
Senior IT Security Engineer
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Massachusetts.
• Oversee the continuous administration, enhancement, and expansion of the enterprise Data Protection Program.
• Create and implement data protection roadmaps that align with business, regulatory, and security goals.
• Recognize opportunities to elevate data protection maturity and mitigate organizational risk.
• Develop metrics and reporting to showcase program effectiveness.
• Collaborate with leadership to establish long-term strategies for data governance and protection.
• Design and manage enterprise data classification frameworks.
• Develop and enforce data handling standards and protection requirements.
• Implement and oversee sensitivity labeling, encryption, and information protection controls.
• Establish classification taxonomies, data ownership models, automated classification, and data discovery capabilities.
• Design, implement, and manage enterprise Data Loss Prevention (DLP) strategies and policies.
• Analyze DLP incidents and oversee data loss investigations and response efforts.
• Execute insider risk monitoring and detection strategies.
• Assist with internal investigations involving sensitive data and policy breaches.
• Facilitate legal hold, eDiscovery, regulatory responses, data retention, and records management processes.
• Support security, privacy, and regulatory audits, risk assessments, and remediation planning.
• Design and maintain enterprise data protection architectures.
• Integrate data security tools with Security Information and Event Management (SIEM), case management, and operational platforms.
• Onboard data sources from cloud, SaaS, endpoint, and on-premises environments.
• Develop automation solutions using scripting and APIs.
• Manage tool upgrades, enhancements, health monitoring, and operational support.
• Collaborate with Security, Legal, Compliance, Privacy, IT, Data Governance, HR, and other business stakeholders.
• Over 7 years of experience in information security.
• More than 5 years of hands-on experience in supporting enterprise data protection initiatives.
• Experience in administering one or more enterprise data protection, governance, or compliance platforms.
• Proven experience in implementing DLP, information protection, data classification, and compliance solutions.
• Familiarity with working alongside Legal, Compliance, Privacy, and Audit functions.
• Experience leading large-scale enterprise security initiatives and projects.
• Must have authorization to work in the United States without current or future sponsorship (U.S. citizen or lawful permanent resident).
• Strong background in various areas such as data protection programs, data governance, data classification, information protection, sensitivity labels, encryption technologies, DLP, insider risk management, communication compliance, records management, data lifecycle management, eDiscovery, Data Security Posture Management (DSPM), cloud security, Identity and Access Management (IAM), Role-Based Access Control (RBAC), Microsoft 365 Security, endpoint security, enterprise security architecture, security monitoring and SIEM integration, as well as security automation and scripting.
• Knowledge of compliance frameworks including NIST, ISO 27001, CIS, PCI-DSS, HIPAA, GDPR, and SOX.
• Full-time, exempt position.
• Remote work options available.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.