Manager - Data Security
Discovery Communications
Sterling, VAThis was removed by the employer on 1/8/2020 9:32:00 AM PST
Not to worry we have many other jobs on the site;
Browse all jobs
Browse the IS/IT Category
Search for Manager - Data Security jobs in Sterling-VA
Search all Manager - Data Security postings
Full Time Job
The Role
The Data Security Manager is a technology and process focused security professional with an emphasis in information security, data discovery, data classification, data security/privacy compliance and remediation. The Manager will coordinate and oversee the data security compliance programs, including review, assess, recommend and implement policy and technical controls to ensure the Discovery’s Data Security program is effective.
Responsibilities
1. Collaborate with the InfoSec Department and Privacy Office in cataloguing applications and systems that fall into scope of privacy compliance programs such as General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA).
2. Respond to day-to-day requests from Data Security, Information Security Team, and the CISO such as advising on enterprise-wide initiatives
3. Monitor and analyze the results, trends, patterns, and events from Data Security and Privacy Compliance Tools (e.g., SAS, OneTrust, BigID, etc.) in addition to other tools (e.g., Splunk/QRadar) to enforce Data Privacy and Security requirements
4. Quality Assurance & Review for DPS and Data Compliance Deliverables (1st Level-Reviewer)
5. Assess the data security posture of systems through focused reviews with application owners, identify gaps to data protection safeguards, and areas for enhancements including encryption, anonymization and escalate to management's attention through timely reporting
6. Monitor the risk and compliance of data security safeguards through measurements and monitoring
7. Develop & Implement Data Flow Review (DFR) process for new and existing/critical business IT services
8. Provide data security requirements and guidance on secure software development and deployment
9. Evaluate, recommend, and implement data security solutions through open-source and COTS tools
10. Coordinate with business and IT teams, as a SME/InfoSec liaison, supporting data security initiatives
11. Identify, Assess, and Recommend Data Security and Privacy Enhancing Technologies (PET) software and tools
12. Enable continuous data security monitoring hygiene through managing the execution of security control assessments of applications and systems, through establishing a repeatable process
13. Work with the InfoSec Department and Privacy Office in socializing the data security control enhancements and developing remediation actions through coordination with business units
Requirements
* Bachelor’s or Master’s degree in related field, such as Business, IT, Computer Science or equivalent work experience
* 5 to 10 years of work experience in Data Protection, Information Security Dept. (e.g., Cyber SecOps, Security Architecture & Engineering, and/or Data Security/Forensic Analysis)
* Understanding of privacy compliance programs such as General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), Payment Card Industry Data Security Standard (PCI-DSS), etc.
* Strong working knowledge and experience with data security compliance, control design, and processes
* 4 years of professional experience, supporting Cybersecurity Operation program(s) using security solutions such as enterprise data loss prevention tools, data encryption technologies, SIEM, EDR, etc.
* Active learner - ability to enhance professional growth through new knowledge and experiences
* Excellent analytical, problem-solving, and interpersonal skills to interact with senior management
* Investigates, interprets, and responds to technical and/or complex IT security data
* Strong organizational, time management and diplomacy skills
* Demonstrated ability to be proactive, take ownership of and solve problems, and to deliver work products which are consistent with sound and ethical business practices
* Excellent communication skills, including the ability to present complex topics in clear, non-technical language; outstanding analytical, writing, and oral presentation skills
* Must have the legal right to work in the United States
Preferred Qualifications
* Desirable certifications include CISSP, CISM, CIPP, CIPT, CIPM, GCFE/GCFA, GCIH, CEH, OSCP, CHFI
* 2 years of data security or security architecture and engineering experience
* 1 years of security experience with cloud security environments
* Working knowledge with digital forensic tools such as Encase, SIFT Workstation, etc.
* Experience in leading and performing data privacy discussions, reviews, and IT/security audits
* Working knowledge and experience in developing and reporting performance and risk metrics (e.g., KPIs/KRIs – Status Reporting and Dashboard for senior management)
Sterling, Virginia, VA