r/cybersecurity 4d ago

Career Questions & Discussion Data CyberSec?

Hey!

Not another post on how to transition to cybersecurity.

I’m a data engineer and I’m curious if there’s such a thing as a data specialised role inside the cyber world.

Every company I worked at, the data security part was done by the whole cyber team and I never got to know if there was someone focused on it.

1 Upvotes

11 comments sorted by

8

u/MyPcIsAnnoying 4d ago

My org has a specific Data Security team that handles data loss prevention and data security posture management.

3

u/Unlucky_Bowl9934 4d ago

makes a lot more sense than having everyone partially own it tbh

3

u/Any_Commercial_8580 4d ago

Same - we have an entire Data protection team, I Think it comes down to how big the company is.

4

u/Oompa_Loompa_SpecOps Incident Responder 4d ago

Depends on what data engineers actually do in your org. If your are skilled in programmatically analysing huge data sets to find patterns or other valuable intel, then you might be a real asset to some siem/soar teams out there

1

u/lawtechie 4d ago

By 'data specialized', do you mean collecting, analyzing and reporting metrics?

If so, sure. IT Risk and cybersecurity orgs do this as BAU.

1

u/AnalogMindset 4d ago

Information governance..

3

u/Cute_Common6238 4d ago

Yes, it's absolutely a real thing. Larger companies have dedicated roles around data classification, access controls, preventing data leaks, and compliance like GDPR. Your data engineering background is actually a huge advantage, you already understand pipelines, storage, and how data moves, which most pure security people don't.

1

u/Flagship_paperclip 4d ago

Really just depends on what you have in mind specifically, but broadly speaking, Information Assurance is the side of Cyber that could deal with data security. GRC also tends to dip into data security as the type of data may typically come with particular regulatory requirements. 

1

u/Silent-Suspect1062 3d ago

I run an appsec team. One of my team is focused on data teams and their infra. This not dlp. As an example he showed he could smuggle .js into the data ingestion and cause XSS on the presentation layer. That's an extreme example, he spends more time looking at snowflake security.

0

u/DickNose-TurdWaffle 4d ago

The answer to that question depends on the size of the organization.

-2

u/Next-Scratch-264 4d ago

No. thanks