Job Purpose
The Data and Application Security Engineer will oversee and implement all aspects of data and information security for LP. This role will also serve in a support capacity for our third-party application stack, assisting in providing guidance for the data residing in these applications, and understanding the application’s inline security best practices.
We’d love to meet you if...
you’re energized by big challenges and creating a plan to meet the challenge
you enjoy working with others to deliver great work
you’re innovative and looking for a values-driven, positive culture and environment
In this position you will have the opportunity to :
- Implement and / or maintain data security platforms and processes across the enterprise including data discovery, and DLP systems.
- Support data assurance processes to prevent unauthorized access and safeguard sensitive data.
- Ensure the organization is following the NIST 800-53 framework for Data Security.
- Prepare the organization for an eventual SOC 2 certification as it relates to Data and Application Security.
- Perform risk assessments on existing and proposed information systems, identifying sensitive data areas and making recommendations for risk mitigation.
- Design and architect secure data infrastructure solutions including discovery, classification of data, access controls, encryption, tokenization, masking, and monitoring.
- Work closely with database administrators and other IT staff to institute database security measures such as user account management, access privileges, logging, encryption, auditing, backups, etc.
- Institute data security measures for big data environments including Snowflake, SAP, cloud storage, etc.
- Assist all IT partners and business partners (when relevant) to understand third party platform best practices for security configurations. Review architecture diagrams and provide guidance for data connectors, API security, protocols for data in transit, and encryption requirements / protocols for data at rest associated to these applications.
- Review SaaS applications and ensure security best practices are being followed with regard to LP data being transferred to and from third party applications.
What do I need to be successful?
4+ years in data / information security role with hands-on technical experience.Or any equivalent combination of experience and education that demonstrates the ability to perform the key responsibilities of this position.Bilingual in English and Spanish preferredCertifications such as CISSP, CISA, CISM preferred but not required.In-depth knowledge of data security protocols, encryption, access controls, regulatory standards, API Security, and data encryption.Strong problem diagnosis and analytical thinking skills are a must.Excellent written and verbal communication skills for collaborating with technical and business teams.Education
Bachelor's degree in Information Security or Computer Science. Master’s degree preferred.Work Environment
This position will be remote, working in a home office environmentOccasional travel to our headquarters in Nashville, TN requiredLI-REMOTE
LP offers competitive salaries and comprehensive benefits and programs including health and welfare benefits, 401(k) program, career mobility, tuition reimbursement, volunteer opportunities, profit sharing and more.