Senior Data Security Engineer

I.T. Solutions, Inc.

United States

On-site

USD 150,000 - 190,000

Full time

1 hour ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

I.T. Solutions, Inc. is seeking a Sr.

Data Security Engineer to identify where sensitive data exists, how it moves, who can access it, and how it should be protected. You will build and operationalize capabilities to classify, monitor, and protect data across cloud environments, SaaS platforms, databases, analytics platforms, endpoints, and non-production systems. This hands-on engineering role focuses on turning data risk into durable technical controls, tuning controls to align with business

Qualifications

  • 5+ years of experience across data security, cloud security, platform security, security engineering, or related roles.
  • Hands-on experience implementing or operating capabilities such as DLP, DSPM, CASB, database activity monitoring, data discovery, or sensitive data classification.
  • Strong understanding of data protection across cloud storage, databases, SaaS platforms, collaboration tools, endpoints, and analytics environments.
  • Experience securing AWS data services and multi-account environments, including storage permissions, encryption, logging, identity, and public exposure controls.
  • Experience with encryption, key management, tokenization, masking, secrets management, and protection of production data in non-production environments.
  • Strong understanding of IAM, least privilege, privileged access, service identities, and access-control models such as RBAC and ABAC.
  • Experience integrating security telemetry with SIEM, XDR, SOAR, or incident response workflows.
  • Ability to write automation or production-quality scripts in Python, PowerShell, Go, or a similar language.
  • Experience tuning security controls to reduce false positives without weakening protection.
  • Comfort working directly with Data Engineering, Platform Engineering, Architecture, Security Operations, GRC, Privacy, and business stakeholders.

Responsibilities

  • Build and operationalize data discovery and classification capabilities across structured and unstructured data sources.
  • Identify sensitive data such as PII, financial information, payment card data, intellectual property, credentials, and other business-critical information.
  • Develop and maintain inventories and data-flow mappings showing origins, movement, storage, and access of sensitive data.
  • Design, implement, and tune controls across DLP, DSPM, CASB, database activity monitoring, encryption, tokenization, data masking, and key management.
  • Secure data stored in AWS, databases, data lakes, warehouses, SaaS applications, collaboration platforms, endpoints, and non-production environments.
  • Develop data protection policies that account for classification, user context, business process, destination, access patterns, and exfiltration risk.
  • Partner with Identity, Platform, Data, and Architecture teams on RBAC, ABAC, least privilege, privileged access, service identities, and time-bound access patterns.
  • Integrate data security telemetry with SIEM, XDR, and Security Operations workflows to detect anomalous access, insider risk, data misuse, and potential exfiltration.
  • Build automation for investigation, enrichment, containment, remediation, ticketing, evidence collection, and control validation.
  • Support incident response involving sensitive data, including scoping affected information, preserving evidence, determining exposure paths, and improving controls after an event.
  • Define meaningful program metrics, including data coverage, classification accuracy, control coverage, policy effectiveness, false-positive rates, access exposure, and remediation progress.
  • Make technical decisions visible through design documents, runbooks, reference implementations, and repeatable patterns that other teams can adopt.

Skills

DLP/DSPM/CASB
Cloud data security
IAM & access control
Security telemetry integration
Automation scripting
Incident response
Python/PowerShell/Go
Data discovery
RBAC/ABAC concepts

Tools

Python
PowerShell
Go
SQL

Job description

We are hiring a Sr. Data Security Engineer to help us understand where sensitive data exists, how it moves, who can access it, and how it should be protected. You will build and operationalize the technical capabilities used to Client, classify, monitor, and protect data across cloud environments, SaaS platforms, databases, analytics platforms, endpoints, and non-production systems. The goal is not simply to deploy more security tools. It is to make data protection measurable, enforceable, and sustainable across the enterprise.

This is a hands-on engineering role inside our security program. We want someone who can turn data risk into durable technical controls, tune those controls to real business workflows, and work with the SOC to automate the response to exposure, misuse, and exfiltration.

What you'll do
  • Build and operationalize data discovery and classification capabilities across structured and unstructured data sources.
  • Identify sensitive data such as PII, financial information, payment card data, intellectual property, credentials, and other business-critical information.
  • Develop and maintain inventories and data-flow mappings that show where sensitive data originates, how it moves, where it is stored, and who can access it.
  • Design, implement, and tune controls across DLP, DSPM, CASB, database activity monitoring, encryption, tokenization, data masking, and key management capabilities.
  • Secure data stored in AWS, databases, data lakes, warehouses, SaaS applications, collaboration platforms, endpoints, and non-production environments.
  • Develop data protection policies that account for classification, user context, business process, destination, access patterns, and exfiltration risk rather than relying only on broad blocking rules.
  • Partner with Identity, Platform, Data, and Architecture teams on RBAC, ABAC, least privilege, privileged access, service identities, and time-bound access patterns.
  • Integrate data security telemetry with SIEM, XDR, and Security Operations workflows to detect anomalous access, insider risk, data misuse, and potential exfiltration.
  • Build automation for investigation, enrichment, containment, remediation, ticketing, evidence collection, and control validation.
  • Support incident response involving sensitive data, including scoping affected information, preserving evidence, determining exposure paths, and improving controls after an event.
  • Define meaningful program metrics, including data coverage, classification accuracy, control coverage, policy effectiveness, false-positive rates, access exposure, and remediation progress.
  • Make technical decisions visible through design documents, runbooks, reference implementations, and repeatable patterns that other teams can adopt.
What you bring

5+ years of experience across data security, cloud security, platform security, security engineering, or related technical roles.

  • Hands-on experience implementing or operating capabilities such as DLP, DSPM, CASB, database activity monitoring, data discovery, or sensitive data classification.
  • Strong understanding of data protection across cloud storage, databases, SaaS platforms, collaboration tools, endpoints, and analytics environments.
  • Experience securing AWS data services and multi-account environments, including storage permissions, encryption, logging, identity, and public exposure controls.
  • Experience with encryption, key management, tokenization, masking, secrets management, and protection of production data used in non-production environments.
  • Strong understanding of IAM, least privilege, privileged access, service identities, and access-control models such as RBAC and ABAC.
  • Experience integrating security telemetry with SIEM, XDR, SOAR, or incident response workflows.
  • Ability to write automation or production-quality scripts in Python, PowerShell, Go, or a similar language.
  • Experience tuning security controls to reduce false positives without weakening protection.
  • Comfort working directly with Data Engineering, Platform Engineering, Architecture, Security Operations, GRC, Privacy, and business stakeholders.
Nice to have

Experience with platforms such as Microsoft Purview, Prisma Access DLP/CASB, or similar data security technologies.

  • Experience securing Databricks, Amazon S3, Redshift, RDS, DynamoDB, data lakes, or enterprise analytics platforms.
  • Experience with insider-risk detection, user and entity behavior analytics, or data-exfiltration investigations.
  • Familiarity with data protection and privacy requirements associated with SOX, GDPR, ISO 27001, or NIST frameworks.
  • Experience building security controls for AI and generative AI services, including sensitive-data exposure, model inputs, retrieval systems, internal copilots, and agentic workflows.
Culture & Fit

You're comfortable working with a high degree of autonomy and can effectively prioritize your work while understanding how it supports the broader goals of the security program.

  • You're knowledgeable in your area of expertise but are also willing to step outside your comfort zone if needed.
  • You value clear, effective writing and recognize the importance of thorough documentation.
  • You enjoy collaborating with technical counterparts and can clearly communicate complex concepts to non-technical stakeholders.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Data Protection & Identity Security Engineer
Data Protection & Identity Security Engineer

HeartCentrix Solutions • Town of Texas (WI)

On-site
USD 95,000 - 135,000
Senior Data Security Architect
Senior Data Security Architect

United States Digital Space LLC • San Francisco (CA)

Hybrid
USD 181,000 - 217,000
Senior Security Engineer, Data
Senior Security Engineer, Data

Genworth • Richmond (VA)

On-site
USD 80,000 - 110,000
Competitive Compensation
Comprehensive Healthcare Coverage
Generous Paid Time Off
+2
Senior Security Engineer
Senior Security Engineer

Novacoast • Salt Lake City (UT)

On-site
USD 100,000 - 130,000
Sr. Information Security Engineer
Sr. Information Security Engineer

State of Wisconsin Investment Board • Madison (WI)

On-site
USD 120,000 - 180,000
Data Security Architect – VP
Data Security Architect – VP

Jobtailor • Massachusetts

On-site
USD 150,000 - 190,000
Full Stack Software Developer / DLP Data Security
Full Stack Software Developer / DLP Data Security

Motion Recruitment Partners LLC • Plano (TX)

On-site
USD 90,000 - 120,000
Security Engineer
Security Engineer

Iceberg • Chicago (IL)

On-site
USD 120,000 - 170,000
Information Security Engineer
Information Security Engineer

Jobtailor • North Carolina

On-site
USD 110,000 - 150,000
Data Protection Engineer
Data Protection Engineer

First Student • United States

Hybrid
USD 140,000 - 190,000