Ovation Workplace Services · 1 day ago
Data Security Engineer
Ovation Workplace Services is looking for a Senior Data Security Engineer with expertise in BigID deployment and Cloud Security Architecture. This role involves managing the BigID platform, ensuring data governance and compliance, and leading cloud migration security strategies.
Cloud ManagementCyber SecurityInformation TechnologyIT Infrastructure
Responsibilities
Platform Management: Install, configure, and maintain the BigID platform across development (DEV), quality assurance (QA), and production (PROD) environments, ensuring optimal performance and stability
Data Governance & Compliance: Implement and enforce data governance policies, overseeing data classification, sensitivity labeling, data remediation (masking/redaction), and ensuring strict adherence to data privacy regulations (GDPR, CCPA, HIPAA) and internal controls
Technical Leadership & Architecture: Guide the overall architecture, design, and execution of data solutions, ensuring scalability, performance, and alignment with enterprise data strategy
Operations & Support: Manage the onboarding of new data sources, validate scan results, troubleshoot technical issues, and optimize data pipelines (using technologies like Spark and Hadoop)
Cross-Functional Collaboration: Work closely with data scientists, data engineers, product managers, and business stakeholders to meet diverse data needs and drive platform adoption across the enterprise
Development & Integration: Support and manage API integrations, develop necessary scripting (Python, Shell), and leverage cloud services (AWS, GCP) for platform expansion and integration with other tools (e.g., Alation)
Define Cloud Security Patterns: Create and document reusable security patterns and guardrails for AWS migration, ensuring teams have a secure blueprint to build against
Architecture Design & Validation: Conduct deep-dive design reviews and service validations for applications moving to the cloud. You will be the final gate of approval for security architecture
Migration Strategy Assessment: Evaluate various migration strategies (Rehost, Replatform, Refactor) to identify risks and implement compensating controls specific to data security
Threat Modeling: Lead threat modeling sessions with engineering teams to identify vulnerabilities in the design phase (shifting security left)
Business & Stakeholder Alignment: Translate complex security risks into business language. You will meet with application owners and business sponsors to discuss priorities, user experience, and risk appetite
Data Security Governance: Establish strict requirements and guidelines for data protection, encryption, and classification within the AWS environment
Qualification
Required
Proven hands-on experience with the BigID platform, covering configuration, deployment, and operational management
Deep understanding of data privacy principles, data security best practices, and compliance frameworks
Experience with major cloud platforms (AWS, GCP) and data processing tools (Spark, Hadoop)
Proficiency in scripting languages (Python, Shell)
5-7+ years in Cybersecurity with a dedicated focus on Security Architecture or Cloud Engineering
Deep, hands-on understanding of the AWS ecosystem (IAM, VPC, Security Groups, GuardDuty, KMS, etc.) and how to secure it
Proven track record of supporting cloud migration projects (on-prem to cloud or hybrid)
Experience conducting design reviews, architectural assessments, and validating service configurations
Exceptional soft skills. You must be able to hold your own in a room with non-technical business leaders and explain why a security control matters to their bottom line
Preferred
Residence in the Philadelphia or NY Metro area is a massive plus
CISSP, CCSP, or AWS Certified Security – Specialty
Familiarity with NIST, ISO 27001, or SOC2 controls as they apply to cloud infrastructure
Experience with Infrastructure as Code (Terraform/CloudFormation) and CI/CD pipeline security
Company
Ovation Workplace Services
Ovation Workplace Services offers IT solutions, managed services, security, and cloud support.
Funding
Current Stage
Growth StageCompany data provided by crunchbase