
Principal, Access and Data Security SME
EEOC
full-time
Posted on:
Location Type: Hybrid
Location: Scottsdale • Arizona • California • United States
Visit company websiteExplore more
Salary
💰 $154,000 - $193,000 per year
Job Level
Tech Stack
About the role
- Overall Purpose: The Principal of Access Control & Data Security Oversight is responsible for ensuring the organization’s Access Control and Data Security programs are effective, risk-aligned, and defensible—through independent challenge, governance, and validation.
- This role provides independent risk-based governance within a Three Lines of Defense (3LOD) model, ensuring access management and data protection practices are effective, measurable, and aligned to risk appetite and regulatory expectations.
- The position partners closely with engineering, identity, data, and application teams, acting as a credible challenger—not an operator.
- This role will support the Cybersecurity and Technology Risk Management team within the Second Line of Defense (2LOD) and report directly to the 2LOD VP of Information Security Risk.
Requirements
- Data Security Deep expertise in data security domains including encryption, tokenization, masking, and DLP.
- Experience with data classification frameworks and data lifecycle management.
- Strong understanding of data architectures across cloud, on-prem, and hybrid environments.
- Ability to translate data risk into business impact and regulatory implications.
- Access Control Deep expertise in IAM, PAM, and access governance models.
- Experience with identity systems, federation, and modern authentication (e.g., SSO, MFA, Zero Trust).
- Strong understanding of least privilege, role-based and attribute-based access control models.
- Ability to assess and communicate access-related risks at scale.
- General Qualifications 15+ years of IT experience with 8+ years in Information Security.
- Experience operating in a Three Lines of Defense model and/or regulated environment (financial services preferred).
- Ability to translate technical findings into business risk and executive-level insights.
- Experience in fintech or highly regulated industries.
- Familiarity with regulatory expectations for data protection and access control.
- Background in risk management, audit, or control validation.
Benefits
- Healthcare Coverage – Competitive medical (PPO/HDHP), dental, and vision plans as well as company contributions to your Health Savings Account (HSA) or pre-tax savings through flexible spending accounts (FSA) for commuting, health & dependent care expenses.
- 401(k) Retirement Plan – Featuring a 100% Company Safe Harbor Match on your first 6% deferral immediately upon eligibility.
- Paid Time Off – Flexible Time Off for Exempt (salaried) employees, as well as generous PTO for Non-Exempt (hourly) employees, plus 11 paid company holidays and a paid volunteer day.
- 12 weeks of Paid Parental Leave
- Maven Family Planning – provides support through your Parenting journey including egg freezing, fertility, adoption, surrogacy, pregnancy, postpartum, early pediatrics, and returning to work.
- And SO much more!
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills & Tools
data securityencryptiontokenizationmaskingDLPdata classification frameworksdata lifecycle managementIAMPAMaccess governance
Soft Skills
ability to translate data risk into business impactability to assess and communicate access-related risksability to translate technical findings into business riskstrong understanding of data architecturescredible challenger