This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
We are seeking a highly skilled and experienced Senior Information Security Analyst to join our team in the Technology Risk and CISO department. This role will primarily focus on maintaining the integrity and confidentiality of our organization’s data by leading the development and execution of Data Loss Prevention strategies, which includes configuring and managing DLP systems to monitor and prevent unauthorized data movements across endpoints, networks, and cloud platforms. The candidate will handle incident response by investigating alerts, determining the scope and impact of potential data breaches, and coordinating with various teams for resolution. Additionally, the candidate will develop and refine data security policies, provide training to increase organizational awareness, and stay updated with the latest in DLP technology to recommend advancements or modifications to our security infrastructure.
Job Responsibility:
Design, implement, and manage the end-to-end DLP control to protect sensitive data across endpoints, cloud, email, network, and mobile environments according to identified requirements, developed milestones, and approved program
Develop and expand DLP policies, rules, and controls to align with evolving business needs, regulatory requirements, and industry best practices
Continuously improve and optimize DLP processes to enhance accuracy, reduce false positives, and improve efficiency
Support the expansion of DLP capabilities into emerging technologies, and egress channels
Follow the DLP incident response process, collaborating with all stakeholders (i.e., HR, Privacy, and Business Units) to investigate, contain, and remediate data loss incidents
Develop and maintain DLP incident playbooks and ensure timely response to alerts
Provide detailed analysis and reporting on data loss incidents, root causes, and corrective measures
Conduct post-incident reviews and recommend improvements to prevent future incidents
Establish, enforce, and regularly review DLP policies, standards, and guidelines to ensure comprehensive coverage of sensitive data across the organization
Collaborate with Legal, Compliance, Risk, and other departments to ensure DLP policies align with regulatory requirements (e.g., GDPR, PIPEDA, PCI-DSS, HIPAA) and industry frameworks
Develop tailored DLP policies for business units based on specific data classification and operational needs
Define, track, and report on key performance indicators (KPIs) and other DLP metrics to measure control effectiveness and risk posture
Provide detailed reporting on DLP incidents, policy violations, and achieved progress
Develop and deliver DLP awareness and training programs to educate employees on the importance of data protection, acceptable use policies, and secure data handling practices
Promote a culture of data security awareness across the organization through regular communications and engagement activities
Evaluate and implement new DLP technologies, tools, and enhancements to strengthen data protection capabilities
Stay current with industry trends, emerging threats, and new technologies to ensure the organization remains ahead of evolving data loss risks
Regularly assess the effectiveness of DLP controls through testing, audits, and continuous monitoring
Report identified DLP gaps and drive initiatives to close them
Requirements:
Bachelor’s degree from an accredited college or university or equivalent experience
Minimum five years’ experience as an information technology professional with at least three of those in information security
Deep knowledge of Data Loss Prevention (DLP) technologies, frameworks, and platforms—particularly Microsoft Purview, Microsoft Defender for Cloud Apps, and Microsoft Defender for Endpoint
Proven experience implementing and managing solutions for Data Loss Prevention, Insider Risk Management, Data Security Posture Management, and Conditional Access
Strong understanding of data classification, encryption, regulatory requirements, and standards
Proven experience managing DLP incidents, governance forums, and program expansion initiatives
Familiarity with cybersecurity frameworks such as NIST, ISO 27001, and CIS Controls
Experience collaborating with cross-functional teams and senior stakeholders
Exceptional analytical, problem-solving, and investigative skills
Holds at least one information security certification or actively working towards at least one security certification (e.g. CISSP, CISM)
Excellent communicator including demonstrated presentation and negotiation skills
Experience with security solutions for multi-tier cloud-based applications
Experience interpreting and consulting around meeting the requirements of the Information Security Policies and Standards for a large organization
Working knowledge of IT Audit processes, including design of control test procedures
Demonstrated ability to foster relationships and build trust
Ability to work independently and deliver on commitments
Strong analytical and problem-solving skills
Experience in risk assessment methodologies
What we offer:
Reliability Status Security Clearance – this can only be completed with candidates who receive an offer of employment
The cost of submitting these checks will be covered by our client