Principal Data Security Architect

BETHLEHEM, PA, US • Posted 1 day ago • Updated 1 day ago
Contract W2
12 Months
On-site
Depends on Experience
Fitment

Dice Job Match Score™

👤 Reviewing your profile...

Job Details

Skills

  • Data Protection Strategy & Governance
  • Regulatory Compliance (NERC
  • SOX
  • CCPA
  • GDPR)
  • Azure Purview Deployment & Classification
  • Data Loss Prevention (DLP) Implementation
  • AI Data Pipeline Security (RAG
  • Vector DBs)
  • Cross-functional Stakeholder Influence
  • Snowflake
  • Azure Purview / Azure Data Catalog
  • Microsoft Defender
  • DLP Tools (Microsoft 365
  • SharePoint
  • Email)
  • Azure Synapse / Data Lake
  • SQL Server TDE
  • FHE Frameworks
  • Differential Privacy Libraries
  • Vector Databases (Pinecone
  • Weaviate)
  • RAG Pipelines
  • Tokenization Solutions
  • Data Security Posture Management Platforms
  • Azure Security Center / Azure Sentinel
  • Cloud IAM & Access Controls
  • Python / Scala
  • Git / CI/CD
  • Encryption Libraries (OpenSSL
  • libsodium)

Summary

About the Role

Callouts:

-This is a hybrid position requiring on-site presence three days per week at one of our local offices, located in Allentown, PA (Lehigh Valley) or Providence, RI.
- Looking for experience with Snowflake, Microsoft Defender, DLP tools, Azure Purview and with a data engineering background that is operating in an oversight role or assisting a larger organization using those tools.

The client is seeking a highly skilled Data Security Principal Architect to join our Cybersecurity organization. The Data Security Principal Architect will serve as a strategic leader and technical expert, responsible for defining and implementing robust data protection frameworks across our digital estate. This hybrid role bridges traditional Microsoft Information Protection and compliance tools with modern AI-centric data security practices, including encryption for LLM pipelines, secure vector stores, and legacy data remediation. This individual will collaborate closely with Security Engineering, Data Governance, Cloud Ops, and AI/ML teams to secure data throughout its lifecycle.


Responsibilities

ESSENTIAL FUNCTIONS:

Define and own the data protection strategy across structured, semi-structured, and unstructured data. Align with regulatory, legal, and business mandates (e.g., NERC, SOX, CCPA, GDPR).
Architect and deploy Azure Purview for data classification, and insider risk management policies.
Lead secure implementation of AI Data Pipelines (RAG, Vector DBs), TDE for SQL workloads, and explore applicability of Fully Homomorphic Encryption (FHE) and Differential Privacy (DP) for AI/LLM pipelines.
Develop strategies for legacy data de-duplication, archiving, and migration. Evaluate long-term retention risk and optimize lifecycle policies.
Implement and manage DLP rules across email, endpoints, cloud storage, and collaboration platforms (e.g., Microsoft 365, SharePoint).
Provide architectural guidance to product teams and AI/ML engineers. Author security patterns, threat models, and playbooks.
Evaluate and integrate third-party tools for data discovery, monitoring, and tokenization. Drive automation around classification and response.
Define DSPM Strategy and Architecture.
Define Data Incident Protocol and Playbook.
Performs other duties as assigned.
Complies with all policies and standards.
Qualifications

REQUIRED EDUCATION:

Bachelor's Degree in Computer Science, Information Security, and/or a related field or an equivalent level of experience on a year on year basis.
REQUIRED EXPERIENCE:

10+ years in information security or date architecture roles.
PREFERRED QUALIFICATIONS:

Previous experience with utilities or highly regulated industries.
Working knowledge of structured data protection in data lakes or Azure Synapse.
Experience contributing to LLM security or responsible AI design patterns.
SANS/GIAC, CISSP, or Azure Security certification.
Experience with legacy data cleanup initiatives, e.g., tape archive migration.
Experience with DSPM platform.
Strong understanding of cryptographic primitives and modern data security standards (AES, SHA, TLS, etc.) as well as an understanding of proposed quantum ready cryptography standards.
Excellent communication skills and the ability to influence technical and executive stakeholders.
Demonstrated ability to assess risk trade-offs between security, usability, and operational efficiency.
Deep interest in AI safety, responsible data stewardship, and future-proofing sensitive workloads.

Key Responsibilities & Skills
  • Data Protection Strategy & Governance
  • Regulatory Compliance (NERC, SOX, CCPA, GDPR)
  • Azure Purview Deployment & Classification
  • Data Loss Prevention (DLP) Implementation
  • AI Data Pipeline Security (RAG, Vector DBs)
  • Transparent Data Encryption (TDE) for SQL
  • Fully Homomorphic Encryption (FHE) Exploration
  • Differential Privacy (DP) for AI/LLM
  • Legacy Data Remediation & Archiving
  • Data Security Incident Response & Playbooks
  • Data Security Posture Management (DSPM) Architecture
  • Secure Tokenization & Data Discovery Tools
  • Cloud Data Security (Azure, Snowflake)
  • Cryptographic Standards (AES, SHA, TLS, Quantum-Ready)
  • Cross-functional Stakeholder Influence
Technical Skills
  • Snowflake
  • Azure Purview / Azure Data Catalog
  • Microsoft Defender
  • DLP Tools (Microsoft 365, SharePoint, Email)
  • Azure Synapse / Data Lake
  • SQL Server TDE
  • FHE Frameworks
  • Differential Privacy Libraries
  • Vector Databases (Pinecone, Weaviate)
  • RAG Pipelines
  • Tokenization Solutions
  • Data Security Posture Management Platforms
  • Azure Security Center / Azure Sentinel
  • Cloud IAM & Access Controls
  • Python / Scala
  • Git / CI/CD
  • Encryption Libraries (OpenSSL, libsodium)
Education

Bachelor's Degree in Computer Science, Information Security, Cybersecurity, Data Engineering, Computer Engineering. Preferred: Master's in Computer Science, Master's in Cybersecurity, MS in Information Security, MBA (Preferred).

Industry Experience
  • Utilities
  • Energy
  • Highly Regulated Industries
  • Cloud Services (Azure)
  • AI/ML
  • Data Engineering
  • Cybersecurity
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 90838929
  • Position Id: 8980300
  • Posted 1 day ago
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Souderton, Pennsylvania

Today

Contract

$75 - $85 hourly

Hybrid in Easton, Pennsylvania

Yesterday

Easy Apply

Full-time

$125,000 - $130,000

Allentown, Pennsylvania

Today

Full-time

USD 103,413.00 - 144,778.00 per year

Hybrid in Easton, Pennsylvania

5d ago

Easy Apply

Full-time

$120,000 - $140,000

Search all similar jobs