2

Cybersecurity Operations, Data Loss Prevention - Content Developer

260312-South Florida Region Admin
Full-time
On-site
Westerville, Ohio, United States
Cyber Security
Description

Working in cybersecurity takes passion for technology, speed, a desire to learn, and vigilance in order to keep every asset safe. As part of our global team of technologists and innovators, your work will have a critical impact on our company, as well as our clients and our business partners around the world. You’ll work with a highly motivated team focused on delivering solutions built to stop adversaries and strengthen our operations. Your work will contribute to identify and build indicators of insider threats and prevent sensitive data loss through world class tools and technologies. 

Our Data Loss Prevention (DLP) team performs many functions in support of data security at the firm. The team develops world class solutions for detection and prevention of sensitive information leaving the firm based on in-depth analysis. In addition, the team develops new data identifiers, builds and maintains tools and capabilities for data loss triage prioritization, analyzes trends and patterns of DLP activity and works with stakeholders to reduce the risk of data loss across all lines of business.

Job responsibilities  

  • You’ll design, configure and implement DLP policies on Microsoft Information Protection (Microsoft Purview) suite and Symantec DLP at an enterprise level.
  • You’ll use your scripting skills and analytical capabilities to automate deployment and smoothly run the maintenance.
  • You’ll provide expertise and guidance in management, configuration and optimizations of Microsoft O365 security solutions.
  • You’ll contribute to development of new data identifiers, data governance policies, standards and procedures ensuring compliance and data integrity.
  • You’ll collaborate with stakeholders, business and technology groups to provide guidance, advice on best practices, define data management requirements, establish effective controls, practices and procedures.
  • You’ll use your knowledge and expertise to respond to incidents, perform risk reviews, vulnerability assessments and identify new and emerging threats.
  • You’ll use your expertise to deliver cost-effective solutions and leverage your communication and presentation skills to engage senior leaders on important issues and updates.

Required qualifications, capabilities, and skills –

  • Bachelor’s degree with 5 or more years of cybersecurity operations or SOC related experience
  • Excellent command of cybersecurity organization practices, data loss prevention concepts, security incident triage, insider threat, operations risk management principles and processes, architectural requirements, emerging threats and vulnerabilities, and incident response methodologies
  • Hands-on experience of configuration and management of Microsoft Information Protection (Microsoft Purview) in large-scale enterprise environment with knowledge of the following areas – Information Protection/Sensitivity Labels, Data Loss Prevention, Insider Risk/Threat Management.
  • Strong scripting skills in PowerShell, Python etc. and working knowledge of regular expressions.
  • Experience of technical log reviews, Symantec DLP or Microsoft Information Protection and Splunk Enterprise Security or other SIEM tool.
  • Experience of development and implementation of new DLP or insider threat use cases and process automation.
  • Excellent analytical and problem-solving skills with ability to translate complex technical concepts into practical solutions.

Preferred qualifications, capabilities and skills 

  • Possess two or more of the following certifications - Microsoft Certified: Security, Compliance and Identity Fundamentals, Cybersecurity Architect Expert, Security Operations Analyst Associate, Azure Security Engineer, CISSP, Splunk Certified Power User
  • Experience with Agile methodology and the ability to work with at least one of the common frameworks with knowledge of tools like Confluence, JIRA and Service-Now.
  • Ability to identify network attacks and systemic security issues as they relate to threats and vulnerabilities, with a focus on recommendations for enhancements or remediation. 
  • Good understanding of national and international laws, regulations, policies and ethics related to financial industry cybersecurity and foundational knowledge of computer forensics; legal, government and jurisprudence as they relate to cybersecurity; operating systems; and methods for intelligence gathering and sharing.