Need Local to Texas only.
Â
Role: Sr. Cybersecurity/Security Engineer
Location : 14050 FAA Blvd., Fort Worth, TX 76155 (Hybrid)
Position type : Contract
Project Duration : Long Term
Â
Visa : USC & GC only
Â
Detailed JD :
We are seeking an experienced Senior Data Protection & Identity Security Engineer to implement and operate enterprise security controls across data platforms, cloud environments, collaboration systems, and hybrid identity infrastructure. This role will focus on protecting sensitive data, strengthening Active Directory and Microsoft Entra ID environments, identifying security risks, and automating remediation.
The engineer will work closely with Cybersecurity, Privacy, Legal, Enterprise Data, SOC, and product teams to support privacy-by-design, identity security, regulatory compliance, and incident response.
Â
Required:
•            3–7 years of hands-on cybersecurity, identity security, or data protection engineering experience.
•            Strong experience administering and engineering Microsoft Active Directory.
•            Hands-on experience with Microsoft Entra ID/Azure Active Directory.
•            Experience with Azure AD Connect and hybrid identity environments.
•            Demonstrated experience with Active Directory security hardening.
•            Experience identifying and remediating identity-based attack paths.
•            Knowledge of privilege-escalation and lateral-movement techniques.
•            Strong understanding of Tier 0 security and identity as an enterprise control plane.
•            Working knowledge of Kerberos, NTLM, SAML, and OAuth authentication protocols.
•            Experience identifying security risks and implementing practical remediation.
•            Ability to communicate technical incidents, business risks, and recommended actions to technical and nontechnical audiences.
Â
Preferred:
• Experience with Saviynt or a comparable Identity Governance and Administration solution.
•            Knowledge of Ping Identity or other federation platforms.
•            Exposure to HashiCorp Vault, Keyfactor, PKI, or certificate-management environments.
•            Experience supporting Active Directory forest-recovery exercises.
•            Familiarity with Zero Trust security principles.
•            Experience with DSPM tools such as Securiti or BigID.
•            Experience with Microsoft Purview DLP, Imperva, or IBM Guardium.
•            Understanding of SIEM, SOAR, UEBA, Insider Risk, and cloud key-management technologies.
•            Familiarity with GDPR, CCPA/CPRA, PCI DSS, and HIPAA requirements.
Â
Responsibilities:
•            Automate data discovery, classification, inventory, sensitivity labeling, and taxonomy across data stores, pipelines, and collaboration platforms.
•            Engineer Data Security Posture Management capabilities using tools such as Securiti or BigID.
•            Identify and remediate overexposed data, shadow data, stale sensitive information, exposed storage, weak encryption, and excessive permissions.
•            Implement encryption, tokenization, masking, anonymization, and pseudonymization for data at rest and in transit.
•            Integrate data protection controls with cloud key management systems and enforce approved cryptographic standards.
•            Configure and govern RBAC, ABAC, purpose-based authorization, least-privilege access, and fine-grained access controls.
•            Deploy, tune, and support DLP and Database Activity Monitoring solutions such as Microsoft Purview DLP, Imperva, or IBM Guardium.
•            Develop detections for PII, PCI, and PHI while reducing false positives through improved policies and contextual analysis.
•            Integrate UEBA and Insider Risk signals to identify unusual data access, insider misuse, and potential data exfiltration.
•            Integrate data protection telemetry with SIEM and SOAR platforms.
•            Create correlation rules, security detections, and automated response playbooks for data-related threats and policy violations.
•            Automate data retention, minimization, archival, deletion, and redaction processes while supporting legal holds.
•            Implement Data Subject Access Request workflows, including data collection, redaction, secure delivery, SLA tracking, and audit trails.
•            Validate cookie consent signals, data-storage periods, tags, and third-party vendor scripts against privacy requirements.
•            Integrate privacy platforms with identity systems, ticketing tools, data catalogs, lineage platforms, and evidence repositories.
•            Embed privacy and data protection controls into CI/CD pipelines through secret scanning, privacy code scanning, schema validation, and data-egress policies.
•            Produce compliance evidence and reporting for GDPR, CCPA/CPRA, PCI DSS, HIPAA, and internal audits.
•            Maintain control-health dashboards, regulatory tracking, and program KPIs.
•            Investigate data incidents and privacy events in partnership with the Incident Response, SOC, and Privacy teams.
•            Collect evidence, assist with forensic investigations, document findings, and implement preventive engineering fixes.
•            Harden data security and identity platforms and remediate vulnerabilities or configuration weaknesses.
•            Participate in red-team exercises and tabletop scenarios involving insider misuse, public-link exposure, and unintended use of data for AI training.
•            Develop engineering standards, reference architectures, operating procedures, runbooks, and technical training materials.
Â
Looking forward to work with you!
Â
Â
Thanks & Regards
Â
Lokesh Yadav
Sr. Technical Recruiter
CloudThink Tech Inc