About The Position

Join Aya Healthcare, winner of multiple Top Workplace awards! We are seeking a Senior Security Engineer I – Data Security to join Aya’s Security Engineering team. This senior individual contributor role focuses on designing, implementing, and operating scalable data security and governance controls across Aya’s cloud analytics and data platforms, with a strong emphasis on Azure, Microsoft Purview, and Databricks. In this role, you will partner closely with data engineering, platform, analytics, and compliance teams to protect sensitive data throughout its lifecycle - ingestion, processing, storage, analytics, and sharing. You will lead hands-on technical work while also owning end‑to‑end delivery of data security initiatives, helping mature Aya’s data security posture in alignment with regulatory, privacy, and business requirements. Aya’s data platforms are central to delivering trusted healthcare technology and insights. In this role, you will directly shape how sensitive data is protected, governed, and used responsibly at scale - balancing strong security controls with developer velocity and business outcomes.

Requirements

  • Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent practical experience.
  • 5+ years of experience in security engineering, with strong emphasis on data security in cloud environments.
  • Deep hands-on experience with Azure, including PaaS and data services (ADLS Gen2, Azure SQL, Synapse, Storage Accounts).
  • Practical experience with Microsoft Purview for data governance, classification, lineage, and entitlement insights.
  • Hands-on experience securing Databricks environments, including workspace security, cluster policies, secrets management, and data access controls.
  • Strong proficiency with Terraform and infrastructure-as-code, including secure patterns and policy enforcement.
  • Experience with identity and access management (Entra ID, managed identities), networking (private endpoints, firewalls), and encryption.
  • Proficiency in scripting or automation using Python, PowerShell, or similar languages.
  • Strong understanding of data protection principles, privacy-by-design, and common regulatory frameworks.

Nice To Haves

  • Experience securing analytics and big-data platforms in regulated or highly sensitive environments.
  • Familiarity with data loss prevention (DLP), tokenization, masking, or privacy-enhancing technologies.
  • Experience integrating data security tooling with SIEM/SOC workflows.
  • Relevant certifications such as Azure Security Engineer Associate, Azure Data Engineer, SC-400, or equivalent.

Responsibilities

  • Lead the design, implementation, and ongoing improvement of data security controls across Azure data services and Databricks environments, including data classification, access control, encryption, and monitoring.
  • Implement and operationalize Microsoft Purview capabilities such as data discovery, classification, sensitivity labeling, lineage, cataloging, and access insights across structured and unstructured data sources.
  • Define and enforce least-privilege access models for data platforms using Azure RBAC, Entra ID, managed identities, service principals, and Databricks workspace permissions.
  • Partner with privacy, compliance, and legal stakeholders to translate regulatory and contractual requirements into actionable technical controls and standards.
  • Perform in-depth security reviews of Azure data architectures, including storage accounts, Azure SQL, Synapse, ADLS Gen2, Event Hubs, and Databricks deployments.
  • Assess and remediate data-related risks in infrastructure-as-code (Terraform), platform configurations, and CI/CD pipelines.
  • Contribute secure-by-design patterns and reusable templates for data platforms, incorporating encryption, private networking, logging, and policy-as-code.
  • Design and maintain data security monitoring and alerting, integrating Purview, Azure Monitor, and Defender for Cloud workflows.
  • Support investigation and response for data security incidents, including exposure analysis, root cause identification, and long-term remediation.
  • Own documentation, standards, and security guidelines for data platforms; ensure alignment with Aya security standards and audit expectations.
  • Lead medium- to large-scope data security initiatives end-to-end, including requirements, design, implementation, stakeholder alignment, and measurable outcomes.
  • Mentor Security Engineers and partner engineers on data security best practices; act as a subject-matter expert for data protection topics.
  • Translate complex technical risks into clear business impact for engineering leaders and stakeholders.

Benefits

  • Free premium medical, dental, life and vision insurance
  • Generous 401(k) match
  • Reimbursements and discretionary bonuses
  • Paid sick leave in accordance with all applicable state, federal, and local laws
  • Unlimited DTO
  • Virtual yoga, meditation or boot camp classes offered daily
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service