Senior IT Security Engineer (REMOTE)
Worcester, MA, USA
Posted on Sep 25, 2026
We are seeking a highly skilled Senior Security Engineer to join our IT Security organization in Worcester, MA or in a remote work capacity.POSITION SUMMARY:You bring deep expertise in data protection, information governance, compliance technologies, and enterprise security architecture. This individual will serve as a technical leader responsible for administering, maintaining, enhancing, and strategically expanding the organization's Data Protection Program across cloud, SaaS, endpoint, collaboration, and enterprise data platforms. The ideal candidate possesses hands-on experience implementing and operating enterprise-class Data Security Posture Management (DSPM), Data Loss Prevention (DLP), Information Protection, Records Management, eDiscovery, Insider Risk, and Data Governance solutions. Experience with platforms such as Microsoft Purview and other similar security control tools. This role requires an individual who can operate at both the technical and strategic levels, partnering with Security, Legal, Compliance, Privacy, IT, Data Governance, and business stakeholders to mature and scale enterprise data protection capabilities. This is a full-time, exempt position.IN THIS ROLE, YOU WILL:Data Protection Program Leadership Lead the ongoing administration, enhancement, and growth of the enterprise Data Protection Program.Develop and execute data protection roadmaps aligned with business, regulatory, and security objectives.Identify opportunities to improve data protection maturity and reduce organizational risk.Establish metrics and reporting that demonstrate program effectiveness.Partner with leadership to define long-term data governance and protection strategies. Information Protection & Data Governance Design and maintain enterprise data classification frameworks.Develop and govern data handling standards and protection requirements.Implement and manage sensitivity labeling, encryption, and information protection controls.Collaborate with Data Governance teams to establish classification taxonomies and data ownership models.Develop automated classification and data discovery capabilities across structured and unstructured repositories. Data Loss Prevention (DLP) Design, implement, and manage enterprise DLP strategies.Develop policies protecting sensitive information across email, collaboration platforms, endpoints, cloud applications, and remote work environments.Analyze incidents and adjust policies to improve effectiveness while minimizing business disruption.Establish operational processes for data loss investigations and response activities. Insider Risk & Investigations Implement and maintain insider risk monitoring capabilities.Develop use cases and detection strategies for data misuse, theft, fraud, and policy violations.Support internal investigations involving sensitive data and policy violations.Partner with HR, Legal, and Compliance teams during investigations. eDiscovery, Retention & Records Management Support legal hold, eDiscovery, and regulatory response processes.Develop data retention and disposition strategies.Manage records management controls supporting compliance requirements.Ensure defensible preservation and collection processes are established. Compliance & Regulatory Support Support security, privacy, and regulatory audits.Map compliance requirements to implemented technical controls.Assist with risk assessments and remediation planning.Partner with Compliance and Legal teams to demonstrate regulatory adherence. Platform Engineering & Integration Design and maintain enterprise data protection architectures.Integrate data security tools with SIEM, case management, and operational platforms.Onboard cloud, SaaS, endpoint, and on-premises data sources.Develop automation and operational efficiencies using scripting and APIs.Manage tool upgrades, enhancements, health monitoring, and operational support. WHAT YOU NEED TO APPLY: 7+ years of information security experience.5+ years of hands-on experience supporting enterprise data protection initiatives.Experience administering one or more enterprise data protection, governance, or compliance platforms.Experience implementing DLP, information protection, data classification, and compliance solutions.Experience working with Legal, Compliance, Privacy, and Audit functions.Experience leading enterprise-scale security initiatives and projects.Authorization to work in the United States without current or future sponsorship (U.S. citizen or lawful permanent resident). Technical SkillsStrong experience in several of the following areas: Data Protection ProgramsData GovernanceData ClassificationInformation ProtectionSensitivity LabelsEncryption TechnologiesData Loss Prevention (DLP)Insider Risk ManagementCommunication ComplianceRecords ManagementData Lifecycle ManagementeDiscoveryData Security Posture Management (DSPM)Cloud SecurityIdentity and Access Management (IAM)Role-Based Access Control (RBAC)Microsoft 365 SecurityEndpoint SecurityEnterprise Security ArchitectureSecurity Monitoring and SIEM IntegrationSecurity Automation and Scripting Compliance Frameworks (NIST, ISO 27001, CIS, PCI-DSS, HIPAA, GDPR, SOX)