Privacy & Data Security Engineer
- Location
- London Area, United Kingdom
- Working arrangement
- Hybrid
- Salary
- Salary not stated
- Employment type
- Contract
- Experience level
- Mid level
- Posted
Robert Half Technology are assisting a market-leading threat intelligence organisation to recruit a Privacy & Data Security Engineer on a 2-year temporary contract basis . Hybrid working – London, 2–3 days per week.
Role
- The Privacy & Data Security Engineer will lead the technical implementation of the organisation's global privacy and data security strategy, embedding Privacy by Design principles across data processing environments and customer-facing systems.
- Design and implement a comprehensive Data Ring-Fencing control framework , ensuring sensitive data is appropriately partitioned, protected and governed.
- Define and enforce logical and physical separation controls for high-sensitivity data, including PII, PCI and intellectual property .
- Establish secure data-sharing mechanisms, including Data Clean Rooms and controlled data pathways, enabling analysis while minimising privacy and exposure risks.
- Work closely with Engineering, DevOps, Cloud and Data teams to implement micro-segmentation, IAM and granular access controls across technical environments.
- Embed automated privacy and security controls into system architecture, CI/CD pipelines and data processing workflows .
- Implement and manage privacy-preserving technologies including tokenisation, hashing, salting, de-identification and differential privacy .
- Develop technical controls and safeguards to support compliance with GDPR, CCPA/CPRA and emerging data residency and data sovereignty requirements .
- Establish appropriate monitoring, control testing and evidence mechanisms to demonstrate ongoing adherence to privacy and security requirements.
- Develop enforcement blueprints, audit templates, evidence logs and control documentation to support internal audits and external certifications, including SOC 2 and ISO 27001 .
- Maintain a Control Rationale framework, documenting how technical configurations and security controls map to applicable privacy and regulatory requirements.
- Work closely with Legal, Privacy, Product, Engineering and Security stakeholders to translate regulatory and privacy requirements into practical technical controls.
- Support the governance and management of exceptions to ring-fencing and data protection controls.
- Develop and deliver role-specific guidance and training for developers, data scientists and other technical teams on secure data handling and privacy protocols.
- Keep abreast of developments in privacy engineering, data security, cloud security, threat intelligence and data sovereignty , continuously improving the organisation's control environment.
Profile
- The Privacy & Data Security Engineer will have 3+ years' experience in Privacy Engineering, Data Security, Cloud Infrastructure Security or a closely related discipline.
- Strong understanding of privacy-by-design principles and the technical implementation of data protection controls.
- Good knowledge of GDPR, CCPA/CPRA, data residency and data sovereignty , with the ability to translate regulatory requirements into technical solutions.
- Experience with IAM, micro-segmentation, Zero Trust Architecture (ZTA) and Data Loss Prevention (DLP) technologies.
- Practical experience with privacy-preserving technologies such as tokenisation, hashing, salting, de-identification and differential privacy .
- Experience working with AWS, Azure and/or GCP , including native identity, access control and network segmentation capabilities.
- Familiarity with modern data platforms and orchestration technologies such as Snowflake, Databricks and Airflow .
- Experience working within cybersecurity, threat intelligence or security-focused environments would be highly advantageous.
- Understanding of Data Clean Rooms and secure data-sharing architectures would be beneficial.
- Experience producing technical control documentation, audit evidence and compliance artefacts for frameworks such as ISO 27001 and SOC 2 .
- Relevant qualifications such as CIPT, CIPM, CISSP or CISM would be advantageous.
- Excellent written and verbal communication skills, with the ability to explain complex privacy and security concepts clearly to Legal, Privacy, Product, Engineering and Security stakeholders .
- Strong analytical and problem-solving skills, with excellent attention to detail and the ability to operate effectively across technical and governance functions.
Company
- Market-leading threat intelligence organisation with offices in London
- 2-year temporary contract
- Hybrid working – London, 2–3 days per week
- Opportunity to work within a highly security-focused environment at the intersection of privacy engineering, data security and threat intelligence