Data Security Architect

Compunnel

• $125K — $150K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8-12 years of experience in data security, cloud security, or security architecture.
  • Strong experience with cloud-native data platforms like Snowflake and Databricks.
  • Proven ability to design scalable data classification and tagging models.
  • Experience with DLP, masking, and encryption controls.
  • Deep understanding of data protection architecture and lifecycle management.

Responsibilities

  • Define enterprise data security architecture and control strategies.
  • Establish standard control patterns for data classification and encryption.
  • Ensure scalability of data protection across various environments.
  • Design integration across multiple cloud platforms and applications.
  • Translate data risk insights into technical control requirements.

Benefits

  • Opportunity to lead architecture and design for data protection.
  • Collaborative environment with cross-functional teams.
  • Focus on innovative data security solutions.
  • Engagement with emerging technologies and tools.
  • Professional development opportunities in data security.
Full Job Description
Job Summary
The Data Security Architect is responsible for defining enterprise architecture, control patterns, and design standards for protecting sensitive data across platforms including Snowflake, Databricks, M365, Box, and cloud applications. This role focuses on designing and architecting data security capabilities such as DSPM, DLP, and data platform controls, ensuring they are correctly integrated and scalable across the enterprise. The position provides architecture and design leadership focused on data protection rather than day-to-day program execution or tool operations.

Key Responsibilities
• Define the enterprise data security architecture, including data discovery and classification, DSPM integration, DLP/CASB control strategies, data platform security controls, and application/API data protection patterns.
• Establish standard control patterns for data classification and tagging, encryption, tokenization, masking, RBAC, ABAC, RLS, and data movement and sharing controls.
• Ensure consistency and scalability of data protection across SaaS, cloud, and application environments.
• Design and drive integration across Snowflake, Alation, Entra ID, M365, Box, AWS, Azure, and GCP environments.
• Ensure alignment between DSPM findings, DLP policies, and data platform controls.
• Translate data risk insights into technical control implementation requirements.
• Develop and maintain a Data Security Reference Architecture.
• Define secure design patterns and implementation guidance for data engineering, application development, and cloud platform teams.
• Enable engineering teams to embed data protection into systems and workflows.
• Partner with data security program, data security engineering, and Cyber Defense/SOC teams to provide architectural direction and design input.
• Define and evolve data protection standards aligned with data management policies and regulatory requirements.
• Evaluate emerging DSPM, DLP/CASB, and data platform-native security capabilities.
• Continuously improve architecture based on new data risks, platform evolution, and feedback from operations and engineering teams.

Required Qualifications
• 8-12 years of experience in data security, cloud security, or security architecture.
• Strong experience designing security for cloud-native data platforms such as Snowflake and Databricks.
• Experience with SaaS and collaboration environments such as M365 and Box.
• Experience with enterprise identity systems such as Entra ID.
• Proven ability to design and scale data classification and tagging models.
• Experience designing data protection controls including DLP, masking, and encryption.
• Experience designing access control models including RBAC and ABAC.
• Experience working across data engineering, application engineering, and cloud platform teams.
• Deep understanding of data protection architecture and lifecycle management.
• Strong understanding of data platforms, with Snowflake strongly preferred.
• Strong understanding of cloud environments, with AWS preferred and Azure/GCP familiarity.
• Working familiarity with DSPM tools such as Cyera and BigID.
• Working familiarity with CASB/DLP platforms including M365 and endpoint solutions.
• Familiarity with data catalog and governance tools such as Alation.
• Knowledge of encryption, tokenization, and data masking techniques.
• Knowledge of data access governance models and patterns.
• Understanding of regulatory frameworks including GDPR, SOC 2, and PCI DSS.
• Strong architectural thinking and system design capabilities.
• Ability to translate business data risk into technical architecture.
• Excellent collaboration and communication skills across engineering and security domains.
• Ability to communicate through architectural diagrams, whitepapers, and presentations.
• Ability to influence technical and non-technical stakeholders and align teams on architecture and standards.

Preferred Qualifications
• Experience implementing enterprise data security or DSPM programs.
• Background working with data engineering or analytics teams.
• Experience designing controls in Snowflake or similar platforms.

Certifications
• AWS Certified Solutions Architect
• CISSP
• CCSP

Similar Jobs

More Jobs at Compunnel

More Information Technology Jobs

Find similar Data Security Architect jobs: