The Technical Data Protection function is responsible for implementing and operating technical controls that protect the company’s sensitive, confidential, personal, financial, and payment data.
Data Security Engineer will be responsible for the practical implementation, configuration, integration, and continuous improvement of DLP and other data protection technologies across endpoints, cloud platforms, collaboration services, data repositories, and business systems. The role will work closely with the Data Security Architect, SOC, IT, DWH, Infrastructure, Product, Legal, Privacy, and Compliance teams.
Challenges that await you:
- Implementing, configuring, and operating DLP controls across endpoints, cloud services, email, collaboration platforms, and data storage environments.
- Creating and maintaining DLP policies for personal, financial, payment, confidential, and other sensitive data.
- Integrating data classification and labelling with technical enforcement and monitoring controls.
- Developing detection logic based on data types, labels, content patterns, context, user behaviour, destinations, and business processes.
- Investigating DLP alerts and potential data leakage cases in collaboration with SOC, Legal, Privacy, HR, and relevant business teams.
- Tuning policies to reduce false positives while maintaining effective protection and monitoring coverage.
- Implementing data discovery and scanning processes to identify sensitive data stored across corporate environments.
- Supporting the implementation of encryption, masking, tokenisation, access controls, and other technical data protection mechanisms.
- Collecting DLP and data security events in SIEM and creating monitoring dashboards, alerts, and operational metrics.
- Integrating data protection tools with SIEM, Jira, identity platforms, cloud services, and automation workflows.
- Automating repetitive operational tasks, policy deployment, evidence collection, reporting, and incident enrichment.
- Testing data protection controls and validating that policies work as expected before production rollout.
- Maintaining technical documentation, operating procedures, implementation guides, and response playbooks.
- Supporting onboarding of new systems, repositories, data sources, and business processes into the data protection framework.
- Identifying control gaps and proposing technical improvements based on incidents, testing results, and monitoring data.
- Supporting audits and regulatory assessments by providing technical evidence of implemented data protection controls.
Our technology stack:
Data Protection
- Endpoint, email, cloud, and collaboration DLP.
- Google Workspace and Google Drive security controls.
- Data discovery and classification technologies.
- Encryption, masking, and tokenisation solutions.
- Data access and activity monitoring.
Security Monitoring & Automation
- Elastic Stack - Elasticsearch, Kibana, ES|QL, and Detection Rules.
- Jira Service Management.
- Python and Bash.
- n8n and security automation workflows.
- SOAR technologies.
Cloud & Infrastructure
- AWS and cloud-native security services.
- Kubernetes and Docker.
- Snowflake, PostgreSQL, Amazon Aurora, Amazon S3, and related technologies.
- GitLab CI/CD.
- OIDC/SAML SSO and RBAC.
What makes you a great fit:
- 1+ years of experience in Information Security, Security Engineering, Data Security, DLP, or a related technical role.
- Practical experience implementing or operating DLP, data classification, data discovery, or cloud security controls.
- Understanding of sensitive data types, data flows, data handling risks, and common data leakage scenarios.
- Experience creating, testing, and tuning security policies and detection rules.
- Understanding of encryption, masking, tokenisation, access control, and secrets protection.
- Experience analysing security events, investigating alerts, and documenting findings.
- Familiarity with cloud services, enterprise collaboration platforms, and modern data environments.
- Basic scripting or automation skills using Python, Bash, APIs, or workflow automation tools.
- Strong troubleshooting skills, attention to detail, and a structured approach to technical implementation.
- Ability to collaborate with technical and non-technical teams.
- English B1+ for working with documentation, tools, and international teams.
-
Your bonus skills:
- Experience with Google Workspace DLP, endpoint DLP, CASB, or similar security technologies.
- Experience with data discovery and classification across cloud storage, databases, or DWH platforms.
- Familiarity with Elastic Stack or another SIEM platform.
- Experience with AWS, Snowflake, PostgreSQL, or Kubernetes.
- Understanding of PCI DSS, privacy regulations, and financial data protection requirements.
- Experience integrating security products through APIs.
- Experience building dashboards, reports, or automated security workflows.
- Relevant security, cloud, or data protection certifications