Senior Data Security Engineer
HF Sinclair
- Location
- Dallas, TX, US, 75219
- Work model
- On-Site
- Level
- Senior
Skills
About this role
Basic Function
HF Sinclair is seeking a Senior Data Security Engineer in Dallas, Texas. Serves as the technical authority responsible for defining and operationalizing the enterprise data security execution model. This role is accountable for translating data security intent (governance, privacy, policy) into repeatable, enforceable, and observable controls across production environments, with particular focus on application, API, analytics & automation, and AI‑driven data access paths. As the first dedicated data security engineering role, this position provides hands‑on technical leadership while simultaneously shaping architecture standards, maturity targets, and implementation sequencing. The role partners closely with Cybersecurity Architecture, Cloud Engineering, Data & Analytics, and Application teams to ensure data security capabilities are designed for execution speed, not theoretical completeness. This role intentionally prioritizes reducing current exposure before enabling advanced use cases. Secure analytics and AI are treated as outcomes of maturity, not parallel initiatives. Job Duties
Data Security Execution (Primary)
Define and maintain data security reference architectures and control patterns focused on:
Application‑mediated data access API exposure and service‑to‑service data flows Automation, orchestration, and machine‑driven access, AI/ML workloads, etc.
Define and monitor data security capability maturity across structured, unstructured, and application‑centric domains, aligned to the enterprise cybersecurity taxonomy. Translate architectural intent into implementable standards and technical design criteria that engineering teams can execute without ambiguity. Define & maintain enterprise data classification, labeling & protection standards across structured & unstructured data. Participate in architecture reviews & modernization initiatives to ensure secure data handling requirements are incorporated into application, cloud, analytics, integrations, & automation solutions
Data Exposure Reduction & Control Engineering
Lead technical efforts to identify and reduce existing data exposure, with emphasis on:
Access path patterns and permissions across SaaS, cloud service, third-party integrations, and business applications Application and API data flow monitoring Data protection capabilities supporting classification, monitoring, access governance, & data loss prevention requirements
Design and implement controls that operate at execution points, including:
Data access monitoring tied to application context Enforcement patterns beyond static DLP or perimeter controls
Secure Enablement of Analytics and AI
Serve as the technical advisor for securing data used in analytics, automation, and AI initiatives. Collaborate with peer IT and business teams to embed security controls into data pipelines, feature stores, and model interaction layers. Explicitly sequence AI‑related security work to avoid increasing risk through premature enablement.
Selective Cloud Security Engineering Support (Secondary)
Provide targeted cloud security engineering support where it directly impacts data exposure, including cloud storage, data platforms, SaaS, and identity‑driven data access patterns. Collaborate with technical peers on generalized cloud posture management, particularly where it directly reduces data risk.
Operationalization & Incident Readiness
Define data‑centric detection and response patterns to improve monitoring. Partner with SOC and Engineering teams to ensure response workflows are realistic, tested, and actionable.
Role Relationships & Boundaries
Cybersecurity Architect: Peer relationship. Joint ownership of architecture coherence; this role owns data security execution detail, while the Architect owns enterprise‑wide alignment. Data Governance & Privacy: Consumers of intent and constraints; this role owns how those constraints are