Title: Senior Data Security Engineer
Dallas, TX, US, 75219
Basic Function
HF Sinclair is seeking a Senior Data Security Engineer in Dallas, Texas. Serves as the technical authority responsible for defining and operationalizing the enterprise data security execution model. This role is accountable for translating data security intent (governance, privacy, policy) into repeatable, enforceable, and observable controls across production environments, with particular focus on application, API, analytics & automation, and AI‑driven data access paths.
As the first dedicated data security engineering role, this position provides hands‑on technical leadership while simultaneously shaping architecture standards, maturity targets, and implementation sequencing. The role partners closely with Cybersecurity Architecture, Cloud Engineering, Data & Analytics, and Application teams to ensure data security capabilities are designed for execution speed, not theoretical completeness.
This role intentionally prioritizes reducing current exposure before enabling advanced use cases. Secure analytics and AI are treated as outcomes of maturity, not parallel initiatives.
Job Duties
Data Security Execution (Primary)
- Define and maintain data security reference architectures and control patterns focused on:
- Application‑mediated data access
- API exposure and service‑to‑service data flows
- Automation, orchestration, and machine‑driven access, AI/ML workloads, etc.
- Define and monitor data security capability maturity across structured, unstructured, and application‑centric domains, aligned to the enterprise cybersecurity taxonomy.
- Translate architectural intent into implementable standards and technical design criteria that engineering teams can execute without ambiguity.
- Define & maintain enterprise data classification, labeling & protection standards across structured & unstructured data.
- Participate in architecture reviews & modernization initiatives to ensure secure data handling requirements are incorporated into application, cloud, analytics, integrations, & automation solutions
Data Exposure Reduction & Control Engineering
- Lead technical efforts to identify and reduce existing data exposure, with emphasis on:
- Access path patterns and permissions across SaaS, cloud service, third-party integrations, and business applications
- Application and API data flow monitoring
- Data protection capabilities supporting classification, monitoring, access governance, & data loss prevention requirements
- Design and implement controls that operate at execution points, including:
- Data access monitoring tied to application context
- Enforcement patterns beyond static DLP or perimeter controls
Secure Enablement of Analytics and AI
- Serve as the technical advisor for securing data used in analytics, automation, and AI initiatives.
- Collaborate with peer IT and business teams to embed security controls into data pipelines, feature stores, and model interaction layers.
- Explicitly sequence AI‑related security work to avoid increasing risk through premature enablement.
Selective Cloud Security Engineering Support (Secondary)
- Provide targeted cloud security engineering support where it directly impacts data exposure, including cloud storage, data platforms, SaaS, and identity‑driven data access patterns.
- Collaborate with technical peers on generalized cloud posture management, particularly where it directly reduces data risk.
Operationalization & Incident Readiness
- Define data‑centric detection and response patterns to improve monitoring.
- Partner with SOC and Engineering teams to ensure response workflows are realistic, tested, and actionable.
Role Relationships & Boundaries
- Cybersecurity Architect: Peer relationship. Joint ownership of architecture coherence; this role owns data security execution detail, while the Architect owns enterprise‑wide alignment.
- Data Governance & Privacy: Consumers of intent and constraints; this role owns how those constraints are enforced in production.
- Cloud & Application Engineering: Execution partners; this role defines what “secure” means in practice and helps teams implement it.
Special assignments or tasks assigned to the employee by their supervisor, as determined from time to time in their sole and complete discretion.
Experience
A minimum of 8 years in cybersecurity or security engineering, with deep hands‑on experience in data security or application security is required.
Education Level
A minimum bachelor’s degree in information technology, Cybersecurity, Computer Science, or a related field is required.
Required Skills
Experience:
A minimum of 8 years in cybersecurity or security engineering, with deep hands‑on experience in data security or application security is required.
Education Level:
A minimum bachelor’s degree in information technology, Cybersecurity, Computer Science, or a related field is required.
Required Skills:
- Proven ability to design and operationalize security controls, not just select tools
- Proven ability to implement optimal security controls for AI-driven data access paths and automation systems that balance risk reduction vs innovation enablement
- Proven ability to secure data hosted on-premises, in the Cloud and in SaaS environment
- Strong understanding of:
- Application and API security
- Identity‑based access models
- Data access monitoring and enforcement
- Ability to operate comfortably in ambiguous environments and establish clarity through execution
- Demonstrates ability to collaborate across cross-functional teams and business units to deliver solutions
- Builds strong working relationships and fosters open communication and mutual accountability
- Facilitates alignment between business, IT, and external partners through consultative engagement
- Actively contributes to team discussions, decision-making, and problem-solving activities
- Ability to influence stakeholders across business and IT to gain agreement on ideas, strategies, and initiatives
Preferred Skills:
- Experience designing security for data platforms, analytics, or AI‑adjacent systems
- Background in cloud‑native application architectures
- Experience with Snowflake, Azure, Purview, MS SQL and endpoint security
- Prior experience acting as a first‑of‑kind or foundational security role
Supervisory/Managerial Responsibility
Work Conditions
Office based with travel up to 40% by land or air is required. Driver based environment. Subject to all weather and varying road conditions.
Benefits
- Medical Insurance
- Vision Insurance
- Dental Insurance
- Paid Time-Off
- 401(k) Retirement Plan with match
- Educational Reimbursement
- Parental Bonding Time
- Employee Discounts
We are committed to fostering a supportive and inclusive work environment, ensuring our employees have the resources needed to thrive professionally and personally. Benefit eligibility is governed by official plan documents, for more details visit Total Rewards.
Our One HF Sinclair Culture:
About HF Sinclair Corporation
Equal Opportunity Employer
HF Sinclair Corporation is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status or any other prohibited ground of discrimination.
Nearest Major Market: Dallas
Nearest Secondary Market: Fort Worth