Lead Data Privacy Engineer
Listed on 2026-02-13
-
IT/Tech
Cybersecurity, Data Security
Overview
We’re building a world of health around every individual — shaping a more connected, convenient and compassionate health experience. At CVS Health®, you’ll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger – helping to simplify health care one person, one family and one community at a time.
ResponsibilitiesLead Data Privacy Engineer to assist in leading our Data Protection Engineering, Monitoring, and Audit efforts. This role is responsible for embedding privacy by design principles into systems and processes, designing and maintaining technical controls to safeguard personal data (PII), and ensuring compliance with privacy regulations while supporting business objectives. The position requires a strong technical database background and deep knowledge of privacy laws and security and privacy frameworks, working closely with cross functional teams to maintain a robust data security & privacy posture.
Drive strategy, planning, prioritizing, and execution of data security and privacy initiatives to protect unstructured and structured data in hybrid environments.
Design and Implementation of Privacy Enhancing Technologies (PETs), lead privacy-preserving solutions planning, design, development, implementation, and monitoring.
Drive and support technical components compliance/audit processes.
Provide expert guidance on secure systems architecture, design and implementation in alignment with privacy engineering principles.
Continuous monitoring of emerging technologies, regulatory developments and industry trends to recommend enhancements to organizational privacy posture. Develop and maintain data protection dashboard, metrics roadmap, and scorecards.
Apply threat modeling and risk analysis methodologies to mitigate privacy and security risks. Facilitate risk-based approach to develop, manage, and maintain data protection controls.
Collaborate with engineering, product, legal, and compliance teams to translate privacy and regulatory requirements (e.g., GDPR, CCPA, HIPAA) into technical designs, policies, and guardrails.
Foster a privacy by design culture and embed privacy requirements into engineering documentation.
Lead and contribute to enterprise data governance activities, including data discovery, classification, data loss prevention, audit, and incident response.
Lead project teams of talented professionals to deliver data security capabilities.
7+ years of hands-on experience in security engineering, privacy engineering, privacy enhancing technologies or related fields.
7+ years of experience with privacy and data protection regulations (GDPR, CCPA, HIPAA, etc.) and translating them into technical requirements.
5+ years of experience in one or more programming or scripting languages (e.g. Python, Java, Go, Rust, or similar).
5+ years of experience in designing and implementing cryptographic or data protection systems (e.g. encryption, tokenization, key management).
5+ years of experience in performing privacy threat modeling, data flow mapping, and conducting DPIAs/PIAs.
5+ years of experience in working in CI/CD environments, Infrastructure as Code (IaC), and automating security/privacy checks.
5+ years of data security technology experience, including data classification, DLP, insider risk, encryption, web content filtering and CASB.
Professional Certifications such as CDPSE, CIPP, CIPT, CIPM, CISSP, or equivalent.
Experience with security controls alignment to key regulations like NIST, FIPS 140-2, ISO, HITRUST, HIPAA, PCI, CPRA, GDPR
Experience supporting regulatory audits, investigations, or independent assessments.
Experience building and scaling privacy platforms or features in a fast-paced environment (e.g. developing & automating processes, leveraging AI ML).
Familiarity with Data Loss Prevention (DLP) systems and data mapping tools.
Familiarity with cloud platforms (AWS, Azure, GCP) and various data technologies (SQL, No
SQL databases, data lakes, etc.).Experience implementing controls at scale in…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).