Data is
arrivia's most valuable asset, and this role keeps it protected wherever it lives. As Director of Data Security & Governance, you'll own the controls that most often separate a clean audit from a high-severity finding: classification, data loss prevention, and encryption.
You'll set the standard for how
arrivia classifies, protects, and governs data across cloud, SaaS, and endpoints. You'll lead a dedicated Data Security team and operate with real autonomy, partnering across Privacy, Infrastructure, and App & AI Security while owning the technical protection controls end to end.
You'll also define how we protect data in the age of AI, from training-data controls to prompt and response DLP.
arrivia is investing in AI-driven innovation, and you'll have modern tools and the mandate to use them to work faster and smarter.
What You'll Own- Data classification and handling: Own information classification, labeling, and handling standards so sensitive data is identified and protected everywhere it lives.
- Data loss prevention: Own DLP across every egress channel, including PII and SOC adherence reviews and controls.
- Data security posture management: Own DSPM across cloud, SaaS, and endpoints to find and close exposure before it becomes a finding.
- Encryption and key management: Own cryptography standards, key management, HSM, and the full key lifecycle, including tokenization.
- Access governance and insider risk: Own data-access governance, insider-risk programs, and enterprise data retention and deletion.
- Data residency and records: Own data residency and sovereignty controls plus records management and eDiscovery.
- Data governance for AI: Own training-data and RAG-source controls and prompt and response DLP to keep sensitive data from leaking to LLMs.
- Team leadership: Lead and grow the Data Security team, setting the methods and standards the broader organization relies on.
- Measurable outcomes: Drive toward full classification coverage, DLP on every egress channel, and automated discovery and enforcement across the estate.
What You'll Bring- Bachelor's degree in Computer Science, Cybersecurity, or a related field, or a minimum of 7 years in security.
- 5+ years in data security and governance, including team leadership.
- Hands-on experience with data classification and DLP tooling (for example Microsoft Purview, Symantec/Broadcom, or Forcepoint) across email, endpoint, and cloud.
- Experience deploying Data Security Posture Management (DSPM) across cloud, SaaS, and endpoints.
- Strong knowledge of encryption for data at rest and in transit, plus hands-on key management, HSM, and key-lifecycle experience, including tokenization.
- Experience with data-access governance, insider-risk, and enterprise data retention.
- Knowledge of data residency and sovereignty and records management and eDiscovery.
- Working knowledge of data governance for AI (training-data and RAG controls and prompt and response DLP).
- Strong understanding of ISO 27001/27701, HIPAA, PII, PCI, and GDPR principles.
- Ability to translate complex technology issues into language a wide range of audiences can understand.
- CISSP required. CIPT, CDPSE, or CISM preferred.
Benefits & Perks- Unlimited PTO
- Exclusive employee travel rates
- Travel discounts through arrivia programs
- Medical, dental, and vision insurance
- 401(k) with company participation