EXPERIENCE- 5-7 year of experience in data security and protection
- Must have experience with data classification and labeling tools including BigID and Microsoft Purview
- Proven experience in Data Security Posture Management (DSPM), including the assessment, management, and improvement of an organization's data security posture
- Experience in implementing DSPM tools and technologies
- Experience in identifying and mitigating data security risks through continuous monitoring and evaluation of data security practices
- Proven experience in data classification and labeling technology, controls, and processes
- Familiarity with data security considerations for AI/ML systems, including privacy, data leakage, and regulatory risk
- Experience working with stakeholders such as Data Privacy, IAM, Security Engineering, and Data Security teams
- Experience in testing alignment with governance standards and cybersecurity frameworks and advising on data security strategies
- Experience defining and reporting metrics and KPIs/KRIs/KCIs
- Cybersecurity experience in a regulated banking or financial environment preferred
FUNCTIONAL SKILLS- Strong understanding of DSPM principles, including data discovery and classification across traditional data stores and AI-related data pipelines, risk assessment, policy management, incident response, and compliance management
- Ability to define and implement data classification patterns for scanning tools
- Ability to implement adaptive security measures based on data sensitivity and regulatory requirements
- Proficiency in using DSPM tools to gain visibility into data assets and user activities, and to enforce least privilege principles
- Proficiency in reporting and analyzing data security metrics
- Experience in developing and executing data security strategies
- Knowledge of data protection and data loss prevention (DLP) technologies
- Ability to adapt data classification requirements to security tools
- Experience with integrating data classification results with security tools for enrichment and enhanced security
- Ability to apply data classification and labeling controls to datasets used for AI training, testing, and inference
- Ability to integrating data classification results with downstream systems to enable safe data usage in analytics and AI-enabled platforms
FOUNDATIONAL SKILLS- Excellent communication and collaboration skills
- Strong analytical and problem-solving abilities
- Ability to work independently and as part of a team
- Strong organizational and project management skills
- Ability to manage multiple priorities and meet deadlines
- Attention to detail and commitment to quality
- Strong presentation and writing skills
RESPONSIBILITIESThe Data Security Engineer role plays a critical function in enabling the secure use of data across emerging technologies, including artificial intelligence and machine learning (AI/ML), by ensuring that sensitive, regulated, and proprietary data is appropriately discovered, classified, governed, and protected throughout its lifecycle. This position is responsible for assessing and managing the organization's data security posture by continuously evaluating current security practices and identifying vulnerabilities. Responsibilities include creating and managing data classification and labeling technology, controls, and processes, working closely with various stakeholders to gather requirements, define patterns, and ensure compliance with governance standards. The specialist will also be responsible for reporting and analyzing data security metrics, advising on data security strategies, and overseeing the execution of data labeling initiatives. Specifically, the position is responsible for:
- Implement and manage DSPM tools to enhance data protection and compliance with regulatory requirements
- Collaborate with various stakeholders to ensure the alignment of DSPM initiatives with overall data security strategies
- Adapting data classification requirements to security tools
- Integrating data classification results with security tools for enrichment and enhanced security
- Working with stakeholders such as Data Privacy, IAM, Security Engineering, and Data Security teams to gather data classification detection requirements
- Defining patterns for scanning tools and ensuring alignment with governance standards
- Reporting and analyzing data security metrics to inform decision-making
- Advising on data security strategies and best practices
- Overseeing the execution and progress of data classification and labeling initiatives
- Assess and mitigate data security risks associated with AI and machine learning use cases, including training data, fine-tuning datasets, inference inputs, and outputs
- Partner with AI, analytics, and engineering teams to ensure data used in AI-enabled solutions complies with classification, privacy, retention, and regulatory requirements
- Support secure adoption of generative AI technologies by enforcing controls that prevent sensitive data exposure, unintended data persistence, or unauthorized reuse
- Contribute to the definition of guardrails for AI data usage, including policy alignment for internal, third-party, and cloud-hosted AI services
- Ensuring compliance with data security and protection regulations and standards
- Liaison with governance, legal, and business divisions to maintain and update classification and labeling requirements
- Presenting findings and strategies to stakeholders
CERTIFICATIONS- Certified Information Systems Security Professional (CISSP)
- Certified Information Security Manager (CISM)
- Any relevant certifications in data security, protection, and governance
EDUCATION• Bachelor's degree in Computer Science or a closely-related discipline, or an equivalent combination of formal education and experience
"Visa sponsorship/support is based on business needs. We do not anticipate providing visa sponsorship/support for this position."The typical base pay range for this role is as follows:
- New York / New Jersey: $121-$194
- Non-New York / New Jersey: $121-$180
depending on job-related knowledge, skills, experience and location. This role may also be eligible for certain discretionary performance-based bonus and/or incentive compensation. Additionally, our Total Rewards program provides colleagues with a competitive benefits package (in accordance with the eligibility requirements and respective terms of each) that includes comprehensive health and wellness benefits, retirement plans, educational assistance and training programs, income replacement for qualified employees with disabilities, paid maternity and parental bonding leave, and paid vacation, sick days, and holidays. For more information on our Total Rewards package, please click the link below.
Our hybrid work schedule is four days on-site and work remotely one day per week.
MUFG Benefits Summary
The above statements are intended to describe the general nature and level of work being performed. They are not intended to be construed as an exhaustive list of all responsibilities duties and skills required of personnel so classified.