Faster Solutions, Smarter Talent
Lead Data Security Architect
Location
United States
Posted
2 days ago
Salary
0
Seniority
Senior
Job Description
Lead Data Security Architect
VAILEXA
• Understand objectives, scope, current-state challenges, governance expectations, and desired outcomes for the broader data security and remediation effort. • Review relevant SharePoint, OneDrive, Microsoft Purview, and Cyera context to identify where sensitive data exposure, oversharing, policy gaps, workflow constraints, or remediation backlog items are creating risk. • Connect discovery, classification, tagging, labeling, remediation, and governance activities into one integrated project approach that supports practical execution and long-term operating maturity. • Work with client teams to identify priority findings, ownership paths, decision points, remediation dependencies, and near-term actions requiring deeper technical validation. • Assess how sensitive data is currently discovered, classified, tagged, labeled, monitored, and remediated across SharePoint, OneDrive, Cyera, and Microsoft Purview. • Help define and refine classification, tagging, and labeling practices that support remediation, DLP policy alignment, access governance, and ongoing data protection objectives. • Provide architecture-level guidance on labeling strategy, DLP policy impacts, access exposure, exception handling, and control behavior across the client’s Microsoft 365 and DSPM environment. • Maintain and support client’s governance model, operational workflows, and risk reduction priorities. • Work hands-on in Cyera and Microsoft Purview to improve findings, validate root cause, confirm control behavior, and support remediation actions. • Support controlled validation activities in approved environments to confirm that remediation actions reduce exposure without creating unacceptable business disruption. • Partner with security operations, DLP, governance, compliance, and business stakeholders to ensure findings are triaged, assigned, remediated, and tracked consistently. • Define practical measures of remediation progress, including closure rate, exposure reduction, policy effectiveness, escalation clarity, and audit readiness. • Take action to integrate DSPM, Microsoft Purview, classification, labeling, DLP, access governance, and incident response workflows. • Document recommended ownership, cadence, escalation paths, and governance checkpoints so remediation can continue beyond the initial project window. • Apply solutions to business-case terms, connecting technical remediation to risk reduction, operational maturity, and governance outcomes.
Job Requirements
- 7+ years in security architecture, data security, or related cybersecurity consulting roles, with demonstrated ownership of client-facing engagements from scoping through delivery.
- Genuinely hands-on-keyboard — able to log into Cyera and Microsoft Purview directly, investigate a finding, and drive it to remediation personally, not only direct others to do so. This is a client-stated requirement, not a nice-to-have.
- Deep working knowledge of Microsoft 365 data-layer security: SharePoint Online, OneDrive for Business, Microsoft Purview (DLP, sensitivity labels, Insider Risk Management, Audit), and Entra ID access/consent fundamentals.
- Direct, practical expertise in Cyera specifically — Client 's enterprise-standard DSPM platform — including how to investigate and remediate findings, not just interpret dashboards.
- Demonstrated ability to remediate findings surfaced by Cyera or any DLP tooling — revoking access, adjusting policy, closing out flagged exposure — since the client's core concern is remediation capability, not just detection or reporting.
- Demonstrated ability to design and lead purple-team-style validation exercises (not full red-team penetration testing) — controlled, safety-guard railed simulations in test environments.
- Strong command of incident response fundamentals: MTTD/MTTC measurement, scope determination, evidence/audit readiness, and remediation tracking, including how DLP findings hand off to the SOC for incident response.
- Comfort working as a peer alongside a client's existing in-house DLP engineer — augmenting and unblocking their work, not replacing or duplicating it.
- Working knowledge of relevant regulatory and contractual notification obligations (e.g., state breach notification laws, SEC cyber disclosure rules) sufficient to guide discovery questions — not intended to substitute for the client's own legal/compliance counsel.
- Excellent stakeholder-facing communication skills; able to translate technical findings into a business case for both technical and executive audiences.
- Hands-on experience with both Cyera and Varonis is viewed favorably by the client, even though Cyera is the enterprise-standard platform — broader DSPM platform fluency is a plus.
- Relevant certifications such as CISSP, SANS/GIAC (e.g., GDSA, GCTI), or Microsoft security certifications (SC-100, SC-401).
- Experience assessing Copilot for M365 or other generative-AI access-exposure risk ahead of rollout.
- Prior experience in a public-company or regulated-industry environment (industrial, manufacturing, or similar).
- Comfort operating within a formal enterprise data governance structure spanning multiple business units — Data Governance Council, segment governance leads, RACI-based accountability model. We strive to create an environment where all employees are empowered to succeed based on their skills, performance, and dedication.
Benefits
- Health insurance
- 401(k) matching
- Flexible work hours
- Paid time off
- Remote work options
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Forward Deployed Security Engineer
Clearly AIAutomate security reviews across the SDLC. Eliminate backlogs and ship secure products faster.
• Lead end-to-end onboarding from signed contract → operational production usage • Integrate Clearly AI into enterprise systems (Jira, ServiceNow, Confluence, GitHub, etc.) • Configure review workflows aligned to each customer’s security processes • Drive implementation timelines and ensure milestones are met • Move customers from pilot → embedded operational usage • Run structured weekly and monthly customer syncs • Maintain clear agendas, owners, and next steps • Track blockers and technical dependencies • Coordinate closely with engineering on integration requirements • Ensure nothing drifts between calls • Operate inside real threat modeling, DPIA, and vendor risk workflows • Identify automation opportunities within existing processes • Help reduce review cycle time and operational backlog • Ensure product usage maps to measurable security outcomes • Conduct structured deployment reviews • Translate workflow friction into actionable feature requests • Log and manage feedback clearly in Linear • Collaborate directly with engineering on requirements and edge cases • Help triage inbound customer support issues • Identify recurring patterns in bugs or workflow friction • Build lightweight processes for tracking blockers and feature requests • Create documentation and onboarding playbooks
Database Administrator, Cybersecurity & Infrastructure
eMAGWe create e-commerce solutions for customers & partners to make their everyday lives easier.
• Lead the installation, configuration, monitoring, maintenance and troubleshooting of SQL and NoSQL database platforms, including MySQL, PostgreSQL and MongoDB. • Design, implement and maintain highly available and scalable database solutions that support business and technical requirements. • Monitor database performance and proactively identify optimization opportunities. • Administer database servers and optimize operating systems for database workloads. • Define, implement and improve backup, recovery and disaster recovery strategies. • Manage database patching and upgrade processes while ensuring service continuity. • Deploy and maintain physical servers and containerized environments supporting database services. • Develop and maintain automation and configuration management solutions. • Collaborate closely with software development, DevOps and infrastructure teams across multiple business units. • Drive database architecture planning and technical decision-making. • Mentor junior database administrators and share best practices across the team. • Develop and maintain internal procedures, operational documentation and best practices. • Respect internal procedures related to the usage of company tools and equipment.
• Develop, implement, and maintain comprehensive security policies and procedures to protect organizational data and systems. • Monitor and assess system vulnerabilities, implementing corrective actions to mitigate risks. • Lead incident response efforts, including investigation, documentation, and resolution of security breaches. • Oversee the implementation of security technologies, tools, and best practices across the organization's infrastructure. • Conduct regular security audits and assessments to identify gaps and ensure compliance with industry standards and regulations. • Collaborate with cross-functional teams to educate staff on security best practices and promote a culture of cybersecurity awareness. • Stay current with the latest trends in cybersecurity and recommend proactive improvements to strengthen defenses.
Cybersecurity Assessment and Authorization SME
ElectrosoftA leader in cybersecurity services and solutions
• Serve as a Cybersecurity Assessment & Authorization (A&A) Subject Matter Expert supporting enterprise Risk Management Framework (RMF) activities across customer Information Systems, Cloud Hosted Services, Operational Technology (OT), Platform Information Technology (PIT), Facility Related Control Systems (FRCS), and hybrid computing environments. • Lead and support all phases of the RMF lifecycle, including system categorization, security control selection, implementation, assessment, authorization, and continuous monitoring. • Develop, review, update, and maintain RMF artifacts including System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), Plans of Action & Milestones (POA&Ms), Continuous Monitoring Strategies, Privacy Impact Assessments (PIAs), Risk Assessment Memorandums (RAMs), Authorizing Official Risk Acceptance (AORA) documentation, and authorization packages. • Assess and validate security controls in accordance with DoDI 8510.01, NIST SP 800-53, DLA RMF guidance, and applicable Federal and DoD cybersecurity requirements. • Conduct security control assessments, vulnerability analyses, and compliance reviews to evaluate the effectiveness of implemented cybersecurity controls. • Support authorization decisions by identifying residual risk, evaluating compensating controls, and providing technical recommendations to Security Control Assessors (SCAs), Authorizing Officials (AOs), and senior Government leadership. • Perform cybersecurity assessments supporting enterprise IT infrastructure, Cloud environments, Operational Technology (OT), Facility Related Control Systems (FRCS), warehouse execution systems, and Platform IT (PIT) environments. • Support implementation and validation of Security Technical Implementation Guides (STIGs), Security Requirements Guides (SRGs), Assured Compliance Assessment Solution (ACAS) scans, IAVA compliance, vulnerability remediation, and continuous monitoring activities. • Utilize eMASS to manage authorization packages, track security control implementation, document vulnerabilities, and maintain authorization status throughout the system lifecycle. • Coordinate remediation efforts with ISSMs, System Owners, engineers, Information Owners, Program Managers, and Government stakeholders to resolve cybersecurity findings and maintain authorization. • Support cybersecurity inspections, audits, compliance assessments, incident response activities, and investigations involving potential cybersecurity events or unauthorized disclosures. • Prepare executive-level briefings, technical reports, dashboards, and risk assessments communicating authorization status, cybersecurity posture, and recommendations to Government leadership. • Monitor evolving cybersecurity threats, regulatory changes, and emerging technologies to ensure continued compliance and improve enterprise cybersecurity posture. • Provide technical mentorship and cybersecurity expertise to project teams while promoting continuous improvement, collaboration, and cybersecurity best practices.




