Data Security Posture Management

Location CO-Bogotá
Posted Date 2 hours ago(8/29/2026 2:23 PM)
Job ID
2026-4822
# Positions
1
Category
ITO

Job Summary

We are seeking an DSPM Lead who is responsible for designing, implementing, and managing the firm’s Data Security Posture Management capabilities across cloud, hybrid, and on‑premise environments. This role provides continuous visibility into where sensitive data resides, how it is accessed, whether it complies with global regulations, and how its security posture can be strengthened. The position serves as a bridge between Information Security, Data Governance, Risk &

Compliance, and GTech to ensure data‑level protection across all regions and systems. The ideal candidate will have hands-on expertise in DSPM technology.

Responsibilities

Sensitive Data Discovery & Classification

o Lead automated discovery of sensitive and regulated data across cloud platforms, SaaS, databases, and on prem systems, as described in DSPM core components.

o Ensure classification and tagging of PII, PHI, financial, client, and regulated data based on policy and regulatory requirements.

 

Risk Assessment & Exposure Analysis

o Continuously assess data exposure risks, excessive permissions, and misconfigurations across environments.

o Evaluate compliance alignment with ISO 27001, NIST 800‑53, GDPR, HIPAA, SOX, and internal standards.

 

Data Security Controls & Remediation

o Collaborate with Identity & Access Management to enforce least‑privilege access and remove excessive permissions.

o Recommend and implement security controls such as encryption, masking, tokenization, and DLP policies.

o Work with platform and application teams to remediate identified data security gaps.

 

Monitoring & Reporting

o Provide continuous monitoring of data access patterns, anomalies, and compliance posture across hybrid environments.

o Deliver automated reporting to Security, Compliance, IT Leadership, and audit stakeholders.

o Track and report metrics related to risk reduction, compliance, and overall data security posture.

 

Policy Alignment & Governance Collaboration

o Ensure alignment between DSPM strategy and the firm’s Data Lifecycle Management (DLM) and Data Governance programs.

o Support the development and enforcement of data‑centric security policies, standards, and operating procedures.

o Work with Data Owners and Stewards to validate classification requirements and ensure ongoing data protection across the lifecycle.

 

Tool & Technology Enablement

o Partner with GTech and Enterprise Architecture to ensure integrations align with global DSPM frameworks and strategy.

o Experience with DSPM vendor solutions (e.g., Veronis, Proofpoint, Cyberhaven) based on business needs and risk posture.

 

Cross‑Functional Incident Response Support

o Support escalations for data‑related security incidents in coordination with Legal, Compliance, GTech, and Business units.

o Participate in investigations involving data leakage, unauthorized access, or policy violations.

Skills and Experience

Skills

· Attention to detail and accuracy

· Strong problem-solving and analytical abilities

· Collaborative mindset across IT, Legal, and Compliance

· Ability to translate compliance requirements into technical controls

· Commitment to continuous improvement and data stewardship

 

Education / Professional Experience/ Qualifications

 

· Required Qualifications

o English Level B2+

o Bachelor’s degree in Information Management, Library Science, Computer Science, Business Administration, or a related field.

o 5+ years of experience in Data Management, Data/Information Governance, or Compliance within a digital environment.

o Deep understanding of DSPM concepts: data discovery, classification, lineage, access governance, risk scoring, and remediation workflows.

o Experience with cloud security architecture across Azure, AWS, and SaaS platforms.

o Strong understanding of IAM controls, RBAC, Conditional Access, and data‑level access models.

o Knowledge of encryption, masking, tokenization, and secure data handling practices.

o Strong familiarity with GDPR, HIPAA, SOX, ISO 27001, NIST frameworks, and global data protection laws.

o Ability to interpret regulatory requirements into technical and operational controls.

o Ability to analyze complex data landscapes and identify risks and remediation priorities.

o Strong communication skills for preparing executive‑ready dashboards and reports.

o Ability to collaborate with cross‑functional teams globally (US, EU, APAC).

 

· Preferred Qualifications

o 5+ years in Information Security, Data Governance, or Cloud Security programs.

o Experience working within multinational environments with complex data architectures.

o Certifications: CISSP, CISM, CCSP, Azure Security Engineer, or equivalent.

o Prior experience deploying DSPM technologies or building governance frameworks.

Options

Sorry the Share function is not working properly at this moment. Please refresh the page and try again later.
Share on your newsfeed