Senior Data Security Engineer

I.T. Solutions, Inc.

United States

On-site

USD 160,000 - 220,000

Full time

30 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

I.T. Solutions, Inc. is seeking a Sr. Data Security Engineer in the United States to mature data protection across cloud environments, databases, and SaaS platforms. You will design, deploy, and tune DLP, DSPM, CASB, and encryption strategies, while aligning with RBAC/ABAC and least-privilege principles.

The role emphasizes hands-on engineering, data discovery, and integration with SOC workflows to automate response and reduce data exfiltration risk. Strong scripting skills are required.

Qualifications

  • 5+ years in data security, cloud, platform security, or security engineering.
  • Hands-on implementing or operating capabilities such as DLP, DSPM, CASB, data discovery, or sensitive data classification.
  • Strong understanding of data protection across cloud storage, databases, SaaS platforms, collaboration tools, endpoints, and analytics environments.
  • Experience securing AWS data services and multi-account environments, including storage permissions, encryption, logging, identity, and public exposure controls.
  • Strong understanding of IAM, least privilege, privileged access, service identities, and access-control models such as RBAC and ABAC.
  • Experience integrating security telemetry with SIEM, XDR, SOAR, or incident response workflows.
  • Ability to write automation or production-quality scripts in Python, PowerShell, Go, or a similar language.

Responsibilities

  • Build and operationalize data discovery and classification across structured and unstructured data sources.
  • Identify sensitive data such as PII, financial information, payment card data, intellectual property, credentials, and other business-critical information.
  • Develop data-flow inventories and mappings that show where sensitive data originates, how it moves, where it is stored, and who can access it.
  • Design, implement, and tune controls across DLP, DSPM, CASB, database activity monitoring, encryption, tokenization, data masking, and key management capabilities.
  • Secure data stored in AWS, databases, data lakes, warehouses, SaaS applications, collaboration platforms, endpoints, and non-production environments.
  • Develop data protection policies that account for classification, user context, business process, destination, access patterns, and exfiltration risk rather than relying only on broad blocking rules.
  • Partner with Identity, Platform, Data, and Architecture teams on RBAC, ABAC, least privilege, privileged access, service identities, and time-bound access patterns.
  • Integrate data security telemetry with SIEM, XDR, and Security Operations workflows to detect anomalous access, insider risk, data misuse, and potential exfiltration.
  • Build automation for investigation, enrichment, containment, remediation, ticketing, evidence collection, and control validation.
  • Support incident response involving sensitive data, including scoping affected information, preserving evidence, determining exposure paths, and improving controls after an event.
  • Define meaningful program metrics, including data coverage, classification accuracy, control coverage, policy effectiveness, false-positive rates, access exposure, and remediation progress.
  • Make technical decisions visible through design documents, runbooks, reference implementations, and repeatable patterns that other teams can adopt.

Skills

Data security
Cloud security
Platform security
Security engineering
DLP
DSPM
CASB
SIEM integration
Automation scripting
Python/PowerShell/Go

Tools

Microsoft Purview
Prisma Access
SIEM
XDR
SOAR

Job description

We are hiring a Sr. Data Security Engineer to help us understand where sensitive data exists, how it moves, who can access it, and how it should be protected. You will build and operationalize the technical capabilities used to Client, classify, monitor, and protect data across cloud environments, SaaS platforms, databases, analytics platforms, endpoints, and non-production systems. The goal is not simply to deploy more security tools. It is to make data protection measurable, enforceable, and sustainable across the enterprise.

This is a hands-on engineering role inside our security program. We want someone who can turn data risk into durable technical controls, tune those controls to real business workflows, and work with the SOC to automate the response to exposure, misuse, and exfiltration.

What you'll do
  • Build and operationalize data discovery and classification capabilities across structured and unstructured data sources.
  • Identify sensitive data such as PII, financial information, payment card data, intellectual property, credentials, and other business-critical information.
  • Develop and maintain inventories and data-flow mappings that show where sensitive data originates, how it moves, where it is stored, and who can access it.
  • Design, implement, and tune controls across DLP, DSPM, CASB, database activity monitoring, encryption, tokenization, data masking, and key management capabilities.
  • Secure data stored in AWS, databases, data lakes, warehouses, SaaS applications, collaboration platforms, endpoints, and non-production environments.
  • Develop data protection policies that account for classification, user context, business process, destination, access patterns, and exfiltration risk rather than relying only on broad blocking rules.
  • Partner with Identity, Platform, Data, and Architecture teams on RBAC, ABAC, least privilege, privileged access, service identities, and time-bound access patterns.
  • Integrate data security telemetry with SIEM, XDR, and Security Operations workflows to detect anomalous access, insider risk, data misuse, and potential exfiltration.
  • Build automation for investigation, enrichment, containment, remediation, ticketing, evidence collection, and control validation.
  • Support incident response involving sensitive data, including scoping affected information, preserving evidence, determining exposure paths, and improving controls after an event.
  • Define meaningful program metrics, including data coverage, classification accuracy, control coverage, policy effectiveness, false-positive rates, access exposure, and remediation progress.
  • Make technical decisions visible through design documents, runbooks, reference implementations, and repeatable patterns that other teams can adopt.
What you bring
5+ years of experience across data security, cloud security, platform security, security engineering, or related technical roles.
  • Hands-on experience implementing or operating capabilities such as DLP, DSPM, CASB, database activity monitoring, data discovery, or sensitive data classification.
  • Strong understanding of data protection across cloud storage, databases, SaaS platforms, collaboration tools, endpoints, and analytics environments.
  • Experience securing AWS data services and multi-account environments, including storage permissions, encryption, logging, identity, and public exposure controls.
  • Experience with encryption, key management, tokenization, masking, secrets management, and protection of production data used in non-production environments.
  • Strong understanding of IAM, least privilege, privileged access, service identities, and access-control models such as RBAC and ABAC.
  • Experience integrating security telemetry with SIEM, XDR, SOAR, or incident response workflows.
  • Ability to write automation or production-quality scripts in Python, PowerShell, Go, or a similar language.
  • Experience tuning security controls to reduce false positives without weakening protection.
  • Comfort working directly with Data Engineering, Platform Engineering, Architecture, Security Operations, GRC, Privacy, and business stakeholders.
Nice to have
Experience with platforms such as Microsoft Purview, Prisma Access DLP/CASB, or similar data security technologies.
  • Experience securing Databricks, Amazon S3, Redshift, RDS, DynamoDB, data lakes, or enterprise analytics platforms.
  • Experience with insider-risk detection, user and entity behavior analytics, or data-exfiltration investigations.
  • Familiarity with data protection and privacy requirements associated with SOX, GDPR, ISO 27001, or NIST frameworks.
  • Experience building security controls for AI and generative AI services, including sensitive-data exposure, model inputs, retrieval systems, internal copilots, and agentic workflows.
Culture & Fit
You're comfortable working with a high degree of autonomy and can effectively prioritize your work while understanding how it supports the broader goals of the security program.
  • You're knowledgeable in your area of expertise but are also willing to step outside your comfort zone if needed.
  • You value clear, effective writing and recognize the importance of thorough documentation.
  • You enjoy collaborating with technical counterparts and can clearly communicate complex concepts to non-technical stakeholders.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Data Security Engineer
Senior Data Security Engineer

247Hire • New York (NY)

On-site
USD 150,000 - 210,000
Remote Senior Cybersecurity Engineer - Build & Own Controls
Remote Senior Cybersecurity Engineer - Build & Own Controls

Think Consulting • Columbus (OH)

On-site
USD 140,000 - 190,000
Senior Software Security Engineer / DevSecOps
Senior Software Security Engineer / DevSecOps

GTN Technical Staffing • Dallas (TX)

On-site
USD 140,000 - 195,000
Data Loss Prevention - Senior Security Engineer
Data Loss Prevention - Senior Security Engineer

Cetera Financial Group Inc • Dallas (TX)

Hybrid
USD 120,000 - 180,000
Senior Manager of Information Security
Senior Manager of Information Security

Plume • United States

On-site
USD 180,000 - 240,000
Sr. CyberSecurity Engineer
Sr. CyberSecurity Engineer

Think Consulting • Columbus (OH)

On-site
USD 140,000 - 190,000
Security Engineer
Security Engineer

Enterprise Engineering Inc. (EEI) • New York (NY)

On-site
USD 120,000 - 160,000
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Maestro Technologies, Inc. • Santa Monica (CA)

Hybrid
USD 150,000 - 210,000
Security Engineer
Security Engineer

The DATA Foundation • United States

On-site
USD 120,000 - 160,000
Senior Security Engineer
Senior Security Engineer

Chris Baily • New York (NY)

On-site
USD 150,000 - 190,000
On-site in NYC
Competitive salary