Own and lead the insider risk program strategy, governance framework, and roadmap.
Define policies, standards, and procedures for insider risk management aligned with regulatory and organizational requirements.
Develop and report on KPIs and metrics to measure program effectiveness and maturity.
Lead the selection, assessment, and proof-of-concept (POC) for insider risk management tools (e.g., DLP, UEBA, SIM, CASB).
Architect and implement advanced insider risk detection and response capabilities leveraging behavioral analytics, machine learning, and automation.
Leverage AI-driven tools and automation to enhance efficiency, accuracy, and scalability of the insider risk management program.
Integrate insider risk monitoring with broader cybersecurity platforms and threat intelligence feeds.
Oversee day-to-day insider risk operations, ensuring timely detection, triage, and resolution of alerts.
Define and maintain high-risk user groups, implementing automation for dynamic updates.
Direct investigations into suspicious activities, ensuring proper documentation, evidence handling, and escalation.
Monitor insider risk users through IRM alerts, DLP alerts, UEBA alerts, and database activity monitoring (DAM) alerts.
Detect anomalous queries, unauthorized schema changes, or mass data exports, correlating database activity with user behavior analytics (UEBA).
Deploy DAM tools to track queries, changes, and access patterns; set alerts for suspicious activities like bulk data extraction or unusual query patterns.
Integrate DAM logs with SIEM for centralized monitoring.
Requirements
Bachelor in Computer Science or related field.
At least seven (7) years of information security and information risk experience.
Expertise in insider risk platforms and technologies: DLP, IRM, UEBA, SIEM, CASB, EDR
Strong knowledge of database security principles, encryption, and DAM tools
Proficiency in scripting and automation (Python, PowerShell) for alert enrichment and remediation workflows.
CISSP or similar certification is preferred.
Ability to work in a fast-paced environment with minimal guidance and supervision.
Ability to adapt to constantly changing technical, regulatory, and compliance environments.
Good verbal and written skills are important.
Experience working in a banking or financial services environment is an asset.
Ability to think out of the box for solutions to technical problems.
Benefits
Competitive discretionary bonus
Market leading RRSP match program
Medical, dental, vision, life, and disability benefits
Employee Share Purchase Plan
Maternity/Parental top-up while you care for your little one
Generous vacation policy and personal days
Virtual events to connect with your fellow colleagues
Annual professional development allowance and a comprehensive Career Development program
A fulfilling opportunity to join one of the top FinTechs and help create a new kind of banking experience
Product Security Expert in a hybrid role focusing on cybersecurity implementation for medical devices at Fresenius Medical Care in Germany. Collaborating with cross - functional teams to enhance product security.
Senior Penetration Tester defending fintech platform from payment fraud and cyber threats. Leading offensive security assessments to enhance fraud defenses and ensure customer trust.
Manager leading project management for large engagements at a top - ranked CPA and advisory firm. Focused on compliance automation and fostering client relationships.
Cyber Security SME ensuring the security and compliance of enterprise cloud applications. Collaborating across teams to achieve and maintain security authorization requirements.
Segment Risk Manager supporting the Cybersecurity segment with risk management and governance. Collaborating on risk assessments and providing advisory on standards and practices.
Penetration Testing Coordination Leader managing pre - testing activities and pipelines. Mentoring teams and ensuring timely execution of penetration tests in financial services context.
Sales Representative responsible for B2B IT - Security Consulting services. Focused on active sales, relationship management, and new business opportunities in cybersecurity.
Leading Cybersecurity Consulting initiatives and teams to drive client security strategies at Schönbrunn TASC GmbH. Ensuring the development of secure digital solutions and fostering client relationships.
Security Engineer focusing on detection and response and collaborating with teams to secure infrastructure at Semperis. Building security monitoring solutions and contributing to risk management.