OverviewPOSITION SUMMARY:
The IT Security Engineer (Database) is responsible for securing and protecting the organization’s enterprise databases, database platforms, and related data assets. This role combines database administration expertise with information security best practices to ensure the confidentiality, integrity, and availability of sensitive company and customer data.
This role is focused on database security engineering, not routine production database administration.You will partner closely with Database Administrators, Infrastructure, Application Development, Information Security, and Compliance teams to secure database architectures, monitor for suspicious activity, support vulnerability remediation, and strengthen data protection across the enterprise.The ideal candidate will have a strong background in database administration (DBA) along with hands-on experience in database security, auditing, vulnerability management, and data protection technologies in on premise data center and public cloud environments. The candidate must be familiar with a variety of database technologies, security concepts, practices, and procedures.
ESSENTIAL DUTIES AND RESPONSIBILITIES:
- Design, implement and maintain database security controls across SQL Server, Oracle, PostgreSQL, MySQL, NoSQL and cloud-native database services
- Conduct database security architecture reviews and recommend secure configurations before production deployment
- Operate and fine tune Database Activity Monitoring solutions such as IBM Guardium, Imerva Data Security Fabric/SecureSphere, Oracle Audit Valut, or equivalent platforms.
- Support public cloud database security for IaaS, PaaS, and SaaS environments including AWS, Azure, and Oracle Cloud platforms
- Implement and maintain controls for RBAC, least privilege, privileged access management, encryption, auditing, data masking, tokenization, and DLP
- Monitor database environments for suspicious activity, unauthorized access attempts, data exfiltration risks, and security anomalies
- Perform database vulnerability assessments, security reviews, patch management, and remediation activities
- Support Data Loss Prevention (DLP), database activity monitoring (DAM), and security information and event management (SIEM) integrations
- Partner with application teams and DBAs to ensure secure database design, configuration, and deployment practices
- Develop and maintain database security standards, baselines, policies, procedures, and technical documentation
- Assist in incident response investigations related to database security events and data breaches
- Participate in IT Security exercises, audits, penetration testing activities, and third-party assessments
- Support regulatory and compliance requirements including SOX, PCI-DSS, GLBA, SOC, and other applicable frameworks
- Automate database security monitoring, reporting, and operational tasks using scripting and automation tools
- Keep abreast of industry security trends, database technologies, vulnerabilities, and emerging threat profiles
- Perform any additional tasks required to support IT and Security control objectives, business objectives, IT projects, and others
SKILLS/KNOWLEDGE/ABILITIES:
Required Experience:
- BA/BS in Computer Science, Computer Engineering, Information Systems, or equivalent experience
- 7+ years of experience in database administration, database engineering, or database security
- Strong hands-on experience administering enterprise database platforms such as SQL Server, Oracle, PostgreSQL, or MySQL
- Experience implementing database security controls including encryption, auditing, access controls, and privileged access management
- Experience with database vulnerability scanning, monitoring, and remediation processes
- Experience in highly regulated environments, preferably Financial Services or similar industries
- Experience supporting cloud database technologies and security best practices in AWS, Oracle and/or Azure
Knowledge and Skills Required:
- Strong understanding of database architecture, database administration, backup/recovery, and performance concepts
- Knowledge of methods to secure databases, applications, and sensitive data assets
- In-depth knowledge of data protection engineering principles, DLP, encryption, masking, and tokenization.
- Strong research and troubleshooting skills
- Strong verbal and written communication skills
- Skill with SQL, Python, Bash, or PowerShell scripting
CERTIFICATIONS, LICENSES, and/or REGISTRATION:
- Preferred: the following licenses or certificates are preferred: CISSP, CISA, Security+, Microsoft Certified: Azure Database Administrator Associate, Oracle Database Security Certified Implementation Specialist, AWS Certified Security – Specialty, GIAC certifications, Microsoft SQL certifications, or equivalent database/security certifications
LOCATION & COMPENSATION:
- This role will be remote based anywhere in the US.
- The compensation from this range will be between $160,000 - 180,000.
- The base compensation will be based on experience and there will be an opportunity for an incentive based bonus.
PHYSICAL DEMANDS and WORK ENVIRONMENT
The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
While performing the duties of this job, the employee is regularly required to sit and use hands to handle, touch or feel objects, tools, or controls. The employee frequently is required to talk and hear. The noise level in the work environment is usually moderate. The employee is occasionally required to stand; walk; reach with hands and arms. The employee is rarely required to stoop, kneel, crouch, or crawl. The employee must regularly lift and/or move up to 10 pounds. Specific vision abilities required by this job include close vision, color vision, and the ability to adjust focus.
EEOC
Bayview Asset Management is an Equal Employment Opportunity employer. All aspects of consideration for employment and employment with the Company are governed on the basis of merit, competence and qualifications without regard to race, color, religion, sex, national origin, age, disability, veteran status, sexual orientation, or any other category protected by federal, state, or local law.