Data Security Architect
IDEXX · Westbrook, ME · 2 days ago
$120k–$150k/yrFull-time
About the role
The Data Security Architect is responsible for defining the enterprise architecture, control patterns, and design standards for protecting sensitive data across IDEXX’s platforms, including Snowflake, Databricks, M365, Box, and cloud applications (AWS-first).
Responsibilities
- Define the enterprise data security architecture, including:
- Data discovery and classification (DSPM integration)
- DLP/CASB control strategy (M365, Box, endpoint)
- Data platform security controls (Snowflake, Databricks)
- Application/API data protection patterns (cloud-first)
- Establish standard control patterns, including:
- Data classification and tagging models
- Cryptography, tokenization, and masking strategies
- Data access control models (RBAC, ABAC, RLS)
- Data movement and sharing controls
- Ensure consistency and scalability of data protection across SaaS, cloud, and application environments
- Design and drive integration across:
- Snowflake and Alation (data catalog and ownership mapping)
- Entra ID (identity-driven access controls and policy enforcement)
- M365 and Box (data loss prevention and collaboration controls)
- Cloud environments (AWS, Azure, GCP)
- Translate data risk insights into technical control implementation requirements
- Develop and maintain a Data Security Reference Architecture
- Define secure design patterns and implementation guidance for:
- Data engineering teams
- Application development teams
- Cloud platform teams
- Enable engineering teams to embed data protection into systems and workflows, rather than relying solely on downstream tooling
- Collaborate with:
- Data Security Program Lead (execution and governance)
- Data Security Engineering Lead (implementation delivery)
- Cyber Defense / SOC teams (operational integration)
- Provide architectural direction and design input while ensuring:
- Execution teams can implement effectively
- Controls remain aligned to risk priorities
Requirements
- 7-10+ years experience in: Data security, cloud security, or security architecture
- Strong experience designing security for: Cloud-native data platforms (Snowflake, Databricks), SaaS and collaboration environments (M365, Box), Enterprise identity systems (Entra ID)
- Proven ability (via outcomes) to design and scale: Data classification and tagging models, Data protection controls (DLP, masking, encryption), Access control models (RBAC, ABAC)
- Experience working across: Data engineering, Application engineering, Cloud platform teams
- Deep understanding of: Data protection architecture and lifecycle management, Data platforms (Snowflake strongly preferred), Cloud environments (AWS preferred; Azure/GCP familiarity)
- Working familiarity with: DSPM tools (e.g., Cyera, BigID, etc.), CASB/DLP platforms (M365, endpoint, etc.), Data catalog and governance tools (e.g., Alation)
- Knowledge of: Encryption, tokenization, and data masking techniques, Data access governance models and patterns, Understanding of regulatory frameworks relevant to IDEXX (GDPR, SOC2, PCI DSS)
- Strong architectural thinking and system design capability, Predilection towards action to achieve outcomes and refine design, Excellent collaboration skills across engineering and security domains, Ability to communicate via architectural diagrams, whitepapers, presentations, Strong communication skills to: Influence technical and non-technical stakeholders, Align teams on architecture and standards
Qualifications
- Experience implementing enterprise data security or DSPM programs
- Background working with data engineering or analytics teams
- Experience designing controls in Snowflake or similar platforms
- Certifications (AWS Certified Solutions Architect, CISSP, CCSP, etc.)
Skills
- Strong communication skills
- Ability to influence stakeholders
- Experience with data protection architecture and lifecycle management
- Knowledge of encryption, tokenization, and data masking techniques
- Experience with data catalog and governance tools
- Experience with CASB/DLP platforms
- Experience with DSPM tools
- Experience with cloud environments (AWS preferred; Azure/GCP familiarity)
- Experience with data platforms (Snowflake strongly preferred)
- Experience with data engineering, application engineering, and cloud platform teams
- Experience with regulatory frameworks relevant to IDEXX (GDPR, SOC2, PCI DSS)
- Experience with data access governance models and patterns
Benefits
- Base annual salary target: $120,000 - $150,000
- Opportunity for annual cash bonus
- Health / Dental / Vision Benefits
- Day-One 5% matching 401k
- Additional benefits including but not limited to financial support, pet insurance, mental health resources, volunteer paid days off, employee stock program, foundation donation matching, and much more!