
Senior Manager, Data Protection and Insider Risk
Posted 3 days ago

Posted 3 days ago
This is a fully remote position, open to applicants in United States.
• Develop and implement the strategy, operating model, and roadmap for Data Protection and Insider Risk.
• Assemble and manage a high-performing global team comprising employees, contractors, and service providers.
• Oversee the lifecycle of enterprise DLP controls across various channels including endpoint, email, web, cloud, SaaS, and collaboration tools.
• Establish and enhance the Insider Risk Program, which encompasses governance, risk scenarios, detection use cases, triage, investigations, escalation procedures, and response playbooks.
• Collaborate with business data owners to identify critical information, establish protection requirements, validate control intent, implement exceptions, and drive remediation efforts.
• Lead investigations regarding insider risk and data protection, focusing on suspected data misuse, exfiltration, control violations, and high-risk departures.
• Supervise the integration and optimization of technologies related to data protection and insider risk, including telemetry and analytics.
• Propel automation, analytics, and AI-driven capabilities to enhance alert quality, prioritization, investigations, control tuning, and response mechanisms.
• Define and report on KPIs and KRIs that assess control coverage, effectiveness, violations, exceptions, investigations, alert quality, program maturity, and risk mitigation.
• Maintain program governance, operational procedures, defensible investigative practices, evidence management, privacy obligations, and consistent decision-making protocols.
• Work collaboratively with Information Security, Privacy, Legal, HR, IT, Global Security, and business data owners.
• Bachelor's or Master's degree in Computer Science, Cybersecurity, Information Technology, Engineering, Risk Management, or a related field, or equivalent professional experience.
• Over 10 years of experience in cybersecurity, data security, risk management, investigations, or related areas.
• At least 5 years dedicated to data protection, DLP, or insider risk initiatives.
• Demonstrated success in building, transforming, or scaling enterprise Data Protection, DLP, or Insider Risk programs within complex global settings.
• Strong familiarity with enterprise DLP controls across endpoint, email, web, cloud, SaaS, and collaboration environments.
• Experience with enterprise DLP and insider risk platforms such as Netskope, Microsoft Purview, or similar technologies.
• Proficiency in user activity, behavioral, identity, endpoint, and other relevant telemetry.
• Background in leading sensitive investigations and collaborating with HR, Legal, Privacy, GRC, Global Security, business leaders, and technical teams.
• Comprehensive knowledge of privacy, legal, regulatory, and ethical considerations relevant to employee monitoring, sensitive data handling, and insider risk programs.
• Experience utilizing automation, analytics, or AI to enhance data protection and insider risk operations.
• Preferred certifications include CISSP, CISM, CIPP, GIAC, CERT Insider Threat credentials, or other relevant certifications.
• Typically requires a Bachelor's degree in a technical field along with 13+ years of industry experience.
• 5–8 years of prior experience in people management.
• Travel requirement of 5–15%.
• Position requires working from a home office; location must be within the United States.
• Comprehensive medical, dental, and vision coverage.
• Participation in wellness programs.
• Performance-based incentives.
• Opportunities for career advancement.
• Flexible work arrangements.
• Unlimited paid time off.
• Access to in-house training and development programs.
• Career mentorship opportunities.
• Chances to attend security conferences.
• Commitment to an inclusive and diverse work environment.
• Engaging purpose-driven mission and community connections.
Consertus
Cartpanda
Syneos Health
Ardent
Get handpicked remote jobs straight to your inbox weekly.