and reduce data security risks.
- Design and support encryption, tokenization, masking, and other data protection technologies for sensitive information.
- Configure and manage role-based and attribute-based access controls while promoting least-privilege access.
- Deploy and maintain Data Loss Prevention (DLP) and Database Activity Monitoring (DAM) solutions.
- Improve detection capabilities for sensitive data exposure, insider threats, and unauthorized data access.
- Integrate security telemetry with SIEM and SOAR platforms to automate threat detection and incident response.
- Support data retention, lifecycle management, and secure data disposal processes.
- Help automate Data Subject Access Requests (DSARs) and privacy workflows.
- Partner with engineering teams to embed security and privacy controls into CI/CD pipelines and development processes.
- Assist with compliance efforts for GDPR, CCPA/CPRA, HIPAA, PCI DSS, and internal security audits.
- Investigate data security incidents, support forensic investigations, and implement long-term improvements.
- Perform security hardening, vulnerability remediation, and configuration reviews across data protection platforms.
- Participate in tabletop exercises and security assessments focused on data protection and insider risk.
- Create documentation, engineering standards, runbooks, and technical guidance for secure data handling.
- Collaborate with cybersecurity, privacy, legal, infrastructure, and engineering teams to improve enterprise security.
What We're Looking For
- 3–7 years of hands-on experience with enterprise identity and security technologies.
- Strong experience administering and securing Active Directory environments.
- Experience with Microsoft Entra ID (Azure AD).
- Experience supporting Azure AD Connect and hybrid identity environments.
- Strong understanding of Active Directory security hardening and identity security best practices.
- Experience identifying and mitigating identity-based attack paths.
- Knowledge of authentication protocols including Kerberos, NTLM, SAML, and OAuth.
- Familiarity with Tier 0 administration and identity as a security control plane.
- Strong troubleshooting and problem-solving skills.
- Excellent communication skills with both technical and non-technical stakeholders.
Preferred Skills
Experience with any of the following is a plus:
- CyberArk or other Privileged Access Management (PAM) platforms
- Saviynt or other Identity Governance & Administration (IGA) solutions
- Ping Identity or federation technologies
- HashiCorp Vault
- Keyfactor
- Public Key Infrastructure (PKI)
- Active Directory forest recovery
- Zero Trust security architecture
- Microsoft Purview DLP
- Imperva or IBM Guardium
- BigID or Securiti
What Makes You Successful
- You enjoy solving challenging security problems.
- You have a strong security-first mindset and focus on reducing risk.
- You can quickly identify issues and implement practical solutions.
- You collaborate well with cross-functional teams.
- You're comfortable working in fast-paced project environments and balancing multiple priorities.
- You take ownership and consistently deliver high-quality work.
If you're passionate about identity security, data protection, and building secure enterprise environments, we'd love to hear from you.