About The Position

The Data at Rest Protection Engineer is responsible for supporting and securing enterprise-scale data protection platforms across hybrid cloud and on-prem environments, with a strong focus on encryption, tokenization, key management, and operational stability. This role partners closely with application and infrastructure teams to troubleshoot integrations, automate operational processes, maintain security controls, and ensure reliable protection of sensitive data across complex production ecosystems.

Requirements

  • BS/BA in information Technology or related field of study and a minimum of 8 years experience in systems administration and security aspects of information systems, access management and network security technologies, network communications, computer networking, telecommunications, systems development and management, hardware, software, data, and people; experience with multiple technical and business disciplines required; requires broad-based experience to plan and design highly complex systems; or any combination of education and experience, which would provide an equivalent background.

Nice To Haves

  • Deep Protegrity expertise across components (architecture familiarity, deployment patterns, policy design/administration, integration troubleshooting, performance/stability considerations).
  • Infrastructure as Code: Experience deploying and troubleshooting with Terraform, including debugging plans/applies, module usage, environment promotion, and state troubleshooting practices.
  • Source control workflows: Experience maintaining infrastructure/config/code in GitHub (or similar), including PR reviews and release/change workflows.
  • Multi-cloud exposure: Practical experience across AWS plus either Azure or GCP (or strong willingness to ramp quickly), especially where app integrations span environments.
  • Serverless integration patterns: Hands-on experience with serverless services (e.g., Lambda/Azure Functions/Cloud Functions, or Cloud Run) and the security/identity patterns around them.
  • Containers/Kubernetes familiarity: Working knowledge of EKS/AKS and/or Cloud Run (or equivalent), particularly around connectivity, identity, secrets, and logging.
  • SIEM/log analysis: Ability to write effective Splunk queries and use log data to support troubleshooting and investigations.
  • ITSM/workflow: ServiceNow experience (incident/request management; creating or maintaining request/catalog forms is a plus).
  • Data platforms & formats: Experience supporting data protection for object storage, databases, and file-based transfers (delimited/fixed-width), including operational concerns like scanning, access patterns, and throughput.
  • Snowflake exposure: Experience with Snowflake integrations/usage (connectivity, role/access concepts, data pipelines, or security model familiarity).
  • Secrets management integration: Experience integrating pipelines/apps with HashiCorp Vault (auth methods, secret consumption patterns, rotation).
  • HSM experience: Experience performing HSM initialization and operations (key ceremony participation, partition/user setup, integration troubleshooting).

Responsibilities

  • Leads system and network architecture support for enterprise information security technologies, including encryption, tokenization, and key management platforms across hybrid cloud and on-prem environments
  • Leads development and execution of risk assessment methodologies to fit business, regulatory, and technical environment considerations
  • Leads the development of requirements, system architecture, and software design of security products and services, including secure data protection integration patterns for enterprise applications
  • Leads the development of strategies for discovery, evaluation and response to new networking attacks
  • Develops security incident response plans and strategies, including support for incident triage, escalation, and post-incident remediation activities
  • Provides trouble resolution and serves as point of technical escalation on complex problems involving network connectivity, TLS handshakes, DNS, and service-to-service communication issues
  • Creates presentations and seeks IT management approval and acceptance of significant replacements or reconfigurations of major security systems serving the Enterprise
  • Sets vendor strategy and direction
  • May be assigned to project teams for technical consultation to business partners and developers supporting cloud, serverless, and hybrid infrastructure integrations
  • Designs & engineers comprehensive access management and network security technical solutions based on business requirements and defined technology standards; works with architecture to update technology direction & strategy
  • Develops reports supporting strategy and direction for management
  • Capable of serving as technical merger & acquisition lead
  • Acts as a subject matter expert among peers, with manager and senior management on data protection technologies, encryption standards, and operational security best practices
  • Must be capable of providing top-tier support for 5 or more of the information security technology common body of knowledge skill sets: 1) Access Control, 2) Application Security, 3) Business Continuity and Disaster Recovery Planning, 4) Cryptography, 5) Information Security and Risk Management 6) Legal, Regulations, 7) Compliance and Investigations, 8) Operations Security, 9) Physical (Environmental) Security, 10) Security Architecture and Design, 11) Telecommunications and Network Security

Benefits

  • merit increases
  • paid holidays
  • Paid Time Off
  • incentive bonus programs
  • medical, dental, vision
  • short and long term disability benefits
  • 401(k) +match
  • stock purchase plan
  • life insurance
  • wellness programs
  • financial education resources
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service