Sr Technical Data Security Architect- Remote (Anywhere in the U.S.)

Sr Technical Data Security Architect- Remote (Anywhere in the U.S.)

Vollzeit 60000 - 80000 € / Jahr (geschätzt) Homeoffice (teilweise)
GuidePoint Security

Auf einen Blick

  • Aufgaben: Entwickle und implementiere Sicherheitsarchitekturen für Daten in der Microsoft-Cloud.
  • Unternehmen: Wachsendes Unternehmen im Bereich Datensicherheit mit flexibler Remote-Arbeit.
  • Vorteile: Attraktives Gehalt, Gesundheitsleistungen, flexible Arbeitszeiten und Weiterbildungsmöglichkeiten.
  • Weitere Informationen: Dynamisches Team mit hervorragenden Karrierechancen und Mentoring-Programmen.
  • Warum dieser Job: Gestalte die Zukunft der Datensicherheit und arbeite an innovativen Projekten.
  • Qualifikationen: Mindestens 5 Jahre Erfahrung in Datenarchitektur oder Informationssicherheit.

Das prognostizierte Gehalt liegt zwischen 60000 - 80000 € pro Jahr.

Position Summary

We are seeking an experienced and strategic Senior Technical Data Security Architect to join our growing data platform team.

In this highly visible role, you will be responsible for designing, implementing, and governing enterprise‑grade data security frameworks across the Microsoft data ecosystem and Databricks lakehouse platform.

You will serve as the authoritative technical expert on data protection, privacy, access governance, and compliance, partnering closely with engineering, architecture, and business stakeholders to embed security by design at every layer of the data stack.

Key Responsibilities

  • Data Security Architecture & Strategy
  • Design and maintain end‑to‑end data security architecture across Microsoft Azure, Microsoft Fabric, Azure Synapse Analytics, Azure Data Lake Storage (ADLS Gen2), and Databricks Lakehouse Platform.
  • Define and enforce enterprise data classification, labeling, and handling standards aligned with Microsoft Purview Information Protection.
  • Develop reference architectures and security blueprints for data ingestion, transformation, storage, and consumption layers.
  • Lead threat modeling sessions for data pipelines and analytics workloads, identifying and mitigating risks proactively.
  • Establish a Zero Trust data security model across all data platforms and integration points.
  • Microsoft Data Technologies - Security Focus
  • Architect and govern data security controls within Microsoft Fabric, including workspace‑level and item‑level permissions, sensitivity labels, and One Lake security.
  • Design role‑based access control (RBAC) and attribute‑based access control (ABAC) strategies across Azure Data Factory, Azure Synapse, Azure Databricks, and Azure SQL.
  • Implement and operationalize Microsoft Purview for data catalog governance, data lineage, and automated sensitivity classification across hybrid and multi‑cloud data estates.
  • Configure and manage Azure Private Endpoints, VNet integration, and network security groups for data services to eliminate public exposure.
  • Oversee encryption strategies including Azure Key Vault integration, customer‑managed keys (CMK), and data‑at‑rest / data‑in‑transit encryption standards.
  • Partner with identity teams to enforce Entra ID Conditional Access policies, Privileged Identity Management (PIM), and managed identities for data service authentication.
  • Lead the implementation and tuning of Microsoft Defender for Cloud data security posture management (DSPM) capabilities.
  • Databricks Security Architecture
  • Architect and implement Unity Catalog as the enterprise‑wide data governance layer across Databricks workspaces, including metastore design, catalog/schema/table‑level permissions, and row/column‑level security.
  • Design Databricks workspace security including network isolation (no‑public‑IP, v Net injection, private link), cluster policies, and IP access lists.
  • Define and enforce Databricks credential passthrough, service principal governance, and OAuth integration with Azure Entra ID.
  • Implement dynamic data masking and column‑level security policies within Unity Catalog to protect PII, PHI, and sensitive financial data.
  • Establish Delta Lake security patterns including table ACLs, fine‑grained access control, and audit logging strategies via Databricks system tables.
  • Oversee the security of Databricks workflows, notebooks, and job clusters, including secrets management integration with Azure Key Vault‑backed secret scopes.
  • Conduct security reviews of MLflow models and Feature Store configurations to address data leakage risks in ML pipelines.
  • Compliance, Audit & Risk Management
  • Ensure data platform compliance with relevant regulatory frameworks including GDPR, CCPA, HIPAA, SOC 2 Type II, and PCI‑DSS where applicable.
  • Design and maintain audit trail and data access logging architectures across Microsoft and Databricks platforms.
  • Conduct regular security risk assessments, gap analyses, and maturity evaluations of the data security program.
  • Develop and maintain security runbooks, policies, and standards documentation for data platform operations.
  • Coordinate with legal, compliance, and privacy teams to respond to data subject access requests (DSARs) and regulatory inquiries.
  • Cross‑Functional Collaboration & Leadership
  • Serve as the primary security advisor to data engineering, analytics engineering, and BI teams throughout the development lifecycle.
  • Lead security architecture review boards for new data initiatives, third‑party data integrations, and major platform changes.
  • Develop and lead a structured mentoring program for junior and mid‑level engineers and architects, providing one‑on‑one coaching, career guidance, and skills development roadmaps tailored to each individual’s growth goals.
  • Conduct regular knowledge‑sharing sessions, lunch‑and‑learns, and internal workshops to upskill teams on evolving data security threats, tooling, and compliance requirements across the Microsoft and Databricks ecosystems.
  • Partner with engineering managers and HR to define data security competency frameworks, leveling guides, and certification pathways that support talent development and retention across the data platform organization.
  • Establish and maintain a community of practice around data security, fostering peer learning, documentation culture, and cross‑team collaboration on shared security challenges and architectural patterns.
  • Collaborate with Sec Ops and SOC teams to build data‑specific detection rules, incident response playbooks, and forensic investigation capabilities.
  • Present security posture, risk findings, and remediation roadmaps to executive leadership and board‑level stakeholders.
  • Required Qualifications
  • 5+ years of experience in data engineering, data architecture, or information security, with at least 5 years focused on data security architecture.
  • Deep hands‑on expertise with Microsoft Azure data services: Azure Data Lake Storage Gen2, Azure Synapse Analytics, Azure Data Factory, Azure SQL Database, and Microsoft Fabric.
  • Demonstrated expertise in designing and implementing Databricks Unity Catalog, including workspace federation, metastore design, and fine‑grained access control.
  • Strong proficiency with Microsoft Purview, including data map configuration, classification rules, sensitivity labels, and policy enforcement.
  • Expert‑level knowledge of Azure identity and access management: Entra ID, Managed Identities, Conditional Access, PIM, and service principal governance.
  • Hands‑on experience with Azure Key Vault, customer‑managed encryption keys, and secrets management integration with data platforms.
  • Solid understanding of data governance frameworks and data security principles including Zero Trust, least privilege, and data minimization.
  • Experience with regulatory compliance programs (GDPR, CCPA, HIPAA, SOC 2, PCI‑DSS) as applied to data platforms.
  • Proficiency in SQL and at least one programming/scripting language (Python, Py Spark, Power Shell, or Terraform) used for security automation.
  • Strong written and verbal communication skills with the ability to articulate complex security concepts to technical and non‑technical audiences.
  • Demonstrated experience securing data workloads across multi‑cloud environments (Azure, AWS, and/or GCP), including cross‑cloud data governance, identity federation, and consistent enforcement of security policies across heterogeneous cloud estates.
  • Hands‑on experience with Snowflake data security, including Snowflake RBAC/DAC models, column‑level and row‑level security policies, dynamic data masking, network policies, Private Link configuration, and Snowflake Data Sharing governance controls.
  • Proven ability to support presales activities, including leading technical discovery sessions, contributing to RFP/RFI responses, delivering solution demonstrations, and authoring security architecture sections of client‑facing proposals and statements of work.
  • Preferred Qualifications
  • Active certifications: Microsoft
  • Certified: Azure Security Engineer Associate (AZ‑500), Microsoft

Certified: Azure Data Engineer Associate (DP‑203), Databricks Certified Data Engineer Professional, or equivalent CISSP / CISM.

  • Experience with Microsoft Sentinel for SIEM integration with data platform audit logs and anomaly detection.
  • Familiarity with Databricks Delta Sharing, Cleanroom, and cross‑cloud governance patterns.
  • Experience with infrastructure‑as‑code (Terraform, Bicep) for automated, policy‑compliant data platform deployments.
  • Background in data mesh or federated data governance operating models.
  • Exposure to AI/ML security considerations including model governance, training data security, and responsible AI frameworks within Azure ML or Databricks.
  • Experience in financial services, healthcare, or other highly regulated industries.
  • Technical Skills Summary
  • Category
  • Technologies & Tools
  • | |
  • Microsoft Data Platform

Microsoft Fabric, Azure Synapse Analytics, Azure Data Lake Storage Gen2, Azure Data Factory, Azure SQL, Azure Cosmos DB, Power BI

  • | |
  • Databricks

Unity Catalog, Delta Lake, Databricks Workflows, MLflow, Feature Store, Databricks SQL, Py Spark

  • | |
  • Snowflake & Multi‑Cloud

Snowflake RBAC/DAC, Dynamic Data Masking, Row‑Level Security, Network Policies, Private Link, Data Sharing Governance, AWS (S3 Security, IAM, Lake Formation), GCP (Big Query Security, IAM, VPC Controls)

  • | |
  • Security & Governance

Microsoft Purview, Microsoft Defender for Cloud, Azure Key Vault, Entra ID, Conditional Access, PIM

  • | |
  • Networking & Isolation

Azure Private Link, VNet Integration, Network Security Groups, Databricks VNet Injection, IP Access Lists

  • | |
  • Ia C & Automation
  • Terraform, Azure Bicep, ARM Templates, Power Shell, Azure Dev Ops, Git Hub Actions
  • | |
  • Compliance Frameworks
  • GDPR, CCPA, HIPAA, SOC 2, PCI‑DSS, NIST CSF, ISO 27001
  • | |
  • Monitoring & SIEM
  • Microsoft Sentinel, Azure Monitor, Databricks System Tables, Log Analytics Workspace

Some added perks….

  • Remote workforce primarily (U. S. based only, some travel may be required for certain positions, working on‑site may be required for Federal positions)
  • Group Medical Insurance options: Zero Deductible PPO Plan (Guide Point pays 90% of the premium for employees and 70% for family plans (spouse/children/family) or High Deductible Health Plan with HSA (Guide Point pays 100% of the employees premiums and 75% for family plans (spouse/children/family).

If you choose the High Deductible / HSA plan, GPS will contribute in 4 equal quarterly installments: ($850 per EE annually / $1750 per family annually (includes spouse/children/family options)

  • Group Dental Insurance: Guide Point pays 100% of the premium for employees and 75% of family plans
  • 12 corporate holidays and a Flexible Time Off (FTO) program
  • Healthy mobile phone and home internet allowance
  • Eligibility for retirement plan after 2 months at open enrollment
  • Pet Benefit Option
  • #J-18808-Ljbffr

Sr Technical Data Security Architect- Remote (Anywhere in the U.S.) Arbeitgeber: GuidePoint Security

GuidePoint Security ist ein hervorragender Arbeitgeber, der eine remote-first Kultur fördert und seinen Mitarbeitern flexible Urlaubszeiten sowie wettbewerbsfähige medizinische und zahnmedizinische Leistungen bietet. Mit über 1.200 Mitarbeitern und einem Fokus auf die Entwicklung von Fachkräften in der Cybersicherheit, bietet das Unternehmen zahlreiche Möglichkeiten zur beruflichen Weiterentwicklung und ist stolz darauf, als vertrauenswürdiger Berater für Fortune 500 Unternehmen und US-Regierungsbehörden zu agieren.

GuidePoint Security

Kontaktdaten:

GuidePoint Security Recruiting-Team

StudySmarter Expertenrat🤫

Wir sind der Meinung, dass du so Sr Technical Data Security Architect- Remote (Anywhere in the U.S.) erhalten könntest

Werde sichtbar in der IT-Sicherheits-Community

In der IT-Sicherheit gibt’s eine Menge Fachkreise und Konferenzen, die super für Networking sind. Schau dir Events wie die "IT-Security Convention" oder regionale Meetups an, um Gleichgesinnte und potenzielle Arbeitgeber wie GuidePoint Security kennenzulernen!

Kollaboriere an Open-Source-Projekten

Zeig dein Können und engagiere dich in Open-Source-Projekten, die auf IT-Sicherheit abzielen. Das ist nicht nur eine tolle Möglichkeit, praktische Erfahrungen zu sammeln, sondern auch, um dein Portfolio zu erweitern und Sichtbarkeit in der Branche zu gewinnen.

Nutze spezielle Jobportale für IT-Sicherheit

Schau auf spezialisierten Jobportalen wie "heise jobs" oder "StepStone" nach offenen Stellen in der IT-Sicherheit. Hier findest du viele Angebote, die nicht immer auf den großen Plattformen gelistet sind. Vergiss nicht, dich direkt auf der Website von GuidePoint Security zu bewerben!

Halte deine Skills up-to-date

In der IT-Sicherheit bleibt nichts stehen, also bleib am Ball! Investiere Zeit in Weiterbildung und besuche Online-Kurse oder Webinare zu aktuellen Sicherheitsthemen. Das zeigt nicht nur dein Engagement, sondern stärkt auch dein Profil bei GuidePoint Security.

Wir glauben, dass du diese Fähigkeiten brauchst, um Sr Technical Data Security Architect- Remote (Anywhere in the U.S.) mit Bravour zu bestehen

Datenarchitektur
Datensicherheit
Microsoft Azure
Databricks Unity Catalog
Zugriffssteuerung (RBAC, ABAC)
Microsoft Purview
Verschlüsselungsstrategien

Einige Tipps für deine Bewerbung 🫡

Zeig deine technischen Skills!:Im Bereich IT-Sicherheit ist es wichtig, dass du deine technischen Fähigkeiten klar kommunizierst. Stelle sicher, dass dein Lebenslauf relevante Zertifikate (wie CEH oder CISSP) sowie praktische Erfahrungen bei Sicherheitsprojekten oder Penetrationstests zeigt. Dies wird uns helfen, einen besseren Eindruck von deinem Fachwissen zu bekommen.

Präsentiere dein Wissen über aktuelle Trends:Wir möchten sehen, dass du über die neuesten Entwicklungen im Bereich IT-Sicherheit informiert bist. In deinem Anschreiben kannst du beispielsweise auf ein aktuelles Sicherheitsproblem oder einen neuen Standard eingehen, den du für relevant hältst. Dadurch zeigst du uns, dass du dich aktiv mit dem Thema auseinandersetzt und für die Position brennst.

Mach deine Leidenschaft deutlich:Da es sich um eine Vollzeitposition handelt, ist es wichtig, dass du uns in deinem Anschreiben zeigst, warum du in der IT-Sicherheit arbeiten möchtest. Erzähl uns von deinen Erfahrungen, wie du zur Cyber-Security gekommen bist und was dich motiviert, in dieser Branche zu arbeiten. Deine Motivation spielt eine große Rolle bei der Auswahl!

Referenzen oder Projekte anfügen:Wenn du bereits an interessanten Projekten gearbeitet hast oder relevante Referenzen hast, die deine Fähigkeiten unterstreichen, füge diese in deine Bewerbung hinzu. Das gibt uns einen Einblick in deine praktische Erfahrung und zeigt, was du wirklich drauf hast. Ein Link zu einem GitHub-Profil oder Sicherheitsanalysen, die du durchgeführt hast, wäre hier super hilfreich!

Wie man sich auf ein Vorstellungsgespräch bei GuidePoint Security vorbereitet

Sicherheitsprotokolle dominiert!

Mach dich mit den neuesten Sicherheitsprotokollen und -standards vertraut. Bei GuidePoint Security könnte es sein, dass du in technisch anspruchsvollen Fragen zu Netzwerksicherheit und Schwachstellenmanagement gefordert wirst – zeig, dass du die Grundlagen und die aktuellen Trends im Bereich IT-Sicherheit beherrschst!

Praktische Erfahrung zählt!

Bereite dich darauf vor, über frühere Projekte oder Erfahrungen im Bereich IT-Sicherheit zu sprechen. Es ist wichtig, Beispiele zu haben, wie du Sicherheitslücken identifiziert und behoben hast oder welche Tools du verwendet hast, um Systeme abzusichern. GuidePoint Security sucht nach jemandem, der die Theorie auch anwenden kann!

Teamarbeit nicht vergessen!

IT-Sicherheit ist oft Teamarbeit. Sei bereit, Fragen zu beantworten, wie du in einem Team umgehst, um Sicherheitsprobleme zu lösen. Denk auch an Beispiel-Situationen, in denen du optimal mit anderen zusammengearbeitet hast – das könnte einen großen Unterschied machen!

Motivation und Lernbereitschaft zeigen!

Da es sich um eine Vollzeitstelle handelt, wird GuidePoint Security auch wissen wollen, wie motiviert du bist und welche Schritte du unternimmst, um dein Wissen in der sich ständig weiterentwickelnden Welt der IT-Sicherheit auf dem neuesten Stand zu halten. Das könnte in einem Gespräch über deine Weiterbildung oder zertifikatsbezogenen Pläne relevant sein!