
CDO - Insider Risk - Technical Analyst
- United Kingdom
- Permanent
- Full-time
The Insider Risk Technical Analyst plays a critical role in data loss prevention security operations, understanding the importance of the data loss controls, insider risk policies and how these protects the sensitive business data and can enhance an analyst response to events. This is a critical role expected to monitor, review and data loss and insider risk controls portfolio and help mature our monitoring and response processes.The successful candidate will be comfortable working at a technical level, reviewing and monitoring the data loss events in the company and work with the business stakeholder in containing the data loss events. Will also demonstrate working with different tools and technologies in the Data Loss and Insider Risk space. Our leadership team will be looking at this role to bring out any automation and fine tuning opportunities for the team to deliver on.About youKey ResponsibilitiesThe Insider Risk - Technical Analyst will be responsible to:
- Ensure data loss events from multiple tools are timely reviewed within the SLA times.
- Work with the user management and stake holders in containing the data loss incidents.
- Escalate to the relevant stakeholders/teams in solving the data loss cases.
- Working as part of a global insider risk team to deliver solutions to reduce manual dependencies on the workload.
- Proactively identify the policy fine tuning opportunities from Business As Usual (BAU) activities.
- Ensure the documentation is followed, improve documentation of the case resolution where possible.
- Work on technical implementations of the controls in various tools.
- At least 4 years of experience working in a SOC or Incident Response position, most of it in data loss teams.
- At least 2 year of working experience in Microsoft Purview tools including implementing the policies
- Knowledge of or experience working with security solutions - Proxy, SIEM, DLP, SOAR
- Experience explaining the risk of security threats and creating mitigations.
- Experience of general IT infrastructure technologies and principles.
- Experience in designing and implementation of the Data loss controls in industry known tools (e.g. Microsoft Purview, Proof Point, Zscaler)
- Experience in working on SIEM and SOAR platforms.
- Reporting ability, with an understanding on how to tailor reports to show capacity and efficiency improvements
- Understanding of how business data can be exfiltrated outside the enterprise.
- Banking or Finance industry related experience desirable