Root Insurance

Senior Security Engineer

Root is on a mission to unbreak insurance by creating experiences people love at prices they can't believe. We believe that investing in world-class technology will facilitate a new class of insurance products, driving a massive positive impact on the hundreds of millions of drivers who carry auto insurance in the US. Root's Engineering team is committed to building a flexible platform on which our product designers and quantitative scientists can quickly test ideas, deploy them into production, and iterate, with the ultimate objective of a delightful customer experience coupled with effective risk management.


The Opportunity


We are seeking a Senior Security Engineer to lead our Data Security domain and help define how the organization protects sensitive data at scale. In this role, you will contribute to the data security roadmap and help establish the standards, control requirements, and risk priorities across the data lifecycle.


You will partner closely with Data Platform, Analytics, Engineering, Security Operations, and GRC teams to protect policyholder and corporate data in cloud-native environments. Your responsibilities will include data discovery and classification, encryption and key management, data obfuscation and de-identification, fine-grained access controls, secure data sharing, retention and deletion, backup protection, monitoring, and data loss prevention.


This is a hands-on, highly collaborative role. You will establish secure patterns and standards, influence technical decisions, automate repeatable workflows, and help teams adopt practical controls that enable secure use of data for business and analytics purposes.


Salary Range: $111,500 - $139,400 (Eligible for competitive bonus and equity offering)

Root is a "work where it works best" company. This means we will support you working in whatever location that works best for you across the US.


How You Will Make an Impact

  • Help establish the data security strategy and roadmap for sensitive policyholder, customer, employee, and corporate data.
  • Protect PII, financial information, health-related information where applicable, claims data, and other regulated or confidential data across its full lifecycle.
  • Establish standards for data classification, encryption, key management, masking, tokenization, anonymization, pseudonymization, retention, deletion, and secure data sharing.
  • Design and improve data access governance, including least privilege, RBAC/ABAC, privileged access, row-level controls, column-level controls, and periodic access reviews.
  • Partner with Data Platform and Analytics teams to embed security controls into data pipelines, warehouses, data lakes, reporting platforms, and machine learning workflows.
  • Improve visibility into sensitive data stores, data flows, third-party transfers, and access patterns through discovery, monitoring, DLP, and related security tooling.
  • Establish secure backup, recovery, and resilience requirements for critical data.
  • Translate regulatory and business requirements into practical technical controls and measurable risk-reduction initiatives.
  • Lead cross-functional prioritization, balancing urgent risk remediation with long-term data security maturity and SOC 2 readiness.
  • Automate security workflows using scripting, APIs, policy-as-code, and approved AI-assisted tools while protecting confidential and regulated information.
  • Develop playbooks, reference architectures, and reusable patterns that improve consistency and reduce operational overhead.
  • Participate in the Security Engineering on-call rotation, triaging alerts and security issues during business hours and responding to after-hours escalations as needed.
  • Communicate data security risks, decisions, and recommendations clearly to engineers, business stakeholders, and senior leadership.
  • Coach engineering and analytics teams on secure data handling and help raise the organization’s overall data security maturity.


What You Will Need to Succeed

  • 5+ years of experience in data security, cloud security, security engineering, privacy engineering, or a related technical field.
  • Hands-on experience securing sensitive data in cloud environments and applying controls across storage, processing, analytics, and data-sharing systems.
  • Experience with several of the following: IAM, RBAC/ABAC, encryption, KMS/HSM, data classification, DLP, data discovery, access reviews, tokenization, masking, retention, deletion, backup security, and audit logging.
  • Demonstrated experience embedding security requirements into data platforms, data pipelines, analytics workflows, or application architectures.
  • Experience working with engineering, data platform, analytics, infrastructure, Security Operations, Privacy, Legal, or GRC teams.
  • Experience improving security operations through automation, scripting, integrations, policy-as-code, or systematic process improvement.
  • Familiarity with applicable privacy, security, and regulatory requirements, such as HIPAA, GLBA, state privacy laws, NYDFS, PCI DSS, NIST, or similar frameworks, where relevant.
  • Strong communication skills, including the ability to explain technical risks and tradeoffs to both engineers and senior leadership.
  • Demonstrated ability to balance security requirements with business needs and build alignment across stakeholders.
  • Sound judgment when using approved AI-assisted tools with confidential, proprietary, or regulated information.


Preferred Qualifications

  • Experience in insurance, financial services, healthcare, or another regulated industry.
  • Experience with data security posture management, data activity monitoring, enterprise DLP, or cloud data security platforms.
  • Familiarity with major cloud providers and cloud-native data services.
  • Experience with infrastructure-as-code, CI/CD security, policy-as-code, or security automation.
  • Experience supporting SOC 2, HIPAA, GLBA, NYDFS, PCI DSS, ISO 27001, or similar compliance programs.
  • Familiarity with AI-assisted engineering tools such as GitHub Copilot, Claude, Codex, or comparable platforms.


As part of Root's interview process, we kindly ask that all candidates be on camera for virtual interviews. This helps us create a more personal and engaging experience for both you and our interviewers. Being on camera is a standard requirement for our process and part of how we assess fit and communication style, so we do require it to move forward with any applicant's candidacy. If you have any concerns, feel free to let us know once you are contacted. We’re happy to talk it through.


Please see our Privacy Notice available HERE for more information on how we process your personal data.


Consistent with the Americans with Disabilities Act (ADA) and the Civil Rights Act of 1964, it is the policy of Root to provide reasonable accommodation when requested by a qualified applicant or candidate with a disability, unless such accommodation would cause an undue hardship for Root. The policy regarding requests for reasonable accommodation applies to all aspects of the hiring process. If reasonable accommodation is needed, please contact recruiting@joinroot.com.

Information Technology & Infosec

Remote (United States)

Compartir en:

Condiciones del servicioPrivacidadCookiesDesarrollado por Rippling