Insider Threat Program Manager, Information Security

5 Months ago • 5 Years + • Cyber Security

Job Summary

Job Description

ByteDance's Internal Security Risk Management & Governance team seeks an Insider Threat Program Manager to develop and maintain the organization's insider risk security governance framework. This role involves collaborating with stakeholders, conducting security risk assessments, monitoring and reporting on control effectiveness, and staying abreast of security trends. Ideal candidates possess a minimum of 5 years of experience in DLP, UEBA, or security platforms, and a strong understanding of risk assessment methodologies.
Must have:
  • Bachelor's degree in Information Security, Computer Science, or related field
  • Minimum 5 years of work experience in DLP, UEBA, or security platforms
  • Experience with security risk assessment methodologies and tools
  • Skilled in creating and maintaining risk registers
  • Excellent communication and interpersonal skills
  • Proven ability to manage and prioritize multiple projects
Good to have:
  • Professional certifications such as CISSP, CISM, CRISC, or CGEIT
  • Hands-on experience with commercial or in-house UBA/UEBA solutions
  • Experience with threat modeling methodologies

Job Details

Responsibilities
About the Company Founded in 2012, ByteDance's mission is to inspire creativity and enrich life. With a suite of more than a dozen products, including TikTok as well as platforms specific to the China market, including Toutiao, Douyin, and Xigua, ByteDance has made it easier and more fun for people to connect with, consume, and create content. Why Join Us Creation is the core of ByteDance's purpose. Our products are built to help imaginations thrive. This is doubly true of the teams that make our innovations possible. Together, we inspire creativity and enrich life - a mission we aim towards achieving every day. To us, every challenge, no matter how ambiguous, is an opportunity; to learn, to innovate, and to grow as one team. Status quo? Never. Courage? Always. At ByteDance, we create together and grow together. That's how we drive impact - for ourselves, our company, and the users we serve. Join us. About the Team The Internal Security Risk Management & Governance team is responsible for managing and mitigating information security risks posed within the organisation. To ensure that the company's risk management and governance strategies are up to date and aligned across the organisation, this team is responsible for working with stakeholders from cross-functional teams to perform regular risk assessments, designing and implementing risk mitigation controls. This team is also responsible for managing the optimization, operation, training, and data analysis of the internal threat platform and UEBA (User and Entity Behavior Analytics) and DLP (Data Loss Prevention) platforms within the company. Responsibilities - Develop and maintain the organization's insider risk security governance framework, including risk scenario mapping to controls, policies, procedures, and standards that align with industry best practices and regulatory requirements. Such framework must be sufficiently detailed to allow ease of execution with clarity in roles and responsibility amongst stakeholders. - Communicate the insider threat governance framework to key stakeholders and build effective collaboration models with stakeholders with clear roles and responsibilities, transparent tracking of metrics and seamless management reporting. - Conduct regular security risk assessments to identify risk trends, vulnerabilities and alert patterns, and work with relevant departments to develop mitigation and remediation strategies. - Monitor and report on the effectiveness of security controls and the status of security risks to senior management. Communicate risk assessment and trend analysis findings, risks and gaps to both technical and non-technical program stakeholders. - Coordinate with IT and business units to ensure insider threat security measures are integrated into technology projects and business processes. - Identify and garner the support of internal and external stakeholders to collaborate on driving change, including risk remediation and leading parties involved to meet risk remediation objectives. - Translate business and technology requirements into relevant insider threat rules for operational teams to implement - Stay abreast of the latest security trends, threats, and technologies to continuously improve the organization's insider threat security posture. - Conduct analysis of large complex datasets involving insider risks, track metrics and identify gaps and vulnerabilities - Understanding emerging insider risks to build and improve proactive threat detection.
Qualifications
Minimum Qualifications 1. Bachelor's degree or above, with a preference for majors in Information Security, Computer Science, Information Technology, privacy, risk or a related field. Professional certifications such as CISSP, CISM, CRISC, or CGEIT are highly desirable. 2. Minimum of 5 years of work experience, with a preference for experience in DLP (Data Loss Prevention), UEBA (User and Entity Behavior Analytics), or security platforms-related work. 3. Experience with security risk assessment methodologies and tools. 4. Skilled in creating and maintaining risk registers, developing risk treatment plans, and effectively communicating risk posture to stakeholders at all levels of the organization. 5. Self-driven and results-oriented, enjoys challenging tasks, demonstrates enthusiasm for work, and can handle job pressures. 6. Excellent communication and interpersonal skills, with the ability to engage and influence stakeholders at all levels. 7. Proven ability to manage and prioritize multiple projects and tasks. Preferred Qualifications - Hands on in-house experience with designing, implementation and operation of commercial or in-house UBA/UEBA solutions (e.g., Splunk, Exabeam) are highly desirable - Experience with threat modeling methodologies (e.g., STRIDE, PASTA) to analyze and assess security threats within software applications, systems, and networks. ByteDance is committed to creating an inclusive space where employees are valued for their skills, experiences, and unique perspectives. Our platform connects people from across the globe and so does our workplace. At ByteDance, our mission is to inspire creativity and enrich life. To achieve that goal, we are committed to celebrating our diverse voices and to creating an environment that reflects the many communities we reach. We are passionate about this and hope you are too.

Similar Jobs

Likewize - Solarwinds Tools Expert

Likewize

Chennai, Tamil Nadu, India (On-Site)
6 Months ago
The Walt Disney Company - Principal Software Engineer

The Walt Disney Company

Seattle, Washington, United States (On-Site)
1 Month ago
PwC - D365 Azure Integration Developer-Manager

PwC

Kolkata, West Bengal, India (On-Site)
6 Months ago
Onward Search - DevOps Engineer

Onward Search

Irvine, California, United States (Hybrid)
1 Month ago
CleverTap - Senior Backend Engineer (Java & Mongo DB)

CleverTap

Mumbai, Maharashtra, India (Hybrid)
5 Months ago
PwC - Senior Associate, Infrastructure and Operations, Cybersecurity

PwC

Vaughan, Ontario, Canada (On-Site)
2 Months ago
PwC - Workday - Senior Consultant-  Bangalore

PwC

Bengaluru, Karnataka, India (On-Site)
6 Months ago
Assystems - SOC L1 Analyst

Assystems

Gurugram, Haryana, India (On-Site)
5 Months ago
Magna International - Sr. Penetration Test Engineer

Magna International

Bengaluru, Karnataka, India (On-Site)
6 Months ago
CD PROJEKT RED - Senior Pentester (Cybersecurity team)

CD PROJEKT RED

Warsaw, Masovian Voivodeship, Poland (On-Site)
4 Months ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

Rackspace Technology - Site Reliability Engineer / Observability Engineer

Rackspace Technology

India (Remote)
1 Month ago
The Walt Disney Company - Lead Media Performance Engineer, Quality

The Walt Disney Company

New York, New York, United States (On-Site)
2 Months ago
ZeniMax Media - Backend Programmer

ZeniMax Media

Rockville, Maryland, United States (On-Site)
6 Months ago
CloudHire - DevOps Automation Engineer

CloudHire

New York, New York, United States (On-Site)
5 Months ago
PENN Interactive - Senior Technical Product Manager, Data

PENN Interactive

Philadelphia, Pennsylvania, United States (Hybrid)
1 Month ago
Rackspace Technology - Site Reliability Engineer III

Rackspace Technology

India (Remote)
3 Weeks ago
The Walt Disney Company - Media Performance Engineer II, Distribution

The Walt Disney Company

San Francisco, California, United States (On-Site)
1 Month ago
Tesla - Senior Application Support Engineer

Tesla

North Holland, Netherlands (On-Site)
1 Month ago
The Walt Disney Company - Senior Media Performance Engineer, Distribution

The Walt Disney Company

Amsterdam, North Holland, Netherlands (On-Site)
1 Month ago

Get notifed when new similar jobs are uploaded

Jobs in Singapore

HoYoverse - Data Analyst - Honkai: Star Rail - Fresh Grad

HoYoverse

Singapore (On-Site)
4 Months ago
The Walt Disney Company - Sr Manager, Product Management

The Walt Disney Company

Singapore, Singapore (On-Site)
4 Months ago
ByteDance - Software Engineer, Video-On-Demand

ByteDance

Singapore (On-Site)
5 Months ago
ByteDance - Training and Mechanism Partner - Global Organisational Culture

ByteDance

Singapore (On-Site)
5 Months ago
ByteDance - Research Engineer (Foundation Model) - Machine Learning Systems

ByteDance

Singapore (On-Site)
5 Months ago
ByteDance - Channel Risk Expert - Global Payment

ByteDance

Singapore (On-Site)
2 Months ago
The Walt Disney Company - Intern, Talent Acquisition & Employer Branding

The Walt Disney Company

Singapore, Singapore (On-Site)
1 Month ago
ByteDance - Site Reliability Engineer, Traffic Platform

ByteDance

Singapore (On-Site)
2 Months ago
ByteDance - Security Engineer (Penetration Tester) - Security Assurance

ByteDance

Singapore (On-Site)
5 Months ago
HoYoverse - Legal Counsel (Privacy and Data Protection)

HoYoverse

Singapore (On-Site)
8 Months ago

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

The Walt Disney Company - Manager, Security Assurance

The Walt Disney Company

Orlando, Florida, United States (On-Site)
1 Month ago
Company3 Method Studios - Security Compliance Assessor

Company3 Method Studios

United States (Remote)
1 Month ago
PwC - Internship program - Risk Consulting

PwC

Bangkok, Bangkok, Thailand (On-Site)
6 Months ago
Canva - Security Engineering Director - Detection & Response - Remote across ANZ

Canva

Adelaide, South Australia, Australia (Remote)
4 Months ago
Axinous - Transformation Architect - South East

Axinous

Georgia, United States (Remote)
2 Weeks ago
Tencent - Game Data and Privacy Compliance Manager

Tencent

Shenzhen, Guangdong Province, China (On-Site)
1 Month ago
Saviynt - Technical Lead, Professional Services - NA

Saviynt

Bengaluru, Karnataka, India (Hybrid)
5 Months ago
Glean - Software Engineer, Security

Glean

Palo Alto, California, United States (On-Site)
5 Months ago
ByteDance - Senior Software Engineer - Network Security

ByteDance

San Jose, California, United States (On-Site)
1 Month ago
PwC - Data Protection Expert

PwC

Prague, Prague, Czechia (Hybrid)
4 Months ago

Get notifed when new similar jobs are uploaded

About The Company

Where imagination meets innovation, delivering limitless gaming experiences.

New York, New York, United States (On-Site)

Jakarta, Jakarta, Indonesia (On-Site)

San Jose, California, United States (On-Site)

San Jose, California, United States (On-Site)

Singapore (On-Site)

Taguig, Metro Manila, Philippines (On-Site)

View All Jobs

Get notified when new jobs are added by ByteDance

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug