The Senior Director of Data Security is the senior leader responsible for the overall enterprise data security strategy, operating model, and execution across cloud, on-premises, SaaS, database, and data platform environments. This role leads a team focused on designing, implementing, and maintaining the foundations that enable secure, governed, and compliant use of enterprise data.
This role is responsible for maturing Data Security Posture Management (DSPM), data discovery, classification, tagging, protection controls, data access governance, database activity monitoring, secure data sharing, data loss prevention alignment, and lifecycle security across structured and unstructured data environments.
The Senior Director partners closely with Infrastructure, Cloud Security, Security Architecture, Cyber Defense, Privacy, Legal, Compliance, Data Governance, Platform Engineering, Business Technology, and application teams to ensure scalable data security capabilities are embedded throughout the organization's technology and data landscape.
You'll enjoy the flexibility to work remotely* from anywhere within the U.S. as you take on some tough challenges. For all hires in the Minneapolis or Washington, D.C. area, you will be required to work in the office a minimum of four days per week.
Primary Responsibilities: Role Objectives & Impact
- Establish and mature a unified operating model for data security, enabling seamless engagement across security, infrastructure, platform, data governance, privacy, legal, compliance, and business technology teams
- Develop and enforce enterprise data security standards, including discovery, classification, tagging, access governance, encryption, tokenization, masking, secure sharing, monitoring, and lifecycle controls
- Drive proactive data risk visibility and posture improvement by expanding DSPM capabilities, strengthening data inventory and ownership, and shifting detection, prioritization, and remediation earlier in the data lifecycle
- Partner with cloud, infrastructure, and platform teams to embed data security by default into cloud platforms, data platforms, databases, pipelines, application patterns, and service adoption processes
- Improve conversion of data security signals into measurable outcomes through consistent intake, prioritization, risk disposition, remediation tracking, KPI reporting, and executive-level posture visibility
- Establish durable lifecycle controls for data minimization, retention, archival, and defensible disposition in partnership with data governance, privacy, legal, and business stakeholders
- Support integration of acquired or federated environments by establishing repeatable onboarding patterns, ownership models, control expectations, and reporting mechanisms for enterprise data security capabilities
Core Responsibilities
- Lead and develop the Data Security team, providing direction, coaching, prioritization, and performance management
- Design, document, and mature the enterprise data security operating model, including governance cadence, decision forums, intake, prioritization, escalation paths, and accountability models
- Define and maintain data security standards and technical baselines across structured data, unstructured data, cloud data services, databases, SaaS platforms, data pipelines, and on-premises environments
- Standardize policy execution, operational metrics, KPI reporting, and posture dashboards across data security platforms and business environments
- Direct the product roadmap and backlog for scalable data security capabilities, ensuring efficient intake, prioritization, dependency management, and execution with partner teams
- Operate shared data security guardrails, including classification requirements, tagging standards, access governance expectations, encryption and tokenization controls, masking patterns, DLP alignment, database activity monitoring, and secure data sharing controls
- Drive DSPM maturity, including sensitive data discovery, classification, exposure identification, risk prioritization, ownership mapping, and remediation tracking
- Integrate data inventory, cataloging, lineage, ownership, and posture signals into enterprise dashboards, reporting workflows, and risk management processes
- Establish lifecycle security controls for data creation, storage, processing, usage, sharing, retention, archival, and defensible disposition
- Support acquired or federated environment onboarding through repeatable integration playbooks, control expectations, reporting patterns, and remediation workflows
- Make toolchain choices, including build, buy, rationalize, and deprecate decisions, to maximize return on investment, reduce duplication, and accelerate operational maturity
- Lead technical readiness, incident response, and continuous improvement exercises with infrastructure, platform, security operations, and application teams
- Serve as a trusted leader breaking down silos between Security, Infrastructure, Application, Data Governance, Privacy, Legal, Compliance, and Business teams
- Provide executive-level reporting on data security posture, control maturity, remediation progress, lifecycle compliance, data risk, and program outcomes
You'll be rewarded and recognized for your performance in an environment that will challenge you and give you clear direction on what it takes to succeed in your role as well as provide development for other roles you may be interested in.
Required Qualifications: - 10+ years of experience in data security, cloud security, database security, security engineering, data governance, or related disciplines for large, complex organizations in regulated domains
- 7+ years of experience leading data security, security engineering, or platform security teams in enterprise environments
- Deep experience with DSPM, data discovery, data classification, tagging, data inventory, access governance, data protection, and posture management
- Experience securing databases, cloud data platforms, SaaS repositories, structured data, unstructured data, and hybrid data environments
- Proven solid background in encryption, tokenization, masking, key management, DLP, database activity monitoring, secure data sharing, and least-privilege access models
- Demonstrated ability to build low-friction engagement models across Security, Infrastructure, Application, Data Governance, Privacy, Legal, Compliance, and Business teams
- Experience developing operating models, governance cadences, intake processes, KPIs, dashboards, and executive reporting for enterprise security capabilities
- Proven executive communication, stakeholder influence, and thought leadership in enterprise data security and risk reduction at scale
Preferred Qualifications: - Relevant certifications such as CISSP, CISM, CDPSE, CCSP, CISA, CRISC, or equivalent experience
- Experience partnering with incident response, audit, compliance, privacy, and legal teams
- Demonstrated familiarity with regulatory and control frameworks, including NIST, ISO, HITRUST, HIPAA, GDPR, CCPA, and related enterprise risk frameworks
- Experience with federated environment integration and complex hybrid operating models
- Experience integrating data security with analytics, AI, data governance, cloud security, and enterprise security platforms
*All employees working remotely will be required to adhere to UnitedHealth Group's Telecommuter Policy.
Pay is based on several factors including but not limited to local labor markets, education, work experience, certifications, etc. In addition to your salary, we offer benefits such as, a comprehensive benefits package, incentive and recognition programs, equity stock purchase and 401k contribution (all benefits are subject to eligibility requirements). No matter where or when you begin a career with us, you'll find a far-reaching choice of benefits and incentives. The salary for this role will range from $159,300 to $273,200 annually based on full-time employment. We comply with all minimum wage laws as applicable.
Application Deadline: This will be posted for a minimum of 2 business days or until a sufficient candidate pool has been collected. Job posting may come down early due to volume of applicants.