Security Specialist
Role Overview
Orion Innovation is seeking a Senior Data Security Practitioner to lead Phase 1 of an enterprise Data Security Posture Management (DSPM) platform selection program at one of the world's leading global financial institutions. The client is evaluating approximately ten DSPM vendor platforms against 300+ internal requirements using its own technical workbook and grading methodology. This is a high-visibility, senior client-facing role: the practitioner will refine and socialize requirements with client constituents across three global locations, run the vendor RFP and grading cycle, and present the down-select recommendation that reduces the field to 3-4 platforms for formal lab validation. The role demands equal parts deep data security expertise and executive-grade.
Key Responsibilities
• Serve as the lead evaluator and day-to-day driver of Phase 1, accountable for the requirements package, vendor grading, and down-select deliverables
• Re-evaluate, refine, and prioritize 300+ client data security requirements; socialize and validate them in workshops with business and technical constituents across New York, Glasgow, and Budapest
• Package finalized requirements into the client's prescribed RFP format and manage issuance to approximately ten DSPM vendor partners
• Manage the vendor response cycle, including Q&A traffic, clarifications, and submission logistics, maintaining full transparency with all vendor partners
• Grade vendor responses against the client's accepted technical workbook and grading schedule; organize scoring, produce summary reporting, and document removal rationale per client criteria
• Operate strictly within the client's evaluation methodology and governance - executing and elevating the client's process, not redesigning it; manage scope creep through formal change control
• Present the down-select recommendation (3-4 finalist platforms) to client constituents and senior stakeholders
• Build and document constituent relationships and evaluation context for structured handoff into the prime partner's lab validation phase (Phase 2)
• Maintain weekly status reporting and escalate risks to the prime engagement lead, including realistic counsel on the aggressive 12-week client timeline
Essential Requirements
• Minimum 10-12 years of experience in enterprise data security, with demonstrated depth across the full data security program lifecycle
• Hands-on experience designing, implementing, or formally evaluating DSPM, DLP, and Data Access Governance (DAG) platforms for large multinational organizations; current knowledge of the DSPM vendor landscape (e.g., Varonis, Cyera, BigID, Securiti, Microsoft Purview, and peers)
• Strong command of enterprise cryptography and HSM / key management program operations
• Deep expertise in data classification, tagging, discovery, prioritization policy, and data lifecycle management at enterprise scale
• Working understanding of the intersection of data security and identity (data access governance, entitlements, IAM integration)
• Experience with data flows in hybrid compute environments spanning multi-cloud and on-premises estates with heterogeneous data handling and storage techniques; Microsoft Azure experience preferred
• Understanding of current AI-related requirements for data security platforms - including data exposure risks from copilots, LLM integrations, and agentic systems
• Python-based development capability and a programmatic / automation-first approach to security tooling; demonstrated capability in agentic coding approaches
• Data security experience within a financial enterprise; fluency with regulatory and compliance expectations in strongly regulated environments (e.g., DORA, GDPR, FFIEC, NYDFS, GLBA - depth in at least one strong regime required)
• Understanding of compliance governance and the typical data classification schemes required in a financial environment
• Enterprise architecture literacy - able to read and reason about a complex data application stack, not only the security tooling layered on it
• Experience with integration testing and lab-based proof of concept execution, with evidential reporting against formal acceptance criteria
• Formal RFP / vendor evaluation experience with structured grading methodologies and evidential reporting
• Exceptional written and verbal communication: able to run multi-stakeholder workshops, manage constituents across time zones, deliver executive reporting, and present findings to Director / MD-level audiences
• Proven ability to work independently, make decisions, manage expectations, and re-prioritize in a fast-paced environment
• Based in or commutable to New York, NY, with availability for regular on-site presence; approved delivery location per client Task Order: New York, NY
Desirable Qualifications
• CISSP, CISM, CDPSE, or equivalent senior security/privacy certification
• Prior engagement experience at Tier 1 Bank or an equivalent investment bank
• Prior experience at a Big-4 firm, IBM, Accenture, or specialist data security consultancy
• Familiarity with non-human identity (NHI) security trends and tooling
• Availability and interest in continuing into Phase 3 (live-environment PoC) following the prime-led lab validation phase - continuity of client relationships is highly valued