About this role
We are seeking a Cyber Security Engineer – Data Security to design, implement, and continuously improve security capabilities that protect sensitive data across the enterprise.
This is a hands-on security engineering role focused on understanding where sensitive data resides, how it moves, who and what can access it, and ensuring appropriate controls are implemented throughout the data lifecycle.
The engineer will work closely with Security, Infrastructure, Cloud, Data, Application, and AI teams to implement scalable data protection capabilities across cloud, SaaS, application, database, endpoint, and emerging AI environments.
Key Responsibilities:
- Design, implement, and maintain enterprise data security controls across cloud, SaaS, applications, databases, endpoints, and AI platforms.
- Implement and improve data discovery, classification, labeling, and protection capabilities for sensitive and regulated data.
- Engineer and operate Data Security Posture Management (DSPM) capabilities to identify sensitive data, excessive exposure, misconfigurations, and inappropriate access.
- Develop and tune Data Loss Prevention (DLP) controls across endpoint, cloud, email, collaboration, and SaaS environments.
- Assess how sensitive data is stored, processed, transmitted, and accessed and recommend appropriate security controls.
- Identify excessive or inappropriate access to sensitive data and partner with IAM, Privacy and platform teams to implement least-privilege access.
- Support encryption, tokenization, masking, secrets protection, and key-management strategies where appropriate.
- Develop monitoring and detection capabilities for suspicious or unauthorized access, movement, and exfiltration of sensitive data.
- Automate data security controls, assessments, monitoring, and remediation using APIs, scripting, and security tooling.
- Perform security assessments and threat modeling for systems that store or process sensitive information.
- Partner with application, cloud, data, and AI engineering teams to incorporate data protection requirements into system designs.
- Support incident investigations involving potential data exposure or exfiltration.
- Develop technical standards, security patterns, and engineering guidance for protecting sensitive data.
Minimum Qualification:
- Technical Degree in Computer Science, Cyber Security and/or a High School Diploma/GED from an accredited institution along with equivalent work experience
- Entry-level experience in at least two of the following areas: security engineering, network penetration, incident response, threat hunting, and governance risk & compliance
Preferred Qualifications:
- 3+ years of experience in cybersecurity, security engineering, cloud security, data security, or a related technical discipline.
- Hands-on experience implementing or operating enterprise data protection, DLP, DSPM, or data security technologies.
- Strong understanding of data security principles including discovery, classification, access control, encryption, data loss prevention, and monitoring.
- Experience securing data across cloud, SaaS, database, and application environments.
- Understanding of IAM concepts including authentication, authorization, RBAC, least privilege, and privileged access.
- Experience with at least one major cloud platform such as Azure, AWS, or Google Cloud.
- Experience with security automation, scripting, or APIs; Python, PowerShell, or comparable experience preferred.
- Strong understanding of security architecture and common data-exfiltration techniques.
- Ability to troubleshoot complex technical issues and translate identified risks into practical engineering solutions.
- Strong written and verbal communication skills with the ability to collaborate across security and engineering teams.
- Experience implementing or operating DSPM/CNAPP/data security platforms in large enterprise environments.
- Experience with enterprise DLP technologies across endpoint, email, cloud, and SaaS environments.
- Experience with Microsoft Purview, Microsoft Defender, or comparable enterprise data security technologies.
- Experience securing structured and unstructured data across databases, data lakes, warehouses, object storage, and collaboration platforms.
- Experience with encryption, key management, tokenization, masking, or secrets-management technologies.
- Experience developing automated data security controls and remediation workflows.
- Experience with Infrastructure as Code and incorporating security controls into cloud deployments.
- Understanding of data security considerations for generative AI and agentic AI, including preventing inappropriate access to or disclosure of sensitive information.
- Familiarity with data governance, retention, privacy, and regulatory requirements.
- Experience protecting PHI, PII, financial, or other sensitive data in a regulated environment.
WE ARE AN EQUAL OPPORTUNITY EMPLOYER. HF Management Services, LLC complies with all applicable laws and regulations. Applicants and employees are considered for positions and are evaluated without regard to race, color, creed, religion, sex, national origin, sexual orientation, pregnancy, age, disability, genetic information, domestic violence victim status, gender and/or gender identity or expression, military status, veteran status, citizenship or immigration status, height and weight, familial status, marital status, or unemployment status, as well as any other legally protected basis. HF Management Services, LLC shall not discriminate against any disabled employee or applicant in regard to any position for which the employee or applicant is otherwise qualified.
If you have a disability under the Americans with Disability Act or a similar law and want a reasonable accommodation to assist with your job search or application for employment, please contact us by sending an email to [email protected] or calling 212-519-1798 . In your email please include a description of the accommodation you are requesting and a description of the position for which you are applying. Only reasonable accommodation requests related to applying for a position within HF Management Services, LLC will be reviewed at the e-mail address and phone number supplied. Thank you for considering a career with HF Management Services, LLC.
Know Your Rights
All hiring and recruitment at Healthfirst is transacted with a valid “@healthfirst.org” email address only or from a recruitment firm representing our Company. Any recruitment firm representing Healthfirst will readily provide you with the name and contact information of the recruiting professional representing the opportunity you are inquiring about. If you receive a communication from a sender whose domain is not @healthfirst.org, or not one of our recruitment partners, please be aware that those communications are not coming from or authorized by Healthfirst. Healthfirst will never ask you for money during the recruitment or onboarding process.
Hiring Range*:
- Greater New York City Area (NY, NJ, CT residents): $108,300 - $156,485
- All Other Locations (within approved locations): $99,100 - $147,390
As a candidate for this position, your salary and related elements of compensation will be contingent upon your work experience, education, licenses and certifications, and any other factors Healthfirst deems pertinent to the hiring decision.
In addition to your salary, Healthfirst offers employees a full range of benefits such as, medical, dental and vision coverage, incentive and recognition programs, life insurance, and 401k contributions (all benefits are subject to eligibility requirements). Healthfirst believes in providing a competitive compensation and benefits package wherever its employees work and live.
*The hiring range is defined as the lowest and highest salaries that Healthfirst in “good faith” would pay to a new hire, or for a job promotion, or transfer into this role.