Matt Burton
DLP/ Insider Threat ManagerWest London (Hybrid)Salary DOEJob SummaryThe fundamental objective of the department is to help harness business opportunities in a safe and secure way. We recognize that cyber security is not just a technical issue and requires engagement with the whole business to adapt a broad approach to cyber security.The DLP Manager role is crucial for supporting configuration (rulesets and technical policy) within DLP and Insider threat tooling and for working with broader teams who operate technology tools to ensure they are optimised for use by the insider threat team. Monitoring and responding to DLP alarms, triaging and driving responsive action is also a key responsibility.The role would be suited to a senior DLP analyst looking to take the next step in their DLP career!Responsibilities Experience working in cyber security through large scale business transformation. Operates global host and network data loss prevention technologies Performs daily triage against DLP alerts. Takes a lead position when positive data loss incidents are identified at a Global level drives incident rigor with the SOC, ensuring the resolution of events working in support of the Insider Threat Director. Maintains and establishes mechanisms to ensure ongoing improvements to Global DLP processes and procedures Recommends DLP configuration changes, including testing and validation. Working in partnership with key infrastructure stakeholders and third parties. Recommends improvements or additions to DLP requirements and use cases Conducts analysis of and provides metrics regarding DLP trends, anomalies, etc. Conducts security research on threats and remediation methods Interprets corporate policies and translate into technical rulesets and technical policy to monitor priority use cases that alarm when policy is not followed or when exceptions to baselines of usual behaviour are identified. Responsible for following up insider incidents, ensuring forensic chain is undertaken where appropriate and full reports are available. Must be able to deputise for the Global Insider Threat Director and to work on highly sensitive, legal and HR investigations with the highest level of quality and integrity. Responsible for working collaborative across multiple teams to coach and influence on insider threat and to help drive a strong security culture across the organization. Responsible for taking on a ‘security coaching role’ when engaging with business and functional partners. Ability to translate technical jargon into business language is crucial. Responsible for ensuring DLP tooling is optimized, is supported by operational rigor and coverage gaps are quickly identified at a Global level. When gaps are identified, driving responsive action will be taken – drive to impact in this space is key. Engagement/support to Cyber Threat Intelligence to be provided on an ad-hoc basis, as agreed with the Director of Insider Threat and CTI Manager.Skills/Experience Experience with using Microsoft DLP Experienced technical understanding of DLP technologies and implementing the rollout of DLP policies. Good understanding of configuration change management and project management processes Experience engaging with DLP stakeholders both within CISO and the broader organization Solid attention to detail, follow-up and excellent organizational skills Ability to collaborate with multi-functional teams Ability to treat sensitive/confidential information appropriately Must possess personal tact, discretion and good judgment. Excellent interpersonal, written and verbal communication skillsQualifications Certification or demonstrable technical skills in a range of different DLP tooling Knowledge of Web and Mail gateway solutions. High level of Operating System and general IT knowledge. Working knowledge of security fundamentals, including firewalls, routers and ACLs. Awareness of various regulatory compliances such as privacy/GDPR, PCI, and others. Experience is preferred above certifications
