Orion Innovation

Security Specialist

Orion Innovation$125K — $150K *
US-AnywhereRemote in United States
Finance & Insurance
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 10-12 years of enterprise data security experience.
  • Hands-on experience with DSPM, DLP, and Data Access Governance platforms.
  • Strong knowledge of enterprise cryptography and key management.
  • Expertise in data classification and lifecycle management at scale.
  • Understanding of data security and identity intersection.
  • Experience with data flows in hybrid environments, preferably Microsoft Azure.
  • Python-based development skills and automation-focused approach.
  • Fluency with regulatory compliance in financial environments.

Responsibilities

  • Lead the evaluation for Phase 1 of a DSPM platform selection.
  • Refine and prioritize client data security requirements through workshops.
  • Manage vendor RFP issuance and response cycle transparently.
  • Grade vendor responses and document rationale for selections.
  • Operatively follow client evaluation methodology, controlling scope creep.
  • Present vendor down-select recommendations to stakeholders.
  • Document relationships and facilitate handoff to the next evaluation phase.

Benefits

  • Opportunity to work in a high-visibility role at a leading financial institution.
  • Engagement with global teams across multiple locations.
  • Possibility to extend into Phase 3 of the project.
  • Exposure to diverse DSPM vendor technologies and practices.
  • Development of a structured, high-impact work environment.
Full Job Description
Security Specialist

Role Overview

Orion Innovation is seeking a Senior Data Security Practitioner to lead Phase 1 of an enterprise Data Security Posture Management (DSPM) platform selection program at one of the world's leading global financial institutions. The client is evaluating approximately ten DSPM vendor platforms against 300+ internal requirements using its own technical workbook and grading methodology. This is a high-visibility, senior client-facing role: the practitioner will refine and socialize requirements with client constituents across three global locations, run the vendor RFP and grading cycle, and present the down-select recommendation that reduces the field to 3-4 platforms for formal lab validation. The role demands equal parts deep data security expertise and executive-grade.

Key Responsibilities
• Serve as the lead evaluator and day-to-day driver of Phase 1, accountable for the requirements package, vendor grading, and down-select deliverables
• Re-evaluate, refine, and prioritize 300+ client data security requirements; socialize and validate them in workshops with business and technical constituents across New York, Glasgow, and Budapest
• Package finalized requirements into the client's prescribed RFP format and manage issuance to approximately ten DSPM vendor partners
• Manage the vendor response cycle, including Q&A traffic, clarifications, and submission logistics, maintaining full transparency with all vendor partners
• Grade vendor responses against the client's accepted technical workbook and grading schedule; organize scoring, produce summary reporting, and document removal rationale per client criteria
• Operate strictly within the client's evaluation methodology and governance - executing and elevating the client's process, not redesigning it; manage scope creep through formal change control
• Present the down-select recommendation (3-4 finalist platforms) to client constituents and senior stakeholders
• Build and document constituent relationships and evaluation context for structured handoff into the prime partner's lab validation phase (Phase 2)
• Maintain weekly status reporting and escalate risks to the prime engagement lead, including realistic counsel on the aggressive 12-week client timeline

Essential Requirements
• Minimum 10-12 years of experience in enterprise data security, with demonstrated depth across the full data security program lifecycle
• Hands-on experience designing, implementing, or formally evaluating DSPM, DLP, and Data Access Governance (DAG) platforms for large multinational organizations; current knowledge of the DSPM vendor landscape (e.g., Varonis, Cyera, BigID, Securiti, Microsoft Purview, and peers)
• Strong command of enterprise cryptography and HSM / key management program operations
• Deep expertise in data classification, tagging, discovery, prioritization policy, and data lifecycle management at enterprise scale
• Working understanding of the intersection of data security and identity (data access governance, entitlements, IAM integration)
• Experience with data flows in hybrid compute environments spanning multi-cloud and on-premises estates with heterogeneous data handling and storage techniques; Microsoft Azure experience preferred
• Understanding of current AI-related requirements for data security platforms - including data exposure risks from copilots, LLM integrations, and agentic systems
• Python-based development capability and a programmatic / automation-first approach to security tooling; demonstrated capability in agentic coding approaches
• Data security experience within a financial enterprise; fluency with regulatory and compliance expectations in strongly regulated environments (e.g., DORA, GDPR, FFIEC, NYDFS, GLBA - depth in at least one strong regime required)
• Understanding of compliance governance and the typical data classification schemes required in a financial environment
• Enterprise architecture literacy - able to read and reason about a complex data application stack, not only the security tooling layered on it
• Experience with integration testing and lab-based proof of concept execution, with evidential reporting against formal acceptance criteria
• Formal RFP / vendor evaluation experience with structured grading methodologies and evidential reporting
• Exceptional written and verbal communication: able to run multi-stakeholder workshops, manage constituents across time zones, deliver executive reporting, and present findings to Director / MD-level audiences
• Proven ability to work independently, make decisions, manage expectations, and re-prioritize in a fast-paced environment
• Based in or commutable to New York, NY, with availability for regular on-site presence; approved delivery location per client Task Order: New York, NY

Desirable Qualifications
• CISSP, CISM, CDPSE, or equivalent senior security/privacy certification
• Prior engagement experience at Tier 1 Bank or an equivalent investment bank
• Prior experience at a Big-4 firm, IBM, Accenture, or specialist data security consultancy
• Familiarity with non-human identity (NHI) security trends and tooling
• Availability and interest in continuing into Phase 3 (live-environment PoC) following the prime-led lab validation phase - continuity of client relationships is highly valued

About Orion Innovation

Orion Innovation is a global technology services firm that provides IT solutions and services to businesses across various industries. The company offers digital transformation, product engineering, data analytics, cloud computing, and other IT services to help businesses improve their operations and achieve their goals. Orion Innovation has offices in the United States, Europe, and Asia, and serves clients in industries such as financial services, healthcare, retail, and more.
Learn more about Orion Innovation
Size
4,000 employees
Industry

Similar Jobs

More Jobs at Orion Innovation

More Finance & Insurance Jobs

Find similar Security Specialist jobs: