We are seeking a highly technical and delivery-focused Data Protection Engineer to support the Cybersecurity, Engineering, and Compliance organisations. This role is responsible for designing, implementing, and continuously improving technical safeguards that protect sensitive corporate and customer data across cloud, endpoint, and enterprise environments.
As a subject matter expert in data security and privacy engineering, this individual deploys and tunes data discovery, classification, DLP, encryption, and key management controls. The Data Protection Engineer partners closely with Engineering, IT, Compliance, Legal, and Privacy stakeholders to embed privacy-by-design principles into how data is created, stored, shared, retained, and monitored.
Success in this role means measurably reducing data exposure risk, strengthening compliance alignment (e. g., SOC 2 PCI, privacy obligations), improving signal quality in data protection tooling, and delivering audit-ready, scalable controls that enable teams to operate quickly and responsibly.
This role is anchored in our company's core competencies. These competencies reflect the mindsets and behaviours that define success in this role. We outline how each competency translates into real-world actions and outcomes specific to this role.
The candidate will have responsibilities across the following functions:
Results Driven:
- Leads Data Discovery, Classification and DLP Implementation by deploying and tuning data discovery and classification tooling across corporate and cloud environments, expanding coverage of sensitive data repositories and improving DLP signal quality.
- Implements and strengthens Encryption, Tokenisation and Key Management Controls, including key rotation, access control enforcement, and break-glass procedures, reducing exposure risk for sensitive corporate and customer data.
- Drives measurable improvements in Data Lifecycle Management and Retention Enforcement in partnership with system owners, ensuring appropriate storage patterns, retention schedules, and secure disposal of data assets.
- Delivers documented 30-, 150-, and 210-day outcomes including expanded classification coverage, reduced DLP false positives, improved encryption posture, and executive-ready reporting on data protection KPIs.
Takes Ownership
- Integrates Data Protection Tooling with Governance and Incident Response Systems (e. g., SIEM/SOAR, ticketing) to ensure DLP alerts, misconfigurations, and exposure risks are investigated and resolved in a structured and auditable manner.
- Partners with Compliance, Legal, and Privacy stakeholders to translate regulatory and contractual obligations into enforceable technical controls aligned to SOC 2 PCI, and privacy requirements.
- Investigates and supports response to Data Protection Incidents, including DLP events, accidental exposure, and misconfiguration scenarios, ensuring corrective actions are tracked to closure.
- Develops and maintains documentation, operational standards, and runbooks that support audit readiness, evidence integrity, and repeatable control execution.
Drives Efficiency:
- Automates audit evidence collection and continuous control validation workflows using scripting and APIs (e. g., PowerShell, Python), reducing manual effort and improving reliability of compliance reporting.
- Standardises data protection configurations, labelling models, and DLP policy structures to improve consistency across systems and reduce operational friction.
- Establishes repeatable dashboards and metrics to measure data protection coverage, control effectiveness, false-positive rates, and remediation timelines.
- Embeds privacy-by-design principles into product and engineering workflows by providing structured guidance on secure data flows, storage patterns, logging, and access controls.
Innovative
- Applies forward-looking data protection strategies to address evolving cloud, collaboration, and SaaS risks, ensuring controls adapt to modern work patterns and distributed environments.
- Leverages AI and automation to enhance data classification accuracy, improve anomaly detection in DLP alerts, and generate actionable insights from data protection telemetry.
- Continuously evaluates emerging data governance and privacy engineering capabilities, translating new tooling and best practices into scalable improvements across the enterprise.
Requirements:
- Bachelor's degree in Information Security, Computer Engineering, or a related field (or equivalent experience).
- 5+ years of experience in data security, privacy engineering, or security engineering roles.
- Hands-on experience with data discovery, classification, and governance platforms (e. g., Microsoft Purview, OneTrust, or similar).
- Experience implementing and tuning DLP controls across endpoints, email, collaboration platforms, and cloud storage environments.
- Experience implementing encryption, tokenisation, and key management controls.
- Familiarity with compliance frameworks such as SOC 2 PCI, and privacy regulations.
- Ability to automate workflows and integrations using scripting and APIs (PowerShell, Python, or similar).
- Strong documentation and cross-functional collaboration skills.
- Certifications such as CDPSE, CIPT, Security+, or similar are a plus.
- High integrity and sound judgment when handling sensitive and confidential information.

