Overview
Skills
Job Details
Position :: Data Security Engineer
Location :: 100% Remote
Duration :: 6-12+ months
Interview :: Video
Job Description:
need to have unity catalog experience!
Position Summary
The Enterprise Data Security Engineer III is a senior-level technical practitioner responsible for securing and monitoring all data assets and platforms within enterprise data ecosystem. This person is involved throughout the entire data lifecycle, from inception through disposal, ensuring access to data is managed and maintained following rigorous security and governance principles. Positioned within the Chief Data & Analytics Office and in close alignment with the Information Security Office.
This role ensures trusted, compliant, and resilient data use across data engineering, advanced analytics, AI, and enterprise-wide digital transformation to enable secure, scalable, and strategic data operations. The Data Security Engineer must collaborate with technical and non-technical teams to design, implement and manage data protection processes that reduce risks across enterprise data environment.
Key Responsibilities
- Data Platform Security Frameworks:
- Design and implement comprehensive, end-to-end frameworks across modern data platforms - including Databricks, Data Lakehouse, Synapse, and Power BI.
- Enforce robust identity and access controls (RBAC, ABAC), encryption (at rest and in transit), tokenization, and key management.
- Integrate security seamlessly into advanced analytics, data pipelines, and AI/ML workflows.
- Regulatory Compliance & Data Protection:
- Conduct proactive risk assessments to identify vulnerabilities, close compliance gaps, and enhance audit readiness.
- Ensure strict adherence to data protection frameworks including HIPAA, HITECH, HITRUST.
- Define and maintain security policies aligned with regulatory mandates, business requirements, and operational objectives.
- Monitoring & Detection:
- Deploy advanced monitoring and anomaly detection across the data platform using tools like Microsoft Sentinel and Defender for Cloud Apps, and similar tools.
- Enable insider threat detection and User and Entity Behavior Analytics (UEBA) to proactively identify anomalous activity.
- Data Governance, Classification & DSPM:
- Administer Data Governance to apply classification, sensitivity labeling, and Data Loss Prevention (DLP) via Microsoft Purview or similar tools.
- Deploy Data Security Posture Management (DSPM) solutions for automated discovery, monitoring, and policy enforcement.
- Data Integration & API Security:
- Secure internal and external data pipelines, APIs, and event-driven transactions through robust encryption, authentication, and access controls.
- Support secure exchange of clinical and business data through standards like FHIR and federated data models.
- Strategic Collaboration & Advocacy:
- Act as a trusted security advisor to Data & Analytics teams-ensuring secure data solution design and translate technical security challenges and risks into actionable insights.
- Collaborate with Information Security leadership to uphold consistent policies, controls, and enterprise-wide accountability.
Skills and Experience
- 5+ years experience in data security, cloud architecture, or data engineering within modern cloud-native environments, with 3+ years technical hands-on data protection practitioner experience.
- 2+ years experience securing enterprise data platforms in provider or payer healthcare settings, with strong application of regulatory frameworks (e.g., HIPAA, HITRUST).
- Proven ability to secure APIs (including REST and FHIR), event-driven platforms, and federated data exchanges within hybrid, cloud-native environments.
- Hands-on experience supporting compliance and privacy in AI/ML model training and inference, along with implementation of insider threat detection, UEBA, and anomaly detection capabilities.
- Familiarity with privacy-enhancing technologies (PETs) such as differential privacy, synthetic data, and modern DSPM tools to support responsible data use at scale.
- Strong written and oral communication skills across varying levels of the organization.
- Excellent judgment and the ability to make quick decisions when working with complex situations.
- Track record acting with integrity, taking pride in work, seeking to excel, and being curious.
- High degree of integrity, trustworthiness, and confidence; represents the company and its management team with the highest level of professionalism.
Education Requirements
- Bachelor s degree in computer science-information security or computer science-data engineering or related technical field.
Preferred Certifications
- Microsoft Certified: Azure Security Engineer Associate
- CISSP Certified Information Systems Security Professional
- HCISPP Healthcare Information Security & Privacy Practitioner
- Other relevant certifications in cloud security, privacy, and AI governance