Conversation, Person, Adult, Male, Man, Head, Computer Keyboard, Face, Coat, Monitor

Principal Data Security Architect

 

Notice: Equinix is aware of scams involving fake employment offers. Read more. 

Principal Data Security Architect

  • JR-160751
  • Hybrid
  • Toronto
  • Dallas
  • Technology
  • Full time
View favorites

Who are we?

Equinix is the world’s digital infrastructure company®, shortening the path to connectivity to enable the innovations that enrich our work, life and planet. 

A place where tech thinkers and future builders turn bold ideas into breakthrough experiences, we welcome your unique perspective.

Help us challenge assumptions, uncover bias, and remove barriers—because progress starts with fresh ideas. You’ll find belonging, purpose, and a team that welcomes you—because when you feel valued, you’re empowered to do your best work.

Job Profile Summary

The Digital Information Security Engineering team is seeking a Principal Data Security Architect to define, design, and influence the enterprise's most complex data protection capabilities across SaaS, web, endpoint, and cloud environments. This is an individual-contributor role for data-centric security — a hands-on technical leader who sets architectural direction, builds reference implementations, and solves the hardest data protection problems at enterprise scale.

The ideal candidate will focus on protecting sensitive data throughout its lifecycle, enabling privacy-by-design architecture, the end-to-end technical design for CASB, DSPM, eDLP, advanced content detection (EDM/IDM), secure file sharing, and translate those capabilities into durable, measurable risk reduction. Beyond engineering, the role shapes enterprise data governance strategy and partners closely with the Data Protection Product Manager to set roadmap and priorities.

Main Responsibilities

Data Security Architecture & Technical Leadership

  • Own the enterprise reference architecture for data-centric security across SaaS, web, endpoint, and cloud.
  • Define the architecture patterns, design standards, and guardrails that engineering teams build against.
  • Lead design for the most complex, novel, or high-risk problems — articulating options, trade-offs (security vs. usability vs. cost vs. operability), and a clear recommendation.
  • Serve as the top technical authority and design-review escalation point for the data protection function.
  • Provide hands-on mentorship and technical direction to senior engineers without formal reporting authority.
  • Prove out emerging technologies through hands-on POCs and pilots before enterprise adoption.

DSPM (Data Security Posture Management)

  • Architect enterprise-wide continuous discovery and classification of sensitive data across SaaS applications, cloud storage and object stores, and unstructured repositories.
  • Design the posture-analysis model for overshared or publicly exposed data, sensitive data sprawl, and misconfigured access controls.
  • Establish risk-based, automated remediation workflows in partnership with data owners and application teams.
  • Define continuous monitoring of data exposure and compliance posture at scale.

Advanced Data Detection & Protection

  • Design the enterprise eDLP architecture to inspect and control data in motion across web and cloud channels.
  • Own advanced detection strategy, including Exact Data Match (EDM) for structured sensitive data (PII, PCI, financial datasets) and Indexed Document Matching (IDM) for unstructured documents and intellectual-property protection.
  • Establish the engineering lifecycle for EDM data sets and IDM fingerprinting repositories — covering scale, freshness, and integrity.
  • Define real-time enforcement models (block, quarantine, alert, coach) balanced against business disruption.
  • Set the detection-tuning standards that systematically drive down false positives and false negatives.

Secure File Sharing & Data Movement Controls

  • Architect secure data-transfer controls across web uploads/downloads, SaaS file sharing and collaboration tools, and third-party/external data exchanges.
  • Design safeguards against unauthorized data exfiltration, risky upload behavior, and unapproved sharing channels.
  • Ensure controls enable legitimate business collaboration while maintaining strong data protection.

CASB & SaaS Security

  • Design inline and API-based CASB architecture to secure enterprise SaaS platforms (e.g., collaboration suites, CRM, productivity clouds).
  • Define granular access and session controls: inline transaction control (upload/download restrictions), session enforcement (block, coach, isolate, redact), and adaptive policy based on user, device, and risk context.
  • Establish detection and mitigation strategy for Shadow IT, OAuth app abuse, and SaaS misconfiguration or oversharing.
  • Align CASB architecture with Zero Trust principles and least-privilege access models.

Enterprise Data Governance Strategy

  • Shape enterprise data governance strategy, connecting data classification, ownership, handling standards, and control enforcement into a coherent model.
  • Translate regulatory and framework obligations (e.g., NIST, PCI DSS, privacy regimes) into enforceable technical controls and data-handling standards.
  • Partner with legal, privacy, compliance, and data-owner communities to align governance policy with technical reality.
  • Define the data classification taxonomy and control mappings that downstream tooling enforces.

Roadmap & Product Partnership

  • Partner with the Data Protection Product Manager to set the multi-quarter roadmap and prioritize investment.
  • Provide technical, feasibility, sequencing, and level-of-effort assessments that inform prioritization decisions.
  • Translate business and risk drivers into an actionable, engineering-grounded capability roadmap.
  • Represent the technical point of view in trade-off and prioritization discussions.

Security Monitoring, Metrics & Risk Reduction

  • Define the data protection metrics model: sensitive data exposure trends, policy enforcement effectiveness, and data exfiltration attempts.
  • Establish standards for reviewing and tuning DLP and CASB alerts, focused on exfiltration and misuse.
  • Drive data risk assessments and continuous control validation.
  • Ensure policies maintain high efficacy with low business disruption.

Qualifications

  • Bachelor's or Master's degree in Computer Science, Information Security, or a related field — or equivalent demonstrated experience.
  • 10–15+ years in data protection or security engineering, including significant time operating at a senior, staff, or principal level.

Required Expertise

  • Deep, hands-on architecture and engineering experience across CASB (inline and API modes), DSPM, eDLP, Exact Data Match (EDM), and Indexed Document Matching (IDM).
  • Proven ability to design and operate data protection controls at enterprise scale.
  • Strong command of data classification and content inspection, data exfiltration vectors and prevention techniques, and SaaS/cloud data security risks.
  • Expertise implementing Zero Trust data protection strategies.
  • Demonstrated ability to make and defend architectural trade-offs across security, usability, cost, and operability.

Technical Skills

  • Strong programming/scripting skills (Python preferred) applied to real automation and integration work.
  • Hands-on experience with REST APIs and security integrations, SIEM/SOAR platforms, and cloud environments (AWS, Azure, GCP).
  • Strong understanding of identity, access control, and conditional access models.

Proven, Demonstrated Experience (Required)

This role requires evidence of real, production-grade work — not theoretical familiarity or vendor exposure alone. Candidates should be prepared to walk through, in concrete technical detail:

  • Specific enterprise data protection solutions they personally architected and implemented — not merely oversaw or advised on.
  • The concrete business and security problem being solved, the real-world constraints, and why the chosen approach won over the alternatives considered.
  • How they built, scaled, and maintained EDM/IDM detection in production and measurably improved accuracy over time.
  • How their designs reduced actual risk, supported by metrics and outcomes.
  • Missteps or failed approaches and what they changed as a result.

The Successful Candidate Will

  • Be deeply hands-on — an architect who still builds, not only advises.
  • Take a data-first approach to security, focused on measurable risk reduction.
  • Demonstrate elite analytical and tuning expertise, especially with EDM/IDM.
  • Influence and elevate senior engineers and cross-functional partners without formal authority.
  • Be proactive, curious, and relentless about improving data protection coverage and accuracy.
  • Thrive in a fast-paced, diverse, and constantly evolving environment.

The targeted pay range for this position in the following location is / locations are:

Canada - Toronto Office TRO : 131,000 - 181,000 CAD / Annual

United States - Dallas Infomart Office DAI : 155,000 - 233,000 USD / Annual

Our pay ranges reflect the minimum and maximum target for new hire pay for the full-time position determined by role, level, and location.The pay range shown is based on our compensation structure in place at the time of posting and may be updated periodically based on business needs. Individual pay is based on additional factors including job-related skills, experience, and relevant education and/or training.

The targeted pay range listed reflects the base pay only and does not include bonus, equity, or benefits. Employees are eligible for bonus, and equity may be offered depending on the position.

Equinix Benefits

As an employee, you become important to Equinix’s success. We ensure all your benefits are in line with our core values: competitive, inclusive, sustainable, connected and efficient. We keep them competitive within the current marketplace to ensure we’re providing you with the best package possible. So, wherever you are in your career and life, you’ll be able to enhance your experience and bring your whole self to work.

Employee Assistance Program: An Employee Assistance program is available to all employees.

US Benefits: - Insurance: You may enroll in health, life, disability and voluntary plans that are designed for you and your eligible family members. - Retirement: You and Equinix may contribute to a retirement plan to help you plan for your financial future. - Paid Time Off (PTO) and Paid Holidays: You will receive an accrued amount of PTO each pay period along with various paid holidays for you to rest and recharge. Eligibility requirements apply to some benefits. Benefits are subject to change and may be subject to specific plan or program terms. Canada Core Benefits: - Insurance: You may enroll in healthcare coverage that is designed to complement the provincial healthcare system, along with life, disability and optional benefit plans that are designed for you and your eligible family members. - Retirement: You may also enroll in Equinix-sponsored retirement or savings plans: Defined Contribution Pension Plan (DCPP), Group Retirement Savings Plan (RRSP) and Tax-Free Savings Plan (TSFA). - Vacation and Paid Holidays: Equinix offers both vacation and personal time, along with various paid holidays for you to rest and recharge. Eligibility requirements apply to some benefits. Benefits are subject to specific plan or program terms, and to change at Equinix discretion.

Equinix is committed to ensuring that our employment process is open to all individuals, including those with a disability.  If you are a qualified candidate and need assistance or an accommodation, please let us know by completing this form.

Equinix is an Equal Employment Opportunity and, in the U.S., an Affirmative Action employer.  All qualified applicants will receive consideration for employment without regard to unlawful consideration of race, color, religion, creed, national or ethnic origin, ancestry, place of birth, citizenship, sex, pregnancy / childbirth or related medical conditions, sexual orientation, gender identity or expression, marital or domestic partnership status, age, veteran or military status, physical or mental disability, medical condition, genetic information, political / organizational affiliation, status as a victim or family member of a victim of crime or abuse, or any other status protected by applicable law. 

We use artificial intelligence in our hiring process. Learn more here.

This posting is a new position within our organization.