|
Join Aya Healthcare, winner of multiple Top Workplace awards! We are seeking a Senior Security Engineer I - Data Security to join Aya's Security Engineering team. This senior individual contributor role focuses on designing, implementing, and operating scalable data security and governance controls across Aya's cloud analytics and data platforms, with a strong emphasis on Azure, Microsoft Purview, and Databricks. In this role, you will partner closely with data engineering, platform, analytics, and compliance teams to protect sensitive data throughout its lifecycle - ingestion, processing, storage, analytics, and sharing. You will lead hands-on technical work while also owning endtoend delivery of data security initiatives, helping mature Aya's data security posture in alignment with regulatory, privacy, and business requirements. Aya's data platforms are central to delivering trusted healthcare technology and insights. In this role, you will directly shape how sensitive data is protected, governed, and used responsibly at scale - balancing strong security controls with developer velocity and business outcomes. Who We Are: We're a $8+ billion, rapidly growing workforce solutions provider in the healthcare industry. We deliver tech-enabled services that help healthcare organizations meet and manage their contingent labor needs. We build and manage tech-enabled marketplaces for national and local healthcare talent and deliver contingent labor management solutions through our proprietary software platform. At Aya, we're obsessed with creating exceptional experiences for our clients, clinicians, and employees. In fact, we put employee satisfaction above all else. Our team members are responsible for incomparable customer experience and we know that happy employees are critical to maintaining happy clients. We foster an entrepreneurial, high-energy, low-bureaucracy culture and value innovative thinking and creative problem-solving. We embrace diversity in thought and backgrounds unified by a commitment to high achievement. When you join Aya, you'll be surrounded by teammates who care about you as an individual and leaders who will help you grow both personally and professionally. Responsibilities: Data Security & Governance
- Lead the design, implementation, and ongoing improvement of data security controls across Azure data services and Databricks environments, including data classification, access control, encryption, and monitoring.
- Implement and operationalize Microsoft Purview capabilities such as data discovery, classification, sensitivity labeling, lineage, cataloging, and access insights across structured and unstructured data sources.
- Define and enforce least-privilege access models for data platforms using Azure RBAC, Entra ID, managed identities, service principals, and Databricks workspace permissions.
- Partner with privacy, compliance, and legal stakeholders to translate regulatory and contractual requirements into actionable technical controls and standards.
Cloud & Platform Security
- Perform in-depth security reviews of Azure data architectures, including storage accounts, Azure SQL, Synapse, ADLS Gen2, Event Hubs, and Databricks deployments.
- Assess and remediate data-related risks in infrastructure-as-code (Terraform), platform configurations, and CI/CD pipelines.
- Contribute secure-by-design patterns and reusable templates for data platforms, incorporating encryption, private networking, logging, and policy-as-code.
Detection, Monitoring & Incident Support
- Design and maintain data security monitoring and alerting, integrating Purview, Azure Monitor, and Defender for Cloud workflows.
- Support investigation and response for data security incidents, including exposure analysis, root cause identification, and long-term remediation.
Enablement, Documentation & Leadership
- Own documentation, standards, and security guidelines for data platforms; ensure alignment with Aya security standards and audit expectations.
- Lead medium- to large-scope data security initiatives end-to-end, including requirements, design, implementation, stakeholder alignment, and measurable outcomes.
- Mentor Security Engineers and partner engineers on data security best practices; act as a subject-matter expert for data protection topics.
- Translate complex technical risks into clear business impact for engineering leaders and stakeholders.
Required Qualifications:
- Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent practical experience.
- 5+ years of experience in security engineering, with strong emphasis on data security in cloud environments.
- Deep hands-on experience with Azure, including PaaS and data services (ADLS Gen2, Azure SQL, Synapse, Storage Accounts).
- Practical experience with Microsoft Purview for data governance, classification, lineage, and entitlement insights.
- Hands-on experience securing Databricks environments, including workspace security, cluster policies, secrets management, and data access controls.
- Strong proficiency with Terraform and infrastructure-as-code, including secure patterns and policy enforcement.
- Experience with identity and access management (Entra ID, managed identities), networking (private endpoints, firewalls), and encryption.
- Proficiency in scripting or automation using Python, PowerShell, or similar languages.
- Strong understanding of data protection principles, privacy-by-design, and common regulatory frameworks.
Preferred Qualifications:
- Experience securing analytics and big-data platforms in regulated or highly sensitive environments.
- Familiarity with data loss prevention (DLP), tokenization, masking, or privacy-enhancing technologies.
- Experience integrating data security tooling with SIEM/SOC workflows.
- Relevant certifications such as Azure Security Engineer Associate, Azure Data Engineer, SC-400, or equivalent.
What We Offer:
- Free premium medical, dental, life and vision insurance
- Generous 401(k) match
- Aya also offers other benefits to those that are eligibleand where required by applicable law, including reimbursementsand discretionary bonuses
- Aya provides paid sick leave in accordance with all applicable state, federal, and local laws. Aya's general sick leave policy is that employees accrue one hour of paid sick leave for every 30 hours worked. However, to the extent any provisions of the statement above conflict with any applicable paid sick leave laws, the applicable paid sick leave laws are controlling
- Celebrations! We hit our goals and reward ourselves.
- Company-sponsored virtual events, happy hours and team-building activities are always on the horizon - plus, you get a special treat on your birthday!
- UnlimitedDTO- we believe in time off!
- Virtual yoga, meditation or boot camp classes offered daily
Compensation: Aya reasonably anticipates the pay scale for this position to be an annual salary of $170,000 to $185,000. The pay scale for this position may vary if applicant possesses experience outside of what Aya reasonably anticipates for this position. Bonuses are subject to the role and your manager's discretion. Aya is an Equal Opportunity Employer (EEO), including Disability / Vets, and welcomes all to apply. Please click here for our EEO policy
|