Job Data Security/ Compliance

Sr Data Protection Security Engineer

Workday is looking for an experienced Security Engineer who has an ability to independently research and tackle technical issues and handle events. The main responsibility of the role will be to lead an enterprise Data Loss Prevention (DLP) solution - CASB, Email and Endpoint - with integrated tools and applications across an array of corporate environments.

 

About the Role

  • Lead the enterprise environment, including but not limited to configuring policies, anomaly detection and patching.
  • Supervise the use of DLP tools and ensure a consistent process of improvement is in place.
  • Build and maintain platform specific documentation.
  • Maintain DLP audit and compliance dashboards supporting continuous process improvement
  • Diagnose and analyze technical information from various source
  • Work with internal stakeholders and business partners to support various areas of DLP technology (troubleshooting, upgrades, etc.)
  • Collaborate with the business to identify critical, high value data (e.g. customer data, critical data, IP & source code) and ensure appropriate controls are in place to protect it.
  • Define, implement and support process and technology improvements related to preventing unauthorized disclosure, modification, removal or destruction of information.
  • Develop new rules and processes to enhance detection capabilities mitigating the risk of the insider threat and data loss.
  • Analyze and aggregate data to provide metric reporting in support of improvement/tuning of existing policies and resolve additional controls.
  • Investigate host, network and log-based security events.
  • Communicate security prevention related concepts to a broad variety of technical and non-technical staff at multi-organizational levels.
  • Bachelor's degree, or higher, in computer science or a related subject area with a minimum 5 years’ experience working in a Security Operations, or related, role.
  • Cloud Access Security Broker (CASB) implementation and/or management experience desirable.
  • Coding/Scripting experience (e.g. Python)
  • Experience deploying data protection solutions in the cloud, and on-premise.
  • Shown background in security engineering, data protection, data lifecycle management, or experience supporting these security-related solutions.
  • Demonstrated experience with creating regular expressions, encoding and encryption.
  • Experience with RESTful APIs and automation.
  • Experience identifying threats (IoCand TTPs), vulnerabilities, and exploitations.
  • Knowledge of cryptographic implementations at media, file, and application levels.
  • Strong problem solving with tried proactive correction capabilities
  • Ability to work independently, handle work to ensure quality and timely delivery.
  • Experience and/or certification in cyber forensics desirable.
  • CISSP, CISA, CEH, OSCP, GIAC, GSEC or other industry recognized security certification(s) preferred.
  • Experience in data analysis anomaly detection (e.g. UEBA) preferred