Data Protection Engineer
About the role
This is a practitioner role serving as the primary owner of First Student's data protection capability while also providing hands-on security engineering support across cloud, infrastructure, and application security domains. The position partners with IT, I&O, and Legal teams to design and operate security controls that protect student, employee, and operational data across cloud and on-premises environments.
The role defines what must be protected and how, coordinates with I&O and Data teams to ensure controls are implemented correctly, and builds validation and reporting of outcomes. This is a direct replacement for a departing senior team member who owned both data protection and security engineering; candidates must be comfortable holding both domains simultaneously and ramping quickly into an active program.
Responsibilities
- Own enterprise data protection risk assessments, classification standards, and control effectiveness evaluations.
- Identify data exposure risk across cloud, SaaS, and on-premises environments.
- Contribute to vulnerability assessments and architecture reviews within the Cybersecurity function.
- Design and define data protection control requirements and standards for DLP, encryption, key management, and data governance across cloud and on-premises environments.
- Work with I&O and Data teams to ensure controls are implemented to Cybersecurity specifications; validate implementation outcomes.
- Provide security engineering expertise across cloud infrastructure and endpoint security domains.
- Monitor for data misuse, exfiltration, and policy violations; integrate DLP detection capabilities with SOC workflows.
- Support SIEM log source expansion and alert quality improvements in coordination with the Security Operations function.
- Lead Cybersecurity response activities for data exposure incidents, including investigation direction, containment guidance to I&O, remediation oversight, and lessons learned.
- Develop and maintain data protection policies aligned with FERPA, CCPA, Canadian provincial privacy laws, and enterprise risk objectives.
- Own the data classification framework and drive operationalization across key data stores and workflows.
- Contribute to management reporting, risk acceptance documentation, and work tracking.
- Provide technical oversight of cybersecurity analysts; review work product and deliverables for quality, accuracy, and alignment with standards.
- Serve as a technical escalation point within the team for data protection and cybersecurity questions.
Qualifications
- Bachelor's degree in Computer Science, Information Systems, or equivalent experience.
- 7+ years of cybersecurity experience with at least 4 years in data protection, cloud security, or cybersecurity engineering.
- Industry certifications such as SANS/GIAC (e.g., GDSA, GDAT, or equivalent), CISSP, or CISM preferred.
- Hands-on experience configuring and operating DLP platforms (M365 Purview strongly preferred; CrowdStrike Falcon Data Protection preferred; equivalent experience acceptable).
- Experience implementing data classification frameworks in enterprise environments with regulated data (FERPA, COPPA, CCPA, or Canadian privacy law familiarity preferred).
- Strong understanding of AWS security services and cloud-native data protection controls (S3 bucket policies, KMS, Macie, CloudTrail).
- Security engineering experience: familiarity with SIEM log sources, endpoint security platforms (CrowdStrike Falcon preferred), and vulnerability management tooling (Rapid7 preferred).
- Proficiency with Python or PowerShell for automation, reporting, and control validation.
- Familiarity with NIST CSF, CIS Controls, and translating regulatory requirements into technical controls.
- Experience working across organizational boundaries, defining requirements for teams that own implementation, and validating outcomes without direct execution authority.
- Prior experience providing technical oversight or mentorship to others.
Skills
- Operates independently and takes clear ownership of outcomes.
- Comfortable defining requirements and holding other teams accountable for implementation without direct control over execution.
- Comfortable holding multiple technical domains simultaneously (data protection and security engineering) and prioritizing across them without daily direction.
- Effective at working across organizational boundaries by communicating requirements clearly, escalating when standards are not met, and building productive working relationships.
- Strong communication skills; able to translate technical data risk into terms meaningful to Legal, management, and executive stakeholders.
- High integrity and ownership mindset with a proactive approach to risk reduction.
Schedule
- Occasional off-hour or weekend work may be required, including participation in on-call rotation for cybersecurity incidents.
- Minimal business travel expected.
- Remote or Hybrid (Cincinnati, OH HQ) opportunities available.
Pay
Compensation ranges from $130,000 to $155,000 depending on experience.