Skip to main content
Root

Senior Security Engineer - Data Security

RemoteUnited States only
Published
Role
Security
Experience
Senior
Employment
Full-time
$111.5k–$139.4k/yr
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Senior Security Engineer needed to lead data security, define protection strategies for sensitive data at scale, and establish standards and risk priorities across the data lifecycle. Requires 5+ years in data/cloud security, hands-on experience securing cloud data, and familiarity with IAM, encryption, data classification, DLP, and privacy regulations.

Core skills

Data SecurityCloud Security

Required skills

IAMRBAC/ABACencryptionKMS/HSMdata classificationDLPdata discoveryaccess reviewstokenizationmaskingretentiondeletionbackup securityaudit loggingscriptingAPIspolicy-as-codeAI-assisted tools

Optional skills

data security posture managementdata activity monitoringenterprise DLPcloud data security platformsinfrastructure-as-codeCI/CD securitypolicy-as-codesecurity automation

Required languages

English

What you'll do

  • Help establish the data security strategy and roadmap for sensitive policyholder, customer, employee, and corporate data.
  • Protect PII, financial information, health-related information where applicable, claims data, and other regulated or confidential data across its full lifecycle.
  • Establish standards for data classification, encryption, key management, masking, tokenization, anonymization, pseudonymization, retention, deletion, and secure data sharing.
  • Design and improve data access governance, including least privilege, RBAC/ABAC, privileged access, row-level controls, column-level controls, and periodic access reviews.
  • Partner with Data Platform and Analytics teams to embed security controls into data pipelines, warehouses, data lakes, reporting platforms, and machine learning workflows.
  • Improve visibility into sensitive data stores, data flows, third-party transfers, and access patterns through discovery, monitoring, DLP, and related security tooling.
  • Establish secure backup, recovery, and resilience requirements for critical data.
  • Translate regulatory and business requirements into practical technical controls and measurable risk-reduction initiatives.
  • Lead cross-functional prioritization, balancing urgent risk remediation with long-term data security maturity and SOC 2 readiness.
  • Automate security workflows using scripting, APIs, policy-as-code, and approved AI-assisted tools while protecting confidential and regulated information.
  • Develop playbooks, reference architectures, and reusable patterns that improve consistency and reduce operational overhead.
  • Participate in the Security Engineering on-call rotation, triaging alerts and security issues during business hours and responding to after-hours escalations as needed.
  • Communicate data security risks, decisions, and recommendations clearly to engineers, business stakeholders, and senior leadership.
  • Coach engineering and analytics teams on secure data handling and help raise the organization’s overall data security maturity.

What they require

  • 5+ years of experience in data security, cloud security, security engineering, privacy engineering, or a related technical field.
  • Hands-on experience securing sensitive data in cloud environments and applying controls across storage, processing, analytics, and data-sharing systems.
  • Experience with several of the following: IAM, RBAC/ABAC, encryption, KMS/HSM, data classification, DLP, data discovery, access reviews, tokenization, masking, retention, deletion, backup security, and audit logging.
  • Demonstrated experience embedding security requirements into data platforms, data pipelines, analytics workflows, or application architectures.
  • Experience working with engineering, data platform, analytics, infrastructure, Security Operations, Privacy, Legal, or GRC teams.
  • Experience improving security operations through automation, scripting, integrations, policy-as-code, or systematic process improvement.
  • Familiarity with applicable privacy, security, and regulatory requirements, such as HIPAA, GLBA, state privacy laws, NYDFS, PCI DSS, NIST, or similar frameworks, where relevant.
  • Strong communication skills, including the ability to explain technical risks and tradeoffs to both engineers and senior leadership.
  • Demonstrated ability to balance security requirements with business needs and build alignment across stakeholders.
  • Sound judgment when using approved AI-assisted tools with confidential, proprietary, or regulated information.
  • Preferred Qualifications: Experience in insurance, financial services, healthcare, or another regulated industry.
  • Preferred Qualifications: Experience with data security posture management, data activity monitoring, enterprise DLP, or cloud data security platforms.
  • Preferred Qualifications: Familiarity with major cloud providers and cloud-native data services.
  • Preferred Qualifications: Experience with infrastructure-as-code, CI/CD security, policy-as-code, or security automation.
  • Preferred Qualifications: Experience supporting SOC 2, HIPAA, GLBA, NYDFS, PCI DSS, ISO 27001, or similar compliance programs.
  • Preferred Qualifications: Familiarity with AI-assisted engineering tools such as GitHub Copilot, Claude, Codex, or comparable platforms.
  • As part of Root's interview process, we kindly ask that all candidates be on camera for virtual interviews. This helps us create a more personal and engaging experience for both you and our interviewers. Being on camera is a standard requirement for our process and part of how we assess fit and communication style, so we do require it to move forward with any applicant's candidacy. If you have any concerns, feel free to let us know once you are contacted. We’re happy to talk it through.
  • Consistent with the Americans with Disabilities Act (ADA) and the Civil Rights Act of 1964, it is the policy of Root to provide reasonable accommodation when requested by a qualified applicant or candidate with a disability, unless such accommodation would cause an undue hardship for Root. The policy regarding requests for reasonable accommodation applies to all aspects of the hiring process. If reasonable accommodation is needed, please contact recruiting@joinroot.com.

Benefits

  • Eligible for competitive bonus and equity offering

Root was founded on the belief that car insurance is broken, and we set out to change it. We’re harnessing the power of technology to revolutionize this archaic, complicated industry. Using machine learning and mobile telematic platforms, we’ve built one of the most innovative insurtech companies in the world.

🇺🇸 United StatesInsuranceStartup
$111.5k–$139.4k/yr