Data Security Analyst
Job Description
Remote role securing enterprise data warehouses, ETL/ELT pipelines, and analytics platforms in international and government environments.
Responsibilities
- Support organization-wide data classification programs for international and government contexts.
- Coordinate and maintain classification schemas (Public, Internal, Confidential, Restricted/Sensitive, Classified) and ensure consistent tagging and handling across data warehouses and pipelines.
- Implement and maintain classification-driven security controls in data platforms including Snowflake, Redshift, BigQuery, Databricks, Azure Synapse, Microsoft Fabric, or on-prem solutions, covering:
- RBAC
- column/row-level security
- dynamic data masking
- encryption at rest
- audit logging
- Manage data sovereignty, localization requirements, and cross-border transfer mechanisms such as Standard Contractual Clauses, Binding Corporate Rules, and adequacy decisions.
- Ensure compliance with GDPR, LGPD, PIPL, and CCPA/CPRA, plus other regional regulations.
- Support government security frameworks including FedRAMP, FISMA, NIST 800-53, CMMC, ITAR or equivalent.
- Prepare for audits, maintain ATO evidence, and implement security controls needed for government contracts or public sector data.
- Secure data ingestion, transformation, and movement using classification-aware controls.
- Protect interfaces (APIs, SFTP, EDI, messaging queues) using TLS, mutual authentication, encryption, and DLP policies suitable for international and government data exchanges.
- Enforce access controls aligned to data classification, user clearance levels (where applicable), and need-to-know principles.
- Manage privileged access and conduct regular access reviews and recertifications.
- Support risk assessments, vulnerability scans, and penetration testing focused on international data flows and government environments.
- Monitor logs and support Cyber Security SIEM detection and compliance monitoring (SIEM use described as part of the role).
- Support security incident investigations involving data warehouses, including proper handling aligned to government and international breach notification requirements.
- Partner with data engineering, compliance, legal, and government stakeholders to embed security and classification into data architecture and pipelines.
- Advise on secure data sharing with international partners or government agencies.
- Perform other responsibilities as assigned.
Requirements
- Bachelor’s degree in Computer Science, Information Security, Cybersecurity, or related field.
- Typically 5 (five) years of experience in data security, including international (multi-jurisdictional) and/or government / public sector environments.
- Hands-on experience with major cloud and on-premise data platforms in secure environments.
- Experience implementing encryption, key management, DLP, and secure data exchange protocols.
- US Citizenship required.
- Deep knowledge of data classification frameworks and tools in regulated settings.
- Strong understanding of international privacy and data protection laws (including GDPR and Schrems II).
- Strong understanding of US Government standards (including FedRAMP, NIST, FISMA, DoD SRG).
- Strong understanding of cloud security and compliance, including AWS, Azure, GCP Government Cloud.
- Ability to support security risk assessments and forensic investigations aligned to global breach notification laws.
- Ability to translate complex international privacy and government regulations into actionable, automated technical controls.
- Ability to maintain clear, audit-ready evidence for internal/external auditing and corporate compliance records.
- Strong analytical thinking, problem-solving skills, and a strategic mindset with capacity to navigate ambiguity and make data-driven decisions.
- Ability to work effectively in a fast-paced environment, both independently and collaboratively.
- Ability to present complex technical information to a non-technical audience.
- Strong collaboration, interpersonal skills, and communication skills.
Technologies
- Snowflake, Redshift, BigQuery, Databricks, Azure Synapse, Microsoft Fabric
- RBAC, dynamic data masking, encryption at rest, audit logging
- Standard Contractual Clauses, Binding Corporate Rules, adequacy decisions
- GDPR, LGPD, PIPL, CCPA/CPRA
- FedRAMP, FISMA, NIST 800-53, CMMC, ITAR
- TLS, mutual authentication, DLP
- SIEM (including Microsoft Purview noted below), Microsoft Purview, Collibra, Alation
- Python, SQL, PowerShell
- CISSP, CISM, CCSP, CRISC, CDPSE, Security+, CAP
- AWS Certified Security, Azure Security Engineer, Google Cloud Professional Security Engineer
- AWS GovCloud, Azure Government
Benefits
- Health, dental, and vision insurance
- Paid time off and holidays
- Retirement benefits including 401(k) matching
- Educational reimbursement
- Parental leave
- Employee stock purchase plan
- Tax-saving options
- Disability and life insurance
- Pet insurance
Knowledge, Skills & Abilities
- Industry-specific knowledge and experience related to the organization’s projects are preferred (Cyber, Infrastructure, Application Development, etc.).
Preferred Skills & Certifications
- Security certifications: CISSP, CISM, CCSP, CRISC, CDPSE, or government-specific (Security+, CAP).
- Cloud certifications: AWS Certified Security, Azure Security Engineer, Google Cloud Professional Security Engineer (Government Cloud experience highly valued).
- Familiarity with data governance platforms (Microsoft Purview, Collibra, Alation) and automated classification tools.
- Experience with hybrid/multi-cloud architectures and secure government cloud environments (AWS GovCloud, Azure Government, etc.).
- Scripting skills (Python, SQL, PowerShell) for automation of classification, monitoring, and compliance reporting.
- Strong ability to translate complex regulatory requirements into practical technical controls.
Compensation
- $100,000 - $121,000 per year
Posting Details
- 08/04/2026 - Until Filled
- Amentum anticipates the requisition will remain open for at least three days, with a closing date no earlier than three days after the original posting (timeline may change based on business needs).