- Location
- Brazil
- Workplace
- Remote
- Department
- Theta
- Seniority
- Manager
- Experience
- 30+ years
- Source
- Lever
Description
At CI&T, we help large enterprises transform the potential of AI into real business impact with AI Deployment, AI-native execution, and tech-integrated business solutions.
With 30 years of experience in technological transformation, we accelerate innovation with expertise in Agentic SDLC, Application modernization, Data & AI, Martech and Business strategy.
We are 8,000 CI&Ters across more than 25 countries, collaborating to build solutions with real impact. AI is already part of how we work, evolve, and innovate every day.
At CI&T, our rapid growth is fueled by the innovative solutions we create for our global clients. We are seeking a Security & Privacy Governance Lead to own sensitive-data classification, masking, and governance design for a large-scale Finance data platform modernization at a major US mortgage lender, working alongside the Principal Data Architect to turn the target architecture's governance requirements into implemented policy. This role leads the classification and masking design work during the program's design-validation phase, because that work gates everything the development team builds afterward.
This position combines hands-on policy implementation with cross-functional coordination: the professional designs classification, masking, and access-tiering rules directly in the platform, defines how standardized business metrics are governed across the data estate, and partners with client security and compliance stakeholders to secure sign-off before build begins.
Responsibilities
-
Lead sensitive-data classification across the source system's tables and dimension values, producing accurate, defensible classification output.
-
Design dynamic data masking policies and row-access policies on sensitive financial fields (general ledger and payroll-adjacent), scoped by role and business unit.
-
Define the raw-vs-curated access tiering and least-privilege access model across the data platform.
-
Design column-level lineage from source through landing, staging, conformed, and curated layers, the semantic model, and into consuming reports — auditable end to end.
-
Support master data management (MDM) efforts to ensure standardized, consistent definitions of key business metrics (such as billing and financial figures) across the platform.
-
Deliver governance artifacts platform-neutrally: policy objects/tags implemented directly in the platform, plus versioned, documented classification and lineage artifacts in client-controlled repositories.
-
Partner with client Security, Privacy, and Compliance teams to secure design approval ahead of build, and resolve open questions on network/identity boundary decisions that touch sensitive data.
-
Support downstream integration of classification and lineage artifacts into the client's own enterprise catalog/governance tooling, without building or operating that tooling directly.
Requirements or this challenge:
-
Solid experience in data security/privacy governance roles on enterprise data platforms, including hands-on policy implementation, not policy-writing alone.
-
Experience implementing data classification, dynamic masking, and row-access/row-level security on a modern cloud data warehouse (Snowflake preferred).
-
Experience designing or contributing to column-level lineage across multi-layer data pipelines.
-
Working knowledge of data privacy and access-governance practice in a regulated industry (financial services, healthcare, or similar).
-
Comfortable leading the classification and masking design during a design-validation phase, where your output directly gates the rest of the build.
-
Fluent English (C1) — direct engagement with client Security, Privacy, and Compliance stakeholders and gate reviews.
Nice to Have
-
Experience with Microsoft Fabric/OneLake governance boundaries alongside Snowflake.
-
Experience in mortgage, lending, or financial-services data governance.
-
Familiarity with constraining AI-assisted development tools to metadata/aggregate access only, never raw sensitive values.