Data Protection & Identity Manager
Job Summary
The Data Protection & Identity Manager will own and advance Extreme's strategy for both identity governance across both human and non-human (AI agent) identities, as well as the enterprise-wide Data Loss Prevention (DLP) program. This role is pivotal to the establishing control over ALL identities, enforcing DLP policies, protecting Extreme’s and stakeholder date, thus reducing the organization's exposure to credential theft, data exfiltration, and malicious activity.
The successful candidate will bring deep technical expertise, strong cross-functional collaboration skills, and the leadership to build scalable security programs in a fast-moving AI-driven environment.
Key Responsibilities:
Identity Governance & Non-Human Identity (NHI) Management
-
Design, implement, and operate a unified Identity Governance & Administration (IGA) program covering human, service account, and AI agent identities — with particular focus on controlling the rapidly growing population of AI agent identities, creating the appropriate governance structure and guardrails based on best practice.
-
Establish lifecycle management processes for AI agent identities, including provisioning, entitlement review, and decommissioning, mitigating exposure to credential theft and malicious activity
-
Define and enforce least privilege access models and zero-trust principles across all identity types
-
Develop and maintain a real-time inventory of AI agent identities, their access scopes, and associated risk profiles
-
Partner with AI platform and engineering teams to embed identity security controls into agent deployment pipelines
-
Lead regular access certification and entitlement review cycles across the enterprise
-
Integrate the process for human identity management with the AI agent identities to create a cohesive strategy.
-
Be a thought leader within Extreme on how the adoption of AI agents can be utilized to add value across the enterprise
Data Loss Prevention (DLP)
-
Own and mature the enterprise DLP strategy, policy framework, and toolset, ensuring coverage extends to AI-assisted and agent-driven data flows
-
Drive full coverage of data tagging, classification, and sensitivity labelling across structured and unstructured data estates
-
Define and enforce DLP policies for email, endpoint, cloud, and AI-assisted workflows
-
Manage the DLP exception review process, ensuring risk-based approvals with appropriate audit trails
-
Monitor DLP telemetry and investigate high-severity incidents in conjunction with the Security Operations Centre
-
Report on DLP program effectiveness, policy coverage, and incident trends to senior leadership and relevant regulatory stakeholders
Job Requirements
The job requirements include but are not limited to the following.
-
Hands-on experience designing and operating identity governance programs, including non-human and service account identity management
-
Demonstrated expertise in enterprise DLP tooling (e.g., Microsoft Purview, Symantec DLP, Zscaler) and policy development
-
Experience with AI/ML platform security, including securing LLM-based agents, APIs, and automation pipelines, ad MCP environments
-
Strong understanding of zero-trust architecture, least-privilege principles, and privileged access management (PAM)
-
Familiarity with data classification frameworks and sensitivity labelling at enterprise scale
-
Ability to lead cross-functional initiatives and influence stakeholders without direct authority
-
Strong analytical and risk assessment skills; ability to translate technical risk into business impact
-
Excellent written and verbal communication skills, including executive-level reporting
-
Ability to manage multiple concurrent priorities and tasks in a fast-paced, high-growth environment
-
Self-starter with a continuous improvement mindset and a drive to challenge existing processes
Working Schedule
Monday–Friday, 40 hours per week. On-call rotation required for high-severity DLP or identity incidents outside standard hours.
Experience & Qualifications
-
8+ years of experience in Information Security, with a minimum of 3 years in identity governance, IAM, or data protection roles
-
Experience securing environments with significant AI/ML or automation workloads is strongly preferred
-
Hands-on experience with Microsoft Entra ID (Azure AD), Okta, SailPoint, or equivalent IGA platforms
-
Experience with SIEM, CASB, and endpoint DLP solutions in enterprise environments
-
Relevant certifications preferred: CISSP, CISM, CCSP, Microsoft SC-300, or equivalent
-
Bachelor's degree in Computer Science, Information Security, or a related field — or equivalent practical experience
Compensation: This role has a market-competitive salary with an anticipated base compensation range of 110,000-140,000 USD. The posted range reflects the amount Extreme Networks reasonably and in good faith expects to pay for this role upon hire. This range is set using objective, gender-neutral criteria based on skills, experience, responsibility, and working conditions. Actual compensation offered will depend on the selected candidate's experience, qualifications, skills, and work location.
Benefits and Total Rewards:
Extreme Networks offers a comprehensive benefits package. Specific benefits vary by country and may include:
• Medical, dental, and vision insurance
• Flexible work schedules and work-from-home opportunities where role permits
• Paid time off, including open time off in eligible markets and statutory leave in all markets
• Paid holidays in accordance with local practice
• Retirement savings programs, including 401(k) matching in the United States
• Employee Stock Purchase Program, where eligible
• Adoption assistance and fertility treatment support, where eligible
• Flexible spending accounts, where eligible
• Employee assistance program
• Tuition reimbursement, where eligible
• Life and disability insurance
Benefits eligibility is based on country of employment, role, and employment status. Complete benefits details will be provided during the interview process and in the formal offer of employment.
Equal Employment Opportunity
Extreme Networks, Inc. is an Equal Opportunity Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. We are committed to taking affirmative action to employ and advance in employment qualified protected veterans, including disabled veterans, recently separated veterans, active-duty wartime or campaign badge veterans, and Armed Forces service medal veterans.
Extreme Networks also strives to prevent other, subtler forms of inappropriate behavior (for example, stereotyping) from ever gaining a foothold in our organization. Whether blatant or hidden, barriers to success have no place at Extreme Networks. We encourage people from underrepresented groups to apply.
Fair chance and background checks
Extreme Networks will consider qualified applicants with criminal histories in a manner consistent with the California Fair Chance Act, Los Angeles Fair Chance Initiative for Hiring Ordinance, Los Angeles County Fair Chance Ordinance for Employers, Philadelphia Fair Criminal Record Screening Standards Ordinance, Illinois Human Rights Act, Cook County Human Rights Ordinance, Seattle Fair Chance Employment Ordinance, and the San Francisco Fair Chance Ordinance. An applicant's conviction history will not be considered until after a conditional offer of employment has been made. Following any individualized assessment, applicants will be provided with the opportunity to respond before any adverse action is taken.
Extreme Networks does not seek salary history information from applicants and will not rely on salary history in determining whether to offer employment or in setting compensation.
Reasonable accommodation
Extreme Networks is committed to providing reasonable accommodations to qualified applicants with disabilities throughout the application, interview, and hiring process. If you require a reasonable accommodation to participate in the application or interview process, please contact [insert contact email and phone]. All requests will be handled confidentially.
Use of artificial intelligence in hiring
Extreme Networks may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are made by humans. Applicants have the right to request human review of any automated decision affecting their candidacy and to request information about how their personal data is processed. To exercise these rights, please contact [insert contact email].
Data privacy
Personal data provided during the application process will be processed in accordance with Extreme Networks' Candidate Privacy Notice, which is available at https://www.extremenetworks.com/about-extreme-networks/company/legal/privacy-and-cookies-policy. For applicants in the European Economic Area, United Kingdom, and other jurisdictions with comparable data protection laws, the Candidate Privacy Notice describes your rights regarding your personal data.
About Extreme Networks
Extreme Networks, Inc. (NASDAQ: EXTR) creates effortless networking experiences that enable people and organizations to advance. We push the boundaries of technology by leveraging machine learning, artificial intelligence, analytics, and automation.