Strengthening and safeguarding the security of critical database platforms, both on-premises and in the cloud. The Security Engineer is responsible for designing, implementing and continuously improving security measures related to access control, encryption, logging, monitoring and secure-by-design data processes.
Expected Outcome of the Assignment
A demonstrably stronger database security landscape in which access control, encryption, monitoring and data processes have been structurally improved, and where critical data is managed and protected according to secure-by-design principles.
Responsibilities
Database Hardening & Platform Security
Harden database platforms, including SQL, NoSQL and cloud-native databases.
Implement security standards and best practices for configuration, patching and lifecycle management.
Perform risk assessments and translate identified risks into concrete technical security measures.
Access Control & Identity Security
Strengthen access controls, including RBAC, least-privilege principles and privileged access models.
Integrate identity and access processes with IAM platforms and cloud security controls.
Establish secure processes for service accounts, secrets management and key management.
Encryption, Logging & Monitoring
Implement and optimise encryption mechanisms for data at rest, data in transit and key management.
Deploy centralised logging and audit mechanisms for database activities.
Integrate database telemetry with SIEM and SOC environments to support detection, alerting and forensic analysis.
Secure-by-Design Data Processes
Embed security structurally into platform and data processes, including CI/CD, provisioning, backup and recovery.
Advise on secure data flows, data classification and data minimisation.
Support platform teams and DBAs in securely onboarding new databases and workloads.
Collaboration & Stakeholder Management
Work closely with DBAs, platform teams, security teams and cloud architects.
Act as a subject matter expert and trusted advisor for data owners and application teams.
Clearly communicate risks, impact and required security measures to both technical and non-technical stakeholders.
Ideal Profile
Extensive experience with database security in both on-premises and cloud environments such as Azure, AWS and GCP.
In-depth knowledge of SQL and NoSQL platforms, database architecture and data security principles.
Experience with encryption, key management, auditing, monitoring and database-related incident response.
Strong background in IAM, privilege management and secure-by-design engineering.
Ability to analyse complex data processes and translate them into robust security solutions.
Strong communication skills, a proactive mindset and the ability to engage teams in implementing security improvements.