Security Engineer
Listed on 2026-02-16
-
IT/Tech
Cybersecurity, Data Security
Overview
Truveta is the world’s first health provider led data platform with a vision of Saving Lives with Data. Our mission is to enable researchers to find cures faster, empower every clinician to be an expert, and help families make the most informed decisions about their care. Achieving Truveta’s ambitious vision requires an incredible team of talented and inspired people with a special combination of health, software and big data experience who share our company values.
This position is based out of our headquarters in the Greater Seattle Area and requires onsite presence 5 days per week.
If you are interested in the opportunity to pursue purposeful work, join a mission-driven team, and build a rewarding career while having fun, Truveta may be the perfect fit for you.
This Opportunity:
Success in the healthcare industry is predicated on a foundation of trust. We demonstrate our trustworthiness as stewards of health data through three foundational pillars: security, privacy, and compliance. The successful candidate will design, implement and support solutions that support the company’s Digital Workplace strategy. They will work on leading edge technologies that help modernize endpoint management by leveraging the cloud to quickly deliver end-user improvements.
Data Security & Governance Engineering
- Design, implement, and operate data discovery and classification programs across structured and unstructured data sources
- Define and maintain data classification standards, labels, and handling requirements aligned with business and regulatory needs
- Deploy, tune, and maintain data security and governance tooling (e.g., Microsoft Purview, DLP, Defender for Cloud Apps, DSPM platforms)
- Integrate data discovery, classification, and exposure signals into security and governance workflows
- Partner with engineering and data platform teams to embed secure-by-design data governance controls into data pipelines and cloud services
- Continuously improve visibility into where sensitive data lives, how it is accessed, and how it is protected
Vulnerability & Exposure Management
- Own and operate vulnerability management efforts with a focus on risks that impact sensitive data
- Identify and assess data exposure risks caused by cloud misconfigurations, excessive permissions, insecure APIs, and weak access controls
- Correlate vulnerability and exposure data with data sensitivity and business impact to drive risk-based prioritization
- Track remediation actions to completion and validate the effectiveness of implemented fixes
- Provide clear reporting on vulnerability trends, data exposure risk, and remediation progress
Proactive Data Security & Risk Reduction
- Proactively identify shadow data stores, over-shared resources, and misclassified sensitive data
- Monitor and continuously improve data security posture, including access controls, encryption, and data lifecycle protections
- Bachelor’s degree in Cyber Security, Computer Science, Information Security, Information Systems, or a related field, or equivalent practical experience
- 5+ years of experience in Security Engineering, Data Security, Cloud Security, Vulnerability Management, or Governance-focused roles
- Hands-on experience with data discovery, classification, and governance tools (e.g., Microsoft Purview, DLP, DSPM platforms)
- Strong understanding of data security concepts, including classification, encryption, access control, data lifecycle management, and least privilege
- Experience operating or contributing to vulnerability management programs, including prioritization and remediation tracking
- Solid understanding of Azure cloud architecture, data services, and native security controls
- Familiarity with identity and access management (Azure Entra , RBAC) as it relates to data access and exposure risk
- Knowledge of regulatory and compliance frameworks impacting data security (e.g., SOC 2, HIPAA, GDPR, ISO 27001)
- Strong written and verbal communication skills, with the ability to explain data risk to both technical and non-technical stakeholders
- Ability to work cross-functionally and influence without direct authority
- Relevant certifications such as SC-400…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).