This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
We are seeking an experienced SQL Server 2022 Security & Encryption Engineer to design and implement a comprehensive security and encryption framework for SQL Server 2022 databases containing Protected Health Information (PHI). This short-term contract role is critical for achieving strong technical safeguards and delivering auditable evidence for HIPAA compliance. The successful candidate will deploy and harden SQL Server 2022 using industry-leading encryption, access control, auditing, and masking technologies, ensuring sensitive data is protected at rest, in transit, and in use.
Job Responsibility:
Deploy and configure SQL Server 2022 with a full security and encryption stack, including: Transparent Data Encryption (TDE), Always Encrypted with Azure Key Vault integration, Column-Level Encryption on all PHI-containing columns, Row-Level Security (RLS), Dynamic Data Masking (DDM)
Implement SQL Server Audit and route audit logs to Microsoft Sentinel for centralized monitoring and alerting
Enforce TLS 1.2 / 1.3 for all database connections and disable legacy protocols
Perform surface area reduction and hardening (disable unnecessary features, xp_cmdshell, etc.)
Design and implement secure key management practices using Azure Key Vault
Develop and document encryption strategies, policies, and procedures for PHI protection
Create a complete HIPAA Technical Safeguard evidence package including configuration documentation, encryption inventories, key management processes, and audit procedures
Collaborate with the Microsoft Security Framework Engineer and Microsoft Sentinel Engineer to ensure seamless integration with the broader security stack (Defender, Sentinel, Purview DLP, etc.)
Provide knowledge transfer and training to internal database and security teams
Requirements:
7+ years of hands-on experience as a SQL Server DBA or Database Security Engineer
Deep expertise in SQL Server 2022 security features, specifically: Transparent Data Encryption (TDE), Always Encrypted (with Azure Key Vault), Column-Level Encryption, Row-Level Security and Dynamic Data Masking, SQL Server Audit and log shipping to SIEM (Sentinel)
Proven experience implementing encryption solutions for databases containing PHI in regulated healthcare environments
Strong knowledge of HIPAA Security Rule technical safeguards and ability to produce auditable compliance evidence
Experience with Azure Key Vault for cryptographic key management
Solid understanding of TLS configuration, certificate management, and SQL Server surface area hardening
Excellent documentation and communication skills
Nice to have:
Prior experience working on Microsoft 365 E5 + Sentinel environments
Familiarity with Microsoft Purview sensitivity labeling and DLP integration with SQL databases
Certifications such as MCSE: Data Management and Analytics, or equivalent modern SQL security-focused credentials