Data Security Engineer
The job description
Tech stack. DLP platforms (Symantec, Microsoft Purview), data classification tools, encryption and tokenization, BigID or Securiti, SQL, Python, cloud data services, data lineage tooling
About the role
You will protect the data itself for a technology company handling sensitive customer and business information at massive scale across regions. The team classifies data, governs where it flows, and ensures encryption and access policies follow it into every warehouse, lake, and application. You will build discovery coverage, deploy preventive controls, and partner with data engineers on controls that survive contact with real pipelines. This role matters because network perimeters fail and endpoints get compromised, but well-governed data stays protected even when everything around it does not, which makes your work the organization's last line of defense. Your work makes privacy compliance a natural byproduct of good engineering.
What you will achieve
- Classify 90 percent of production data stores by sensitivity within your first year, with accountable data owners assigned and recorded for each.
- Deploy DLP policies blocking exfiltration of regulated data while holding false positive rates under 5 percent for legitimate business workflows.
- Implement tokenization and format-preserving encryption for the highest-risk data fields so production systems never handle raw sensitive values.
- Build recurring data access reviews revoking stale permissions quarterly across warehouses, lakes, and analytics platforms.
- Deliver the authoritative data inventory and lineage map powering privacy compliance responses and rapid breach scoping.
What you will bring
Must-haves
- 2 to 5 years in data security, data engineering, or security engineering with a strongly data-centric focus.
- Experience with DLP, data classification, or data loss prevention tooling in complex enterprise environments.
- Strong SQL skills and familiarity with data warehouse, data lake, and streaming pipeline architectures.
- Understanding of encryption, tokenization, and data masking techniques appropriate for sensitive information.
- Knowledge of privacy regulations such as GDPR and CCPA and their concrete technical implementation implications.
- Ability to partner with data engineering teams on controls that fit their workflows instead of fighting them.
- Precision with policy tuning: you reduce risk without breaking the analytics the business depends on.
Nice-to-haves
- Experience with data discovery platforms such as BigID or Securiti.
- Familiarity with differential privacy or other privacy-enhancing technologies.
- Background in data governance, cataloging, or records management programs.
- Knowledge of cross-border data transfer mechanisms and controls.
Google
Microsoft
CrowdStrike
Palo Alto Networks
Cisco
Okta