Experience working in cyber security through large scale business transformation.
Operates global host and network data loss prevention technologies Performs daily triage against DLP alerts.
Takes a lead position when positive data loss incidents are identified at a Global level drives incident rigor with the SOC, ensuring the resolution of events working in support of the Insider Threat Director.
Maintains and establishes mechanisms to ensure ongoing improvements to Global DLP processes and procedures
Recommends DLP configuration changes, including testing and validation. Working in partnership with key infrastructure stakeholders and third parties.
Recommends improvements or additions to DLP requirements and use cases Conducts analysis of and provides metrics regarding DLP trends, anomalies, etc.
Conducts security research on threats and remediation methods
Interprets corporate policies and translate into technical rulesets and technical policy to monitor priority use cases that alarm when policy is not followed or when exceptions to baselines of usual behaviour are identified.
Responsible for following up insider incidents, ensuring forensic chain is undertaken where appropriate and full reports are available.
Must be able to deputise for the Global Insider Threat Director and to work on highly sensitive, legal and HR investigations with the highest level of quality and integrity.
Responsible for working collaborative across multiple teams to coach and influence on insider threat and to help drive a strong security culture across the organization.
Responsible for taking on a ‘security coaching role’ when engaging with business and functional partners. Ability to translate technical jargon into business language is crucial.
Responsible for ensuring DLP tooling is optimized, is supported by operational rigor and coverage gaps are quickly identified at a Global level. When gaps are identified, driving responsive action will be taken – drive to impact in this space is key.
Engagement/support to Cyber Threat Intelligence to be provided on an ad-hoc basis, as agreed with the Director of Insider Threat and CTI Manager.
Skills/Experience
Experience with using Microsoft DLP
Experienced technical understanding of DLP technologies and implementing the rollout of DLP policies.
Good understanding of configuration change management and project management processes
Experience engaging with DLP stakeholders both within CISO and the broader organization
Solid attention to detail, follow-up and excellent organizational skills
Ability to collaborate with multi-functional teams
Ability to treat sensitive/confidential information appropriately
Must possess personal tact, discretion and good judgment.
Excellent interpersonal, written and verbal communication skills