The Senior Security Engineer will be responsible for designing and implementing the Database Activity Monitoring (DAM) function to ensure the security, integrity, and compliance of enterprise data assets. This role will focus on operationalizing DAM solutions, integrating them with broader security architecture, and enabling visibility into database activities across the organization. The engineer will collaborate with IT teams, business units, vendors, and auditors to ensure effective monitoring, alerting, and response mechanisms are in place for database environments.
This role requires deep expertise in DAM technologies, database security controls, and regulatory compliance frameworks. The engineer will work closely with Security Architects to align DAM strategies with enterprise security architecture and risk management priorities.
Essential Functions
- Responsible for design, deployment, and management of Database Activity Monitoring (DAM) solutions across diverse database platforms (e.g., SQL Server, MySQL, PostgreSQL).
- Define and implement policies for monitoring, alerting, and auditing of database activities to detect unauthorized access, data exfiltration, and policy violations.
- Collaborate with Security Architects to integrate DAM into the broader security architecture and ensure alignment with enterprise risk management strategies.
- Develop and maintain cases, rules, and dashboards for DAM tools to support threat detection, compliance reporting, and forensic investigations.
- Partner with database administrators, application owners, and compliance teams to ensure DAM coverage and effectiveness across critical systems.
- Conduct technical risk assessments and security exposure analyses for database environments.
- Evaluate and recommend DAM technologies and vendors; lead proof-of-concept and implementation efforts.
- Automate DAM-related processes for alert triage, incident response, and reporting.
- Participate in security incident investigations involving database systems and contribute to root cause analysis and remediation planning.
- Provide technical assistance and mentorship to security analysts and engineers supporting DAM operations.
- Develop and maintain documentation, operational guidelines, and metrics for DAM program effectiveness.
- Support internal and external audits by providing evidence of DAM controls and activity logs.
- Participate in broader security initiatives including vulnerability management, encryption, identity management, and network security as needed.
Knowledge and Skills / Technology Used
Hands-on experience with DAM platforms such as IBM Guardium, Imperva SecureSphere, SecuPI, or native database auditing tools.Strong understanding of database architectures, access controls, and query languages (SQL).Familiarity with data classification, data loss prevention (DLP), and compliance frameworks (e.g., SOX, HIPAA, PCI-DSS, GDPR).Experience with SIEM integration, log management, and incident response workflows.Working knowledge of UNIX / Linux, Windows Server, and network protocols relevant to database communications.Experience with encryption technologies, identity and access management (IAM), and privileged access controls.Typical Education
Bachelor’s degree in computer science, Information Security, Information Technology, or related field, or equivalent work experience.Typical Range of Experience
Minimum 5 years of information security experience, with at least 1 year focused on database security or DAM.