Remote job
Data Privacy Security Engineer
Job details
About this role
Role overview A Data Privacy Security Engineer will protect sensitive customer and business data across products, data platforms, and third-party services within a Southeast Asian fintech and insurance business. The role partners with Data, Engineering, Product, Legal, and Compliance teams to embed privacy-by-design and reduce data-related risks throughout the organisation.
Responsibilities - Safeguard sensitive data across collection, processing, storage, sharing, retention, and deletion stages. - Map data flows and assess privacy and security risks across applications, analytics, integrations, and third-party providers. - Implement encryption, tokenisation, masking, anonymisation, retention, and least-privilege data access controls. - Collaborate with data engineering teams to secure pipelines, databases, warehouses, and cloud data services on AWS and GCP. - Assess customer data shared with third-party AI model vendors and define minimisation, approved use, retention, and access controls. - Own data and privacy controls for SC TRM and BNM RMiT, including assessments, evidence, remediation, and audit support. - Support privacy impact assessments, access reviews, monitoring, incident response, and privacy-by-design reviews.
Requirements - Degree in Computer Science, Information Security, Data Engineering, or a related field, or equivalent experience. - Three or more years in data security, privacy engineering, security engineering, or data platform engineering. - Experience implementing and owning SC TRM and BNM RMiT controls relevant to data protection and technology risk. - Understanding of privacy-by-design, data classification, retention, access management, and third-party data sharing. - Knowledge of encryption, key management, masking, tokenisation, anonymisation, and secure data processing. - Experience securing databases, data pipelines, and AWS or GCP data platforms; familiarity with AI vendor data flows is beneficial. - Familiarity with applicable privacy and security frameworks and the ability to collaborate across technical and compliance teams.
Nice to have - Strong English communication is required, as English is the primary working language across global teams.