Senior Security Engineer - Data Security
Senior Security Engineer building and scaling data protection platforms, DLP, DSPM, and AI-driven automation across SaaS, cloud, and data warehouse environments. Requires 5+ years in security engineering and strong software engineering skills.
What You'll Do
- Design, build, and maintain security platforms, services, APIs, automation, and internal tooling that protect Sigma's data across cloud, SaaS, endpoint, and analytics environments.
- Develop scalable solutions for data discovery, classification, governance, access controls, monitoring, and protection using modern engineering practices and automation.
- Build and mature capabilities around CASB, DLP, DSPM, SSPM, insider risk, and data access governance to reduce the risk of unauthorized access, sharing, or exposure of sensitive information.
- Build and maintain DLP controls and tooling across multiple cloud, OS environments and decentralized datasets, implementing and tuning prevention capabilities that protect against sophisticated data security incidents.
- Drive automation across DLP engineering and operations by leveraging LLMs, agentic AI, and an automation-first mindset to streamline workflows, reduce manual effort, and scale data protection coverage.
- Design and implement security controls across SaaS applications, collaboration platforms, endpoints, and business-critical services.
- Partner with IT, Engineering, Privacy, Legal, and Business teams to securely enable productivity while maintaining strong data protection controls.
- Design and implement security controls for modern data platforms, data warehouses, AI-enabled systems, and cloud-native environments.
- Assess data architectures, access models, and security configurations while driving secure-by-design principles through architecture reviews, threat modeling, and security best practices.
- Continuously identify opportunities to leverage AI, automation, and modern engineering practices to solve data security challenges.
- Evaluate emerging technologies and drive adoption where they provide measurable security and operational value.
What We're Looking For
Required Qualifications
- 5+ years of hands-on experience in Security Engineering, Data Security, SaaS Security, or related cybersecurity roles.
- Bachelor or Masters in Computer Science, Cyber Security, or similar fields.
- Strong software engineering mindset with demonstrated experience building production-grade tools, automation, and security platforms.
- Proven ability to build versus buy whenever practical and create scalable internal solutions.
- Experience designing and implementing platforms like Insider threat and data protection technologies (SIEM, UBA, DSPM, SSPM, DLP, Browser Protection, Endpoint detection).
- Strong understanding of data security principles including data classification, data governance, access controls, encryption, key management, and data lifecycle management.
- Hands-on experience securing SaaS platforms, cloud environments, endpoints, collaboration systems, and modern data platforms.
- Experience leveraging AI to improve data protection, investigations, classification, and security workflows.
- Strong analytical, communication, and problem-solving skills.
Preferred Qualifications
- Experience securing Snowflake, Databricks, BigQuery, Redshift, or similar modern data platforms.
- Strong understanding of AI/LLM data protection risks, data leakage prevention, and AI governance.
- Building programs and solving complex security challenges across enterprise-wide data Security Programs.
- Experience building internal security products, platforms, and developer-focused security tooling.
- CISSP, CCSP, or equivalent certifications.
Compensation & Benefits
- Base salary range: $175k - $220k annually.
- Eligible for stock options.
- Comprehensive benefits package including generous health benefits, flexible time off, paid bonding time, 401k, commuter and FSA benefits, lunch program, and dog friendly office.
Senior Privacy Engineer
Lead privacy engineering projects protecting user data across search, browser, and AI features. Own major privacy components, participate in audits, and mentor engineers using Go, Node.js, Python, or Perl.
Product Security Engineer
Product Security Engineer embedding into engineering workflows to conduct architecture reviews, threat modeling, and penetration testing coordination while serving as GCP security SME. Requires 5-7 years experience and strong GCP and Python skills.
Senior Product Security Engineer II
Senior security engineer focused on offensive security testing, penetration testing, and scaling security practices across Instacart's product suite. Requires 7+ years in security engineering or pentesting with experience in mobile, cloud, or AI security.
Senior Security Engineer, GRC
Senior GRC engineer owning customer security questionnaires, compliance automation, risk assessments, and policy management across SOC 2, ISO 27001, and HIPAA. Requires 8+ years experience, scripting skills, and strong customer-facing communication.