Senior Security Engineer
Root is on a mission to unbreak insurance by creating experiences people love at prices they can't believe. We believe that investing in world-class technology will facilitate a new class of insurance products, driving a massive positive impact on the hundreds of millions of drivers who carry auto insurance in the US. Root's Engineering team is committed to building a flexible platform on which our product designers and quantitative scientists can quickly test ideas, deploy them into production, and iterate, with the ultimate objective of a delightful customer experience coupled with effective risk management.
The Opportunity
We are seeking a Senior Security Engineer to lead our Data Security domain and help define how the organization protects sensitive data at scale. In this role, you will contribute to the data security roadmap and help establish the standards, control requirements, and risk priorities across the data lifecycle.
You will partner closely with Data Platform, Analytics, Engineering, Security Operations, and GRC teams to protect policyholder and corporate data in cloud-native environments. Your responsibilities will include data discovery and classification, encryption and key management, data obfuscation and de-identification, fine-grained access controls, secure data sharing, retention and deletion, backup protection, monitoring, and data loss prevention.
This is a hands-on, highly collaborative role. You will establish secure patterns and standards, influence technical decisions, automate repeatable workflows, and help teams adopt practical controls that enable secure use of data for business and analytics purposes.
Salary Range : $111,500 - $139,400 (Eligible for competitive bonus and equity offering)
Root is a "work where it works best" company. This means we will support you working in whatever location that works best for you across the US.
How You Will Make an Impact
- Help establish the data security strategy and roadmap for sensitive policyholder, customer, employee, and corporate data.
- Protect PII, financial information, health-related information where applicable, claims data, and other regulated or confidential data across its full lifecycle.
- Establish standards for data classification, encryption, key management, masking, tokenization, anonymization, pseudonymization, retention, deletion, and secure data sharing.
- Design and improve data access governance, including least privilege, RBAC/ABAC, privileged access, row-level controls, column-level controls, and periodic access reviews.
- Partner with Data Platform and Analytics teams to embed security controls into data pipelines, warehouses, data lakes, reporting platforms, and machine learning workflows.
- Improve visibility into sensitive data stores, data flows, third-party transfers, and access patterns through discovery, monitoring, DLP, and related security tooling.
- Establish secure backup, recovery, and resilience requirements for critical data.
- Translate regulatory and business requirements into practical technical controls and measurable risk-reduction initiatives.
- Lead cross-functional prioritization, balancing urgent risk remediation with long-term data security maturity and SOC 2 readiness.
- Automate security workflows using scripting, APIs, policy-as-code, and approved AI-assisted tools while protecting confidential and regulated information.
- Develop playbooks, reference architectures, and reusable patterns that improve consistency and reduce operational overhead.
- Participate in the Security Engineering on-call rotation, triaging alerts and security issues during business hours and responding to after-hours escalations as needed.
- Communicate data security risks, decisions, and recommendations clearly to engineers, business stakeholders, and senior leadership.
- Coach engineering and analytics teams on secure data handling and help raise the organization’s overall data security maturity.
What