Engineer/Sr Engineer, IT Cybersecurity Data Protection

NEW

American Airlines · Fort Worth, TX, United States

Aircraft Maintenance & MRO
Base
Fort Worth, TX, United States
Field
Aircraft Maintenance & MRO
Posted
Closes

Intro

Are you ready to explore a world of possibilities, both at work and during your time off? Join our American Airlines family, and you’ll travel the world, grow your expertise, and become the best version of you. As you embark on a new journey, you’ll tackle challenges with flexibility and grace, learning new skills and advancing your career while having the time of your life. Feel free to enrich both your personal and work life and hop onboard!

Why you'll love this job

As one diverse, high‑performing team committed to technical excellence, you’ll help shape the modern cybersecurity capabilities that drive a more reliable, safe, and profitable airline. The Platform Security product group delivers comprehensive solutions, processes, and platforms that embed and monitor security across Cloud, Application, Endpoint / End User, Data, and AI domains. In this portfolio, you’ll help strengthen the safeguards that protect our systems, data, and people through consistent, scalable practices and deliver solutions that secure one of the world’s most complex global operations.

The Engineer/Sr. Engineer - Data Protection plays a key role in delivering, engineering, and enhancing American Airlines’ data protection and privacy technology capabilities. In this role, you’ll design, build, and support core components of our data protection ecosystem including data security engineering and protection, privacy engineering and assurance, data discovery and classification, retention/ROT data minimization, and access governance. You’ll work closely with Cybersecurity, Privacy Office, Enterprise Data, Legal, and product and platform teams to implement scalable, modern controls that safeguard American Airlines’ critical information assets and enable secure, innovative business solutions. As a hands-on engineer, you will solve complex data protection challenges, automate controls, and contribute to the continuous improvement of our enterprise privacy and data protection program.

What you'll do

As noted above, this list is intended to reflect the current job but there may be additional essential functions (and certainly non-essential job functions) that are not referenced. Management will modify the job or require other tasks be performed whenever it is deemed appropriate to do so, observing, of course, any legal obligations including any collective bargaining obligations.

  • Operationalize automated data discovery, classification, and inventory; apply sensitivity labels and consistent taxonomy across data stores, pipelines, and collaboration systems.
  • Engineer DSPM capabilities with tools (e.g., Securiti, BigID) to surface data posture risks (overexposure, shadow data, stale sensitive data) and drive remediation workflows.
  • Implement and support encryption, tokenization, masking, anonymization/pseudonymization for data at rest and in transit; integrate with cloud key management systems and enforce approved cryptographic standards; define crypto baselines and policy-as-code guardrails.
  • Configure and govern access controls with RBAC/ABAC and purpose-based authorization; perform least-privilege and fine-grained access reviews across data platforms.
  • Deploy, tune, and operate DLP and DAM solutions (e.g., Microsoft Purview DLP, Imperva/Guardium); build detections for PII/PCI/PHI and reduce false positives with policy and context improvements.
  • Integrate and tune UEBA and Insider Risk signals to detect anomalous data access and exfiltration, partner on response workflows and preventive control changes.
  • Integrate data protection telemetry with SIEM/SOAR; build detections, correlation rules, and automated response playbooks for data-related threats and policy violations.

What you'll do (Continued.......)

  • Implement data minimization and retention/ROT enforcement patterns; automate monitoring of lifecycle actions (archive, delete, redact) aligned to policy and legal holds.
  • Implement DSAR (data subject access request) orchestration and fulfillment with SLA monitoring; automate data collection, redaction, and secure delivery with audit trails.
  • Contribute to cookie/tag governance and catalog assurance; validate consent signals, storage durations, and vendor script behavior against policy.
  • Support privacy platform capabilities and integrate with identity, ticketing, data catalogs/lineage, and evidence repositories.
  • Embed data protection and privacy-by-design controls into services and CI/CD (pre-commit/CI privacy code scanning, secret scanning, schema checks for sensitive fields, data egress policies).
  • Produce compliance evidence and reports for GDPR/CCPA/CPRA, PCI DSS, HIPAA, and internal audits; maintain controls health dashboards, regulatory tracking, and program KPIs.
  • Investigate data-related incidents and privacy events in partnership with IR/SOC/Privacy Office. Collect artifacts, support forensics, document findings, and drive preventive engineering fixes.
  • Conduct platform hardening and vulnerability remediation for data control tooling (misconfigurations, exposed buckets, weak crypto, excessive permissions).
  • Participate in red teaming/tabletop exercises for data scenarios (insider misuse, public link exposures, unintended AI training data); translate findings into control improvements.
  • Partner with Cybersecurity, Privacy Office, Enterprise Data, Legal, and product/platform teams to align designs and deliver privacy- and data protection-by-design outcomes.
  • Document engineering patterns, runbooks, and reference architectures; create training and technical guidance that strengthen secure data handling practices across teams.
  • Communicate clearly and concisely with technical and non‑technical audiences - summarize incidents, risks, and recommended actions with accurate, complete context.

Minimum Qualifications- Education & Prior Job Experience

  • Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, Engineering, or a related field (or equivalent practical experience)
  • 3+ years of progressive experience in data protection, privacy engineering, security engineering, or platform engineering roles.
  • Hands‑on experience implementing and operating data protection capabilities such as encryption at rest and in transit, cloud key management, data classification, DLP, DAM, or DSPM platforms.
  • Strong understanding of identity and access control patterns (RBAC/ABAC, least‑privilege access, access reviews) and secure data handling practices including classification, labeling, and retention/ROT.
  • Experience using scripting or automation (e.g., Python, PowerShell) and working with APIs, logs, and CI/CD pipelines to integrate, operate, or enhance security controls.
  • Ability to analyze security signals and alerts, follow and improve runbooks, document findings clearly, and collaborate with cross‑functional teams to implement remediation and continuous improvements.

Preferred Qualifications- Education & Prior Job Experience

  • Master’s degree in Computer Science, Cybersecurity, Engineering, Information Assurance, or a related technical field.
  • Experience with Microsoft Purview (Information Protection & DLP), Securiti.ai, BigID, OneTrust, and DAM (Imperva/Guardium).
  • Exposure to Azure, AWS, or GCP security services and cloud data platforms (e.g., storage, databases, messaging/streaming).
  • Experience with Git/GitHub, GitHub Actions/Azure DevOps, secrets scanning, and code scanning tools.
  • Familiarity with SQL, regex, and data transformation basics (e.g., dbt, Spark, ETL) for building detections and data handling checks.
  • Experience integrating consent/preference and DSAR orchestration with identity, data catalogs/lineage, and evidence repositories.
  • Proven ability to design KPI/telemetry models and build dashboards that demonstrate control effectiveness and maturity uplift.

Skills, Licenses & Certifications

  • Programming / Scripting: Python, PowerShell (nice to have: Bash); strong facility with REST/JSON, YAML, and regex; specific to Privacy Portal - Java, Springboot, Angular/React.
  • Data / Querying: SQL (and exposure to data pipelines—dbt/Spark/ETL concepts helpful).
  • CI/CD & DevOps: Git/GitHub, GitHub Actions or Azure DevOps; artifact/versioning; secret scanning; pre-commit hooks; policy checks in pipelines.
  • Infrastructure / Policy as Code: Terraform or Bicep; OPA/Rego or equivalent for policy-as-code preferred.
  • Cloud & Crypto: Azure/AWS/GCP basics; Azure Key Vault, AWS KMS, GCP KMS; TLS/mTLS; tokenization; HSM/PQC fundamentals.
  • Identity & Access: Microsoft Entra ID (Azure AD), Okta; RBAC/ABAC; JIT/PAM concepts; purpose-based authorization patterns.
  • Data Protection Platforms: Microsoft Purview (Information Protection & DLP), Securiti.ai, BigID, OneTrust (consent/DSAR), Imperva or IBM Guardium (DAM).
  • Monitoring & Response: SIEM (Microsoft Sentinel, Splunk), SOAR (Logic Apps, Splunk SOAR), ITSM/ticketing (ServiceNow/Jira); building detections and playbooks.
  • Insider Risk / UEBA & Collaboration: Microsoft Insider Risk, M365 collaboration safeguards (external sharing governance, link expiration, watermarking).
  • Web/App Privacy: CMP/consent signals, cookie/tag governance, data egress controls, redaction/watermarking where applicable.
  • Clear, well-structured documentation of engineering patterns, runbooks, and technical decisions.
  • Strong analytical and problem-solving skills with the ability to translate requirements into maintainable controls, automations, and repeatable engineering patterns.
  • Privacy and security certifications such as CIPT, CDPSE, CIPP/US, CIPP/E, Security+, CCSP, or CISSP (CISSP relevant for Sr. Engineer).
  • Cloud certifications for Azure, AWS, or GCP at the associate or professional level.
  • Data or engineering-oriented certifications such as Azure Data Engineer, Databricks, or equivalent preferred but not necessary.
  • Ability to work independently with a high degree of initiative.

What you'll get

Feel free to take advantage of all that American Airlines has to offer:

  • Travel Perks: Ready to explore the world? You, your family, and your friends can reach 365 destinations on more than 6,800 daily flights across our global network.
  • Health Benefits: On day one, you’ll have access to your health, dental, prescription and vision benefits to help you stay well. And that’s just the start, we also offer virtual doctor visits, flexible spending accounts and more.
  • Wellness Programs: We want you to be the best version of yourself – that’s why our wellness programs provide you with all the right tools, resources and support you need.
  • 401(k) Program: Available upon hire and, depending on the workgroup, employer contributions to your 401(k) program are available after one year.
  • Additional Benefits: Other great benefits include our Employee Assistance Program, pet insurance and discounts on hotels, cars, cruises and more.

Feel free to be yourself at American

From the team members we hire to the customers we serve, inclusion and diversity are the foundation of the dynamic workforce at American Airlines. Our 20+ Employee Business Resource Groups are focused on connecting our team members to our customers, suppliers, communities, and shareholders, helping team members reach their full potential and creating an inclusive work environment to meet and exceed the needs of our diverse world.

Are you ready to feel a tremendous sense of pride and satisfaction as you do your part to keep the largest airline in the world running smoothly as we care for people on life’s journey? Feel free to be yourself at American.

From jobs.aa.com · seen 1 hour ago