Overview
On Site
Full Time
Skills
Information Security
Data Loss Prevention
Risk Management
Program Development
Policy Writing
Management
Collaboration
Inventory Management
Unstructured Data
Engineering Design
Incident Management
Analytics
Data Security
SaaS
Cloud Computing
Scripting
Python
Windows PowerShell
System Security
Optimization
DLP
Integrated Circuit
Internal Communications
IC
SAP BASIS
Job Details
The Lead Information Security Engineer will be the organization's subject matter expert (SME) for the Data Loss Prevention (DLP) and Insider Risk Management (IRM) programs. This role will be responsible for spearheading the design and implementation of enterprise level DLP and IRM strategies. This individual contributor role will be a member of a global engineering team that collaborates with various organizations and vendors to continually assess and improve the effectiveness of DLP and IRM controls and policies.
Key Responsibilities and Duties
Educational Requirements
Work Experience
Physical Requirements
Career Level
8IC
We are an Equal Opportunity Employer. TIAA does not discriminate against any candidate or employee on the basis of age, race, color, national origin, sex, religion, veteran status, disability, sexual orientation, gender identity, or any other legally protected status.
Read more about your rights and view government notices .
Key Responsibilities and Duties
- DLP Program Development: Lead the design and implementation of a cohesive DLP strategy, including data classification, policy creation, standards, and best practices to safeguard sensitive information.
- Data Classification and Labeling: Develop and manage data classification schemes and collaborate with data owners to ensure data is accurately labeled according to sensitivity and regulatory requirements.
- Data Discovery and Inventory Management: Use data discovery tools to locate unstructured data and catalog sensitive data across on-premises and cloud environments.
- Engineering design: architect and implement highly available and resilient solutions.
- Policy and Rule Configuration: Design, implement, and fine-tune DLP policies and detection rules to minimize false positives and optimize incident management.
- User and Entity Behavior Analytics (UEBA): Integrate user and entity behavior analytics with DLP tools to detect abnormal data access or potential insider threats, developing models to monitor deviations in sensitive data handling.
- Cloud and SaaS Data Protection: Develop DLP strategies for cloud services and SaaS applications to extend data visibility and control in cloud environments.
- Automation & Scripting: Leverage scripting languages (e.g., Python, PowerShell) to automate DLP processes, enhance security monitoring, and support the integration of DLP controls within existing systems. Security Controls Optimization: Identify and implement automation opportunities to improve the DLP program's efficiency in detecting and responding to security incidents.
Educational Requirements
- University (Degree) Preferred
Work Experience
- 5+ Years Required; 7+ Years Preferred
Physical Requirements
- Physical Requirements: Sedentary Work
Career Level
8IC
We are an Equal Opportunity Employer. TIAA does not discriminate against any candidate or employee on the basis of age, race, color, national origin, sex, religion, veteran status, disability, sexual orientation, gender identity, or any other legally protected status.
Read more about your rights and view government notices .
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.