
Manager, Data Protection Services
Posted Jul 28

Posted Jul 28
This is a fully remote position, open to applicants in United States.
• Develop, own, and implement a comprehensive multi-year strategy for data protection and cryptographic services, advancing the program from operational to industry-leading status.
• Create and enforce data protection policies, standards, and frameworks that align with industry best practices such as NIST, ISO 27001, SOC 2, GDPR, CCPA, and emerging AI governance standards.
• Act as the company's definitive authority on data protection strategy, providing counsel to executive leadership regarding risk posture and investment priorities.
• Lead the design, implementation, and ongoing enhancement of the complete Data Loss Prevention (DLP) ecosystem, which includes Web Proxies & SSL Inspection, Cloud Access Security Broker (CASB), Data Classification & Tagging, Data Security Posture Management (DSPM), and AI Security Posture Management (AI-SPM).
• Manage vendor relationships, contract negotiations, and technology roadmap alignment for all data protection tools.
• Supervise the organization’s cryptographic standards and practices, encompassing key management, PKI, encryption-at-rest and in-transit standards, and secrets management.
• Promote the adoption of contemporary cryptographic controls within engineering teams, ensuring compliance with evolving standards and preparations for quantum readiness.
• Establish expectations, oversee performance, and cultivate a high-trust team environment where engineers can excel in their work.
• Over 10 years of experience in information security, including a minimum of 5 years in a leadership role managing technical security teams.
• Proven capability to develop and enhance security programs rather than merely operating them.
• Successful history of influencing cross-functional partners (Engineering, Legal, Compliance, IT, Product) without direct authority.
• Solid understanding of cryptographic principles and applied cryptography, including key management lifecycles, HSMs, PKI, and TLS/mTLS.
• Knowledge of cloud-native data security architectures across platforms such as AWS, GCP, and/or Azure.
• Familiarity with AI/ML security concepts including data poisoning, model exfiltration, prompt injection, and AI governance frameworks.
• Knowledge of agile development practices.
• Practical experience in deploying AI-SPM tools or creating security controls for LLMs.
• Relevant industry certifications such as CISSP, CCSP, CRISC, CISM, CISA, as well as AWS and Azure certifications.
• Experience in contributing to or responding to regulatory audits and certifications.
• Medical, dental, and vision insurance
• Remote-flexible workforce
• Wellness Programs
• 401(k) program with employer match
• Flexible paid time off
• Generous Parental Leave
• Donations for Doers
• Pet insurance, legal and identity protection
• Tuition reimbursement program
CVS Health
FreedomCare
Northrop Grumman
Get handpicked remote jobs straight to your inbox weekly.