
Senior IT Security Engineer
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Massachusetts.
• Oversee the continuous management, enhancement, and expansion of the enterprise Data Protection Program.
• Create and implement data protection roadmaps that align with business, regulatory, and security goals.
• Identify opportunities to enhance data protection maturity and mitigate organizational risks.
• Establish metrics and reporting systems to demonstrate the effectiveness of the program.
• Collaborate with leadership to define long-term strategies for data governance and protection.
• Design and sustain enterprise data classification frameworks.
• Develop and govern standards for data handling and protection requirements.
• Implement and oversee sensitivity labeling, encryption, and information protection controls.
• Create classification taxonomies and data ownership models in partnership with Data Governance teams.
• Develop automated classification and data discovery mechanisms across both structured and unstructured repositories.
• Design, implement, and manage enterprise Data Loss Prevention (DLP) strategies and policies.
• Analyze DLP incidents and refine policies to enhance effectiveness while minimizing disruptions to business operations.
• Establish processes for data loss investigation and response.
• Implement and maintain insider risk monitoring capabilities and detection strategies.
• Support internal investigations involving sensitive data and policy violations in collaboration with HR, Legal, and Compliance.
• Assist with legal hold, eDiscovery, and regulatory response processes.
• Develop strategies for data retention and disposition, and manage records management controls.
• Establish defensible processes for preservation and collection.
• Support security, privacy, and regulatory audits.
• Map compliance requirements to technical controls and assist with risk assessments and remediation planning.
• Design and maintain enterprise data protection architectures.
• Integrate data security tools with Security Information and Event Management (SIEM), case management, and operational platforms.
• Onboard data sources from cloud, SaaS, endpoints, and on-premises environments.
• Develop automation solutions using scripting and APIs.
• Manage tool upgrades, enhancements, health monitoring, and operational support.
• A minimum of 7 years of experience in information security.
• At least 5 years of hands-on experience in supporting enterprise data protection initiatives.
• Proficiency in administering one or more enterprise data protection, governance, or compliance platforms.
• Experience in implementing DLP, information protection, data classification, and compliance solutions.
• Familiarity with working alongside Legal, Compliance, Privacy, and Audit functions.
• Proven experience in leading enterprise-scale security initiatives and projects.
• Authorization to work in the United States without current or future sponsorship (U.S. citizen or lawful permanent resident).
• Strong expertise in several of the following areas: Data Protection Programs, Data Governance, Data Classification, Information Protection, Sensitivity Labels, Encryption Technologies, Data Loss Prevention (DLP), Insider Risk Management, Communication Compliance, Records Management, Data Lifecycle Management, eDiscovery, Data Security Posture Management (DSPM), Cloud Security, Identity and Access Management (IAM), Role-Based Access Control (RBAC), Microsoft 365 Security, Endpoint Security, Enterprise Security Architecture, Security Monitoring and SIEM Integration, Security Automation and Scripting.
• Knowledge of compliance frameworks including NIST, ISO 27001, CIS, PCI-DSS, HIPAA, GDPR, and SOX.
• Full-time, exempt position.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.