Insider Threat lead
Role details
Job location
Tech stack
Job description
ING is seeking an Insider Risk Program Lead to oversee and drive the success of ING's Insider Risk Management Program. This role will provide leadership, ensure high-quality policy, process, workflow, investigative, and analytical deliverables, and serve as the primary referent for the Bank's program. The ideal candidate will have a strong background in insider risk technologies (especially analytic technologies such as UEBA systems and data protection controls), processes, regulatory standards, investigations, cybersecurity, and team management, with the ability to effectively collaborate with stakeholders across multiple functions. The ideal candidate will also have leadership experience in a European Global Systemically Important Financial Institution, having served in a cybersecurity, enterprise security, or financial crimes/fraud management role. Roles and responsibilities
- Lead and manage a team of insider risk professionals across multiple geographies, ensuring all deliverables meet Firm expectations of quality and industry best practices.
- Lead development, coordination, socialization, and implementation of an enterprise operating model with supporting policies, processes, technology integration, and workflows for preventing, detecting, investigating, and mitigating insider risks.
- Lead development and implementation of insider risk technology platforms, especially but not limited to design and deployment of a UEBA platform.
- Recommend metrics, KPIs and report enhancements to measure the effectiveness of the program.
- Coordinate and support complex insider threat investigations, providing high-level guidance and analysis.
- Ensure insider threat detection, analysis, and mitigation strategies align with the Firm's overall security and compliance objectives.
- Act as the Program's primary representative within the Firm, maintaining strong relationships and collaboration with key stakeholders.
- Coordinate efforts with the Firm's cybersecurity, security, HR, legal, compliance, threat management and risk management teams, to develop proactive insider threat prevention and detection strategies.
- Liaise with law enforcement personnel when needed
- Continuously assess and enhance insider risk methodologies, workflows, and technologies to optimize effectiveness.
- Provide regular high-quality briefings, reports, and recommendations to senior leadership and key stakeholders.
- Maintain strict confidentiality and professionalism in all operational and advisory activities.
Requirements
We hire smart people like you for your potential. Our biggest expectation is that you'll stay curious. Keep learning. Take on responsibility. In return, we'll back you to develop into an even more awesome version of yourself.
- Bachelor's degree in a related field.
- 10+ years of experience in cyber and information security, with extensive hands-on experience in insider threat, incident response, threat hunting, and/or forensic analysis.
- 3+ years of demonstrated experience in leading an insider risk program and responding to sophisticated threats.
- Proven leadership experience, with the ability to manage and develop a team in a fast-paced environment.
- Experience and knowledge of the European financial services regulatory environment.
- Proven track record in developing insider threat detection strategies, writing detection signatures, or enhancing SOC processes.
- Strong understanding of cybersecurity principles, network security, digital forensics, and behavioral analytics.
- Expertise in insider threat detection technologies such as UEBA, SIEM, and DLP.
- Demonstrated ability to lead and conduct high-level investigations, including evidence collection, forensic analysis, investigatory interviews, and stakeholder reporting.
- Excellent written and oral communication and interpersonal skills, with the ability to engage effectively with senior leadership and cross-functional teams., * 5+ years of experience in a global systemically important financial institution.
- Advanced industry certifications, such as GCIA, GCIH, GCFA, CISSP, or equivalent.
- Experience leading efforts to combat fraud, theft and sabotage in a highly regulated environment.
Benefits & conditions
Rewards and benefits We want to make sure that it's possible for you to strike the right balance between your career and your private life. The benefits of working with us at ING include:
- 25-28 vacation days depending on contract
- Pension scheme
- 13th month salary
- 8% Holiday payment
- Hybrid working
- Personal growth and challenging work with endless possibilities
- An informal working environment with innovative colleagues