Point your AI agent at freehire and let it find you a job.

Get the CLI →

The Hanover Insurance Group

NewBe an early applicant

Senior IT Security Engineer (REMOTE)

Posted Updated
Discussion

We are seeking a highly skilled Senior Security Engineer to join our IT Security organization in Worcester, MA or in a remote work capacity.
POSITION SUMMARY:
You bring deep expertise in data protection, information governance, compliance technologies, and enterprise security architecture. This individual will serve as a technical leader responsible for administering, maintaining, enhancing, and strategically expanding the organization's Data Protection Program across cloud, SaaS, endpoint, collaboration, and enterprise data platforms.

The ideal candidate possesses hands-on experience implementing and operating enterprise-class Data Security Posture Management (DSPM), Data Loss Prevention (DLP), Information Protection, Records Management, eDiscovery, Insider Risk, and Data Governance solutions. Experience with platforms such as Microsoft Purview and other similar security control tools.

This role requires an individual who can operate at both the technical and strategic levels, partnering with Security, Legal, Compliance, Privacy, IT, Data Governance, and business stakeholders to mature and scale enterprise data protection capabilities.

This is a full-time, exempt position.
IN THIS ROLE, YOU WILL:
Data Protection Program Leadership

Lead the ongoing administration, enhancement, and growth of the enterprise Data Protection Program.
Develop and execute data protection roadmaps aligned with business, regulatory, and security objectives.
Identify opportunities to improve data protection maturity and reduce organizational risk.
Establish metrics and reporting that demonstrate program effectiveness.
Partner with leadership to define long-term data governance and protection strategies.

Information Protection & Data Governance

Design and maintain enterprise data classification frameworks.
Develop and govern data handling standards and protection requirements.
Implement and manage sensitivity labeling, encryption, and information protection controls.
Collaborate with Data Governance teams to establish classification taxonomies and data ownership models.
Develop automated classification and data discovery capabilities across structured and unstructured repositories.

Data Loss Prevention (DLP)

Design, implement, and manage enterprise DLP strategies.
Develop policies protecting sensitive information across email, collaboration platforms, endpoints, cloud applications, and remote work environments.
Analyze incidents and adjust policies to improve effectiveness while minimizing business disruption.
Establish operational processes for data loss investigations and response activities.

Insider Risk & Investigations

Implement and maintain insider risk monitoring capabilities.
Develop use cases and detection strategies for data misuse, theft, fraud, and policy violations.
Support internal investigations involving sensitive data and policy violations.
Partner with HR, Legal, and Compliance teams during investigations.

eDiscovery, Retention & Records Management

Support legal hold, eDiscovery, and regulatory response processes.
Develop data retention and disposition strategies.
Manage records management controls supporting compliance requirements.
Ensure defensible preservation and collection processes are established.

Compliance & Regulatory Support

Support security, privacy, and regulatory audits.
Map compliance requirements to implemented technical controls.
Assist with risk assessments and remediation planning.
Partner with Compliance and Legal teams to demonstrate regulatory adherence.

Platform Engineering & Integration

Design and maintain enterprise data protection architectures.
Integrate data security tools with SIEM, case management, and operational platforms.
Onboard cloud, SaaS, endpoint, and on-premises data sources.
Develop automation and operational efficiencies using scripting and APIs.
Manage tool upgrades, enhancements, health monitoring, and operational support.

WHAT YOU NEED TO APPLY:

7+ years of information security experience.
5+ years of hands-on experience supporting enterprise data protection initiatives.
Experience administering one or more enterprise data protection, governance, or compliance platforms.
Experience implementing DLP, information protection, data classification, and compliance solutions.
Experience working with Legal, Compliance, Privacy, and Audit functions.
Experience leading enterprise-scale security initiatives and projects.
Authorization to work in the United States without current or future sponsorship (U.S. citizen or lawful permanent resident).

Technical Skills
Strong experience in several of the following areas:

Data Protection Programs
Data Governance
Data Classification
Information Protection
Sensitivity Labels
Encryption Technologies
Data Loss Prevention (DLP)
Insider Risk Management
Communication Compliance
Records Management
Data Lifecycle Management
eDiscovery
Data Security Posture Management (DSPM)
Cloud Security
Identity and Access Management (IAM)
Role-Based Access Control (RBAC)
Microsoft 365 Security
Endpoint Security
Enterprise Security Architecture
Security Monitoring and SIEM Integration
Security Automation and Scripting

Compliance Frameworks (NIST, ISO 27001, CIS, PCI-DSS, HIPAA, GDPR, SOX)

Skills

What Senior Security jobs ask for — and how much of it you have →
Apply

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available