Director of Data Security & Governance
arrivia · Scottsdale, AZ · 1 mo ago
Information TechnologyFull-time
About the role
As Director of Data Security & Governance, you'll own the controls that ensure arrivia's data is protected across various environments, including cloud, SaaS, and endpoints.
Responsibilities
- Own information classification, labeling, and handling standards to ensure sensitive data is identified and protected everywhere it lives.
- Own DLP across every egress channel, including PII and SOC adherence reviews and controls.
- Own DSPM across cloud, SaaS, and endpoints to find and close exposure before it becomes a finding.
- Own encryption and key management standards, key management, HSM, and the full key lifecycle, including tokenization.
- Own data-access governance, insider-risk programs, and enterprise data retention and deletion.
- Own data residency and sovereignty controls plus records management and eDiscovery.
- Own data governance for AI, including training-data and RAG-source controls and prompt and response DLP to keep sensitive data from leaking to LLMs.
- Lead and grow the Data Security team, setting the methods and standards the broader organization relies on.
- Drive toward full classification coverage, DLP on every egress channel, and automated discovery and enforcement across the estate.
Requirements
- Bachelor's degree in Computer Science, Cybersecurity, or a related field, or a minimum of 7 years in security.
- 5+ years in data security and governance, including team leadership.
- Hands-on experience with data classification and DLP tooling (such as Microsoft Purview, Symantec/Broadcom, or Forcepoint) across email, endpoint, and cloud.
- Experience deploying Data Security Posture Management (DSPM) across cloud, SaaS, and endpoints.
- Strong knowledge of encryption for data at rest and in transit, plus hands-on key management, HSM, and key-lifecycle experience, including tokenization.
- Experience with data-access governance, insider-risk, and enterprise data retention.
- Knowledge of data residency and sovereignty and records management and eDiscovery.
- Working knowledge of data governance for AI (training-data and RAG controls and prompt and response DLP).
- Strong understanding of ISO 27001/27701, HIPAA, PII, PCI, and GDPR principles.
- Ability to translate complex technology issues into language a wide range of audiences can understand.
- CISSP required. CIPT, CDPSE, or CISM preferred.
Qualifications
- Hands-on experience with data classification and DLP tooling (such as Microsoft Purview, Symantec/Broadcom, or Forcepoint) across email, endpoint, and cloud.
- Experience deploying Data Security Posture Management (DSPM) across cloud, SaaS, and endpoints.
- Strong knowledge of encryption for data at rest and in transit, plus hands-on key management, HSM, and key-lifecycle experience, including tokenization.
- Experience with data-access governance, insider-risk, and enterprise data retention.
- Knowledge of data residency and sovereignty and records management and eDiscovery.
- Working knowledge of data governance for AI (training-data and RAG controls and prompt and response DLP).
- Strong understanding of ISO 27001/27701, HIPAA, PII, PCI, and GDPR principles.
Skills
- CISSP required. CIPT, CDPSE, or CISM preferred.
Benefits & Perks
- Unlimited PTO
- Exclusive employee travel rates
- Travel discounts through arrivia programs
- Medical, dental, and vision insurance
- 401(k) with company participation