Haystack
← Back to Jobs
Remote
Technology
NG

Information Security Engineer (Security Engineering & Data Protection) - W2 Requirement(Remote)

NGTalentTech Group LLCUnited States🇺🇸United StatesPosted Sep 29, 2026

Quick Overview

Seniority
Mid Senior
Work mode
Remote
Location
United States
Posted
Yesterday
SSOJavaScriptPowerShellPython

Job Description

Job Title: Information Security Engineer (Security Engineering & Data Protection)

Location: Remote

W2 Requirement

Role Overview:

Implement data protection tools and lead ePHI discovery and inventory work from deployment through day-to-day operation. Implement the data security posture management platform and related tooling, mature existing DLP and SASE controls, and build an accurate, maintained inventory of where ePHI lives across cloud and SaaS environments. Support vulnerability remediation and back up incident response.

Responsibilities:

- *ePHI discovery and inventory:* Own the technical work of finding, classifying, and inventorying ePHI across cloud storage, databases, file shares, and SaaS applications; keep the inventory accurate as systems change.

- *DSPM implementation:* Deploy and configure a data security posture management platform end to end.

  - Connect data sources and tune classifiers.

  - Identify sensitive data that is over-exposed, unencrypted, or broadly accessible.

  - Work with system owners to right-size access and fix misconfigurations.

- *Supporting tooling:* Implement and integrate additional tools the program needs, such as asset inventory and data classification, so discovery results feed the system of record. Document configurations and runbooks.

- *DLP and SASE maturity:* Mature deployed secure web gateway, CASB, DLP, and zero-trust controls.

  - Tune DLP policies to reduce false positives and false negatives.

  - Move from monitoring to enforcement in phases.

  - Build repeatable response processes for PHI movement events.

- *GenAI and shadow IT guardrails:*

  - Identify unsanctioned AI and SaaS tools, including tools handling PHI without a BAA and apps built outside approved development processes that use production data.

  - Apply policies that allow safe use while blocking what shouldn't be allowed.

- *Secondary focus:*

  - Support the vulnerability remediation lifecycle: monitor critical public vulnerabilities, validate bug bounty, pen test and scanner findings, route them to the right teams, and confirm fixes.

  - Back up incident response using the established plan when the primary responder is unavailable.

  - Investigate data exfiltration and insider-risk events surfaced by data protection controls.

  - Hand technical control gaps to the GRC analyst for tracking.

  - Support security tooling administration, TLS inspection exceptions, and technical offboarding.

Qualifications:

- 7+ years in security engineering, with a proven track record of implementing security tools end to end, not only operating them.

- Hands-on implementation experience with DSPM, data discovery, or data classification platforms.

- Hands-on experience implementing and tuning DLP and SASE, SSE, or CASB solutions.

- Deep understanding of how data is stored and accessed in major cloud platforms and SaaS applications.

- Day-to-day proficiency using AI tools to gain efficiency, plus an understanding of how to secure them.

- Strong written and verbal communication skills.

*Extra Credit:*

- Healthcare or other highly regulated industry experience.

- Vulnerability management or bug bounty triage experience.

- Asset inventory or CAASM implementation experience.

- Scripting experience (e.g., Python, PowerShell, JavaScript).

- Identity provider and SSO experience.

- CISSP, GIAC, or similar certifications (not required).

Similar jobs