Insider Threat / Data Loss Prevention (DLP) technical investigator

State Street
United States
about 1 month ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$110,000.0 - $185,000.0
Working hours
Regular working hours
Job source

Tech stack

Data Analysis Antivirus Softwares Cyber Security Computer Forensics Information Leak Prevention Data Loss Factor Analysis Forensics Tools (Digital Forensics Software) Issue Tracking Systems Network Forensics Security Information and Event Management Cloud Platform System
+1 more
Data Classification

Job description

State Street seeks to recruit an Insider Threat / Data Loss Prevention (DLP) technical investigator responsible for the technical investigative function of responding to DLP incidents and insider threats at State Street. This team will work with the core Global Cyber Security teams, Global Security, Enterprise Continuity Services, and infrastructure teams to investigate, resolve, and recover from insider threat and DLP incidents. This position requires strong technical knowledge of forensics tools, SIEMs, system logs, analytic skills, creativity, quick reaction, interview experience, and technical expertise to protect the bank’s assets. Join us in evolving our insider threat and DLP response capabilities to shape a pro-active, threat intelligence driven fusion model to protect State Street, its customers and partners from sophisticated global threat actors.

What you will be responsible for

As Data Loss Prevention Technical Investigator you will

  • Review data loss prevention, insider threat, and other cyber events to ascertain policy violations
  • Determine data classification of sensitive documents flagged by the Data Loss Prevention tools
  • Build and maintain operating procedures for data loss events and cyber security events
  • Perform forensic analysis of endpoints as required
  • Conduct analysis of endpoint logs, network logs, cloud platform logs, and other relevant information in order to investigate suspected policy violations
  • Provide training, informational and educational materials to impacted employees
  • Conduct root cause and contributing factor analysis in order to understand why an incident occurred
  • Document interviews, write investigative reports, and handle evidence in accordance with organizational processes and procedures
  • Identify gaps in technical controls and develop strategies to remediate the gaps
  • Ensure that security plans, controls, processes, standards, policies and procedures are aligned with overall information security standards
  • Identify security risks and exposures, determine the causes of standard security violations and implement changes to halt future incidents and improve security.
  • Monitor and analyze system access logs to ensure ability to provide audit trails and incident investigation

Requirements

  • Strong understanding of endpoint, network, and system logs
  • Strong understanding of cloud forensic tools and technologies
  • Strong understanding of SIEM tools and how to use them to retrive and analyze data
  • Exceptional problem solving and analytical skills
  • Exceptional report writing skills
  • Knowledge of Endpoint Detection and Response and Anti Virus tools
  • Knowlegde of Data Loss Prevention tools
  • Knowledge and understanding of data organizing or structuring complex data across varied data sources
  • Strong organizational, multi-tasking, and prioritizing skills, * 5+ years of experience performing computer and network forensics demonstrated through work, military, or education
  • 5+ years of experience in production supporting, including problem identification, ticket documentation, and customer/vendor relations, demonstrated through work, military, or education
  • 5+ years of experience using ticket tracking tools for change management, problem and incident management, and availability management, demonstrated through work, military, or education
  • Certified Computer Forensic Examiner
  • Certified Computer Examiner
  • GIAC Network Forensic Analyst

Benefits & conditions

$110,000 - $185,000 Annual

The range quoted above applies to the role in the primary location specified. If the candidate would ultimately work outside of the primary location above, the applicable range could differ.

Employees are eligible to participate in State Street’s comprehensive benefits program, which includes: our retirement savings plan (401K) with company match; insurance coverage including basic life, medical, dental, vision, long-term disability, and other optional additional coverages; paid-time off including vacation, sick leave, short term disability, and family care responsibilities; access to our Employee Assistance Program; incentive compensation including eligibility for annual performance-based awards (excluding certain sales roles subject to sales incentive plans); and, eligibility for certain tax advantaged savings plans., We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you’ll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future.

About the company

Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Loading talks and stories from around this role…