13 Aug
|
Equinix
|
Ontario
The Digital Information Security Engineering team is seeking a Principal Data Security Architect to define, design, and influence the enterprise’s most complex data protection capabilities across SaaS, web, endpoint, and cloud environments.
This is an individual-contributor role for data-centric security — a hands‑on technical leader who sets architectural direction, builds reference implementations, and solves the hardest data protection problems at enterprise scale
The ideal candidate will focus on protecting sensitive data throughout its lifecycle, enabling privacy‑by‑design architecture, the end‑to‑end technical design for CASB, DSPM, eDLP, advanced content detection (EDM/IDM), secure file sharing, and translate those capabilities into durable, measurable risk reduction.
Beyond engineering, the role shapes enterprise data governance strategy and partners closely with the Data Protection Product Manager to set roadmap and priorities
Own the enterprise reference architecture for data‑centric security across SaaS, web, endpoint, and cloud
Define the architecture patterns, design standards, and guardrails that engineering teams build against
Lead design for the most complex, novel, or high‑risk problems — articulating options, trade‑offs (security vs. usability vs. cost vs. operability), and a clear recommendation
Serve as the top technical authority and design‑review escalation point for the data protection function
Provide hands‑on mentorship and technical direction to senior engineers without formal reporting authority
Prove out emerging technologies through hands‑on POCs and pilots before enterprise adoption
Architect enterprise‑wide continuous discovery and classification of sensitive data across SaaS applications, cloud storage and object stores, and unstructured repositories
Design the posture‑analysis model for overshared or publicly exposed data, sensitive data sprawl, and misconfigured access controls
Establish risk‑based, automated remediation workflows in partnership with data owners and application teams
Define continuous monitoring of data exposure and compliance posture at scale
Design the enterprise eDLP architecture to inspect and control data in motion across web and cloud channels
Own advanced detection strategy, including Exact Data Match (EDM) for structured sensitive data (PII, PCI, financial datasets) and Indexed Document Matching (IDM) for unstructured documents and intellectual‑property protection
Establish the engineering lifecycle for EDM data sets and IDM fingerprinting repositories — covering scale, freshness, and integrity
Define real‑time enforcement models (block, quarantine, alert, coach) balanced against business disruption
Set the detection‑tuning standards that systematically drive down false positives and false negatives
Architect secure data‑transfer controls across web uploads/downloads, SaaS file sharing and collaboration tools, and third‑party/external data exchanges
Design safeguards against unauthorized data exfiltration, risky upload behavior, and unapproved sharing channels
Ensure controls enable legitimate business collaboration while maintaining strong data protection
Design inline and API‑based CASB architecture to secure enterprise SaaS platforms (e.g., collaboration suites, CRM, productivity clouds)
Define granular access and session controls: inline transaction control (upload/download restrictions), session enforcement (block, coach, isolate, redact), and adaptive policy based on user, device, and risk context
Establish detection and mitigation strategy for Shadow IT, OAuth app abuse, and SaaS misconfiguration or oversharing
Align CASB architecture with Zero Trust principles and least‑privilege access models
Shape enterprise data governance strategy, connecting data classification, ownership, handling standards, and control enforcement into a coherent model
Translate regulatory and framework obligations (e.g., NIST, PCI DSS, privacy regimes) into enforceable technical controls and data‑handling standards
Partner with legal, privacy, compliance, and data‑owner communities to align governance policy with technical reality
Define the data classification taxonomy and control mappings that downstream tooling enforces
Partner with the Data Protection Product Manager to set the multi‑quarter roadmap and prioritize investment
Provide technical, feasibility, sequencing, and level‑of‑effort assessments that inform prioritization decisions
Translate business and risk drivers into an actionable, engineering‑grounded capability roadmap
Represent the technical point of view in trade‑off and prioritization discussions
Define the data protection metrics model: sensitive data exposure trends, policy enforcement effectiveness, and data exfiltration attempts
Establish standards for reviewing and tuning DLP and CASB alerts, focused on exfiltration and misuse
Drive data risk assessments and continuous control validation
Ensure policies maintain high efficacy with low business disruption
Bachelor’s or Master’s degree in Computer Science, Information Security, or a related field — or equivalent demonstrated experience10–15+ years in data protection or security engineering, including significant time operating at a senior, staff, or principal levelProven ability to design and operate data protection controls at enterprise scaleDemonstrated ability to make and defend architectural trade‑offs across security, usability, cost, and operabilityExpertise implementing Zero Trust data protection strategiesDeep, hands‑on architecture and engineering experience across CASB (inline and API modes), DSPM, eDLP, Exact Data Match (EDM), and Indexed Document Matching (IDM)Strong command of data classification and content inspection, data exfiltration vectors and prevention techniques, and SaaS/cloud data security risksStrong understanding of identity, access control, and conditional access modelsStrong programming/scripting skills (Python preferred) applied to real automation and integration workHands‑on experience with REST APIs and security integrations, SIEM/SOAR platforms, and cloud environments (AWS, Azure, GCP)Demonstrate elite analytical and tuning expertise, especially with EDM/IDMTake a data‑first approach to security, focused on measurable risk reductionBe deeply hands‑on — an architect who still builds, not only advisesThrive in a quick‑paced, diverse, and constantly evolving environmentInfluence and elevate senior engineers and cross‑functional partners without formal authorityBe proactive, curious, and relentless about improving data protection coverage and accuracyMissteps or failed approaches and what they changed as a resultThe concrete business and security problem being solved, the real‑world constraints, and why the chosen approach won over the alternatives consideredSpecific enterprise data protection solutions they personally architected and implemented — not merely oversaw or advised onHow they built, scaled, and maintained EDM/IDM detection in production and measurably improved accuracy over timeThis role requires evidence of real, production‑grade work — not theoretical familiarity or vendor exposure alone. Candidates should be prepared to walk through, in concrete technical detail:How their designs reduced actual risk, supported by metrics and outcomes
#J-18808-Ljbffr
📌 Principal Data Security Architect (Ontario)
🏢 Equinix
📍 Ontario