Insider Risk Specialist, Security Governance and Compliance

9 Minutes ago • 5 Years +
Cyber Security

Job Description

The team is responsible for managing and mitigating information security risks within the organization, ensuring governance strategies are aligned with industry best practices and regulatory requirements. Key responsibilities include developing and maintaining the insider risk security governance framework, conducting regular risk assessments, monitoring control effectiveness, and coordinating with IT to integrate security measures. The role also involves analyzing large complex datasets to identify insider risks and improving proactive threat detection.
Good To Have:
  • Hands-on in-house experience with designing, implementation and operation of commercial or in-house UBA/UEBA solutions (e.g., Splunk, Exabeam).
  • Experience with threat modeling methodologies (e.g., STRIDE, PASTA) to analyze and assess security threats.
Must Have:
  • Develop and maintain the organization's insider risk security governance framework.
  • Communicate the insider threat governance framework to key stakeholders and build effective collaboration models.
  • Conduct regular security risk assessments to identify risk trends, vulnerabilities and alert patterns.
  • Monitor and report on the effectiveness of security controls and the status of security risks to senior management.
  • Coordinate with IT and business units to ensure insider threat security measures are integrated.
  • Identify and garner the support of internal and external stakeholders to collaborate on driving change.
  • Translate business and technology requirements into relevant insider threat rules for operational teams.
  • Stay abreast of the latest security trends, threats, and technologies.
  • Conduct analysis of large complex datasets involving insider risks, track metrics and identify gaps and vulnerabilities.
  • Minimum of 5 years of work experience, with a preference for experience in DLP, UEBA, or security platforms-related work.
  • Experience with security risk assessment methodologies and tools.
  • Skilled in creating and maintaining risk registers, developing risk treatment plans, and effectively communicating risk posture.

Add these skills to join the top 1% applicants for this job

cross-functional
communication
data-analytics
risk-management
risk-assessment
risk-mitigation
game-texts
splunk

Responsibilities

About the Team The team is responsible for managing and mitigating information security risks posed within the organisation. To ensure that the company's risk management and governance strategies are up to date and aligned across the organisation, this team is responsible for working with stakeholders from cross-functional teams to perform regular risk assessments, designing and implementing risk mitigation controls. This team is also responsible for managing the optimization, operation, training, and data analysis of the internal threat platform and UEBA (User and Entity Behavior Analytics) and DLP (Data Loss Prevention) platforms within the company. Responsibilities - Develop and maintain the organization's insider risk security governance framework, including risk scenario mapping to controls, policies, procedures, and standards that align with industry best practices and regulatory requirements. Such framework must be sufficiently detailed to allow ease of execution with clarity in roles and responsibility amongst stakeholders. - Communicate the insider threat governance framework to key stakeholders and build effective collaboration models with stakeholders with clear roles and responsibilities, transparent tracking of metrics and seamless management reporting. - Conduct regular security risk assessments to identify risk trends, vulnerabilities and alert patterns, and work with relevant departments to develop mitigation and remediation strategies. - Monitor and report on the effectiveness of security controls and the status of security risks to senior management. Communicate risk assessment and trend analysis findings, risks and gaps to both technical and non-technical program stakeholders. - Coordinate with IT and business units to ensure insider threat security measures are integrated into technology projects and business processes. - Identify and garner the support of internal and external stakeholders to collaborate on driving change, including risk remediation and leading parties involved to meet risk remediation objectives. - Translate business and technology requirements into relevant insider threat rules for operational teams to implement - Stay abreast of the latest security trends, threats, and technologies to continuously improve the organization's insider threat security posture. - Conduct analysis of large complex datasets involving insider risks, track metrics and identify gaps and vulnerabilities - Understanding emerging insider risks to build and improve proactive threat detection.

Qualifications

Minimum Qualifications - Bachelor's degree or above, with a preference for majors in Information Security, Computer Science, Information Technology, privacy, risk or a related field. Professional certifications such as CISSP, CISM, CRISC, or CGEIT are highly desirable. - Minimum of 5 years of work experience, with a preference for experience in DLP (Data Loss Prevention), UEBA (User and Entity Behavior Analytics), or security platforms-related work. - Experience with security risk assessment methodologies and tools. - Skilled in creating and maintaining risk registers, developing risk treatment plans, and effectively communicating risk posture to stakeholders at all levels of the organization. - Self-driven and results-oriented, enjoys challenging tasks, demonstrates enthusiasm for work, and can handle job pressures. - Excellent communication and interpersonal skills, with the ability to engage and influence stakeholders at all levels. - Proven ability to manage and prioritize multiple projects and tasks. Preferred Qualifications - Hands on in-house experience with designing, implementation and operation of commercial or in-house UBA/UEBA solutions (e.g., Splunk, Exabeam) are highly desirable - Experience with threat modeling methodologies (e.g., STRIDE, PASTA) to analyze and assess security threats within software applications, systems, and networks.

Set alerts for more jobs like Insider Risk Specialist, Security Governance and Compliance
Set alerts for new jobs by bytedance
Set alerts for new Cyber Security jobs in Singapore
Set alerts for new jobs in Singapore
Set alerts for Cyber Security (Remote) jobs

Contact Us
hello@outscal.com
Made in INDIA 💛💙