Insider Threat Program Manager, Information Security
4 weeks ago
About the Company
Founded in 2012, ByteDance's mission is to inspire creativity and enrich life. With a suite of more than a dozen products, including TikTok as well as platforms specific to the China market, including Toutiao, Douyin, and Xigua, ByteDance has made it easier and more fun for people to connect with, consume, and create content.
Why Join Us
Creation is the core of ByteDance's purpose. Our products are built to help imaginations thrive. This is doubly true of the teams that make our innovations possible.
Together, we inspire creativity and enrich life - a mission we aim towards achieving every day.
To us, every challenge, no matter how ambiguous, is an opportunity; to learn, to innovate, and to grow as one team. Status quo? Never. Courage? Always.
At ByteDance, we create together and grow together. That's how we drive impact - for ourselves, our company, and the users we serve.
Join us.
About the Team
The Internal Security Risk Management & Governance team is responsible for managing and mitigating information security risks posed within the organisation. To ensure that the company's risk management and governance strategies are up to date and aligned across the organisation, this team is responsible for working with stakeholders from cross-functional teams to perform regular risk assessments, designing and implementing risk mitigation controls. This team is also responsible for managing the optimization, operation, training, and data analysis of the internal threat platform and UEBA (User and Entity Behavior Analytics) and DLP (Data Loss Prevention) platforms within the company.
Responsibilities
- Develop and maintain the organization's insider risk security governance framework, including risk scenario mapping to controls, policies, procedures, and standards that align with industry best practices and regulatory requirements. Such framework must be sufficiently detailed to allow ease of execution with clarity in roles and responsibility amongst stakeholders.
- Communicate the insider threat governance framework to key stakeholders and build effective collaboration models with stakeholders with clear roles and responsibilities, transparent tracking of metrics and seamless management reporting.
- Conduct regular security risk assessments to identify risk trends, vulnerabilities and alert patterns, and work with relevant departments to develop mitigation and remediation strategies.
- Monitor and report on the effectiveness of security controls and the status of security risks to senior management. Communicate risk assessment and trend analysis findings, risks and gaps to both technical and non-technical program stakeholders.
- Coordinate with IT and business units to ensure insider threat security measures are integrated into technology projects and business processes.
- Identify and garner the support of internal and external stakeholders to collaborate on driving change, including risk remediation and leading parties involved to meet risk remediation objectives.
- Translate business and technology requirements into relevant insider threat rules for operational teams to implement
- Stay abreast of the latest security trends, threats, and technologies to continuously improve the organization's insider threat security posture.
- Conduct analysis of large complex datasets involving insider risks, track metrics and identify gaps and vulnerabilities
- Understanding emerging insider risks to build and improve proactive threat detection.
Minimum Qualifications
1. Bachelor's degree or above, with a preference for majors in Information Security, Computer Science, Information Technology, privacy, risk or a related field. Professional certifications such as CISSP, CISM, CRISC, or CGEIT are highly desirable.
2. Minimum of 5 years of work experience, with a preference for experience in DLP (Data Loss Prevention), UEBA (User and Entity Behavior Analytics), or security platforms-related work.
3. Experience with security risk assessment methodologies and tools.
4. Skilled in creating and maintaining risk registers, developing risk treatment plans, and effectively communicating risk posture to stakeholders at all levels of the organization.
5. Self-driven and results-oriented, enjoys challenging tasks, demonstrates enthusiasm for work, and can handle job pressures.
6. Excellent communication and interpersonal skills, with the ability to engage and influence stakeholders at all levels.
7. Proven ability to manage and prioritize multiple projects and tasks.
Preferred Qualifications
- Hands on in-house experience with designing, implementation and operation of commercial or in-house UBA/UEBA solutions (e.g., Splunk, Exabeam) are highly desirable
- Experience with threat modeling methodologies (e.g., STRIDE, PASTA) to analyze and assess security threats within software applications, systems, and networks.
ByteDance is committed to creating an inclusive space where employees are valued for their skills, experiences, and unique perspectives. Our platform connects people from across the globe and so does our workplace. At ByteDance, our mission is to inspire creativity and enrich life. To achieve that goal, we are committed to celebrating our diverse voices and to creating an environment that reflects the many communities we reach. We are passionate about this and hope you are too.
Tell employers what skills you haveInformation Security
Security Governance
Remediation
Risk Assessment
Data Analysis
Treatment
ISO
Risk Management
Information Technology
ISO 27001
Trend Analysis
Regulatory Requirements
Loss Prevention
CISSP
Mapping
Threat Modeling
-
Singapore BYTEDANCE PTE. LTD. Full timeRoles & ResponsibilitiesAbout the Company Founded in 2012, ByteDance's mission is to inspire creativity and enrich life. With a suite of more than a dozen products, including TikTok as well as platforms specific to the China market, including Toutiao, Douyin, and Xigua, ByteDance has made it easier and more fun for people to connect with, consume, and create...
-
Insider Threat Lead
1 day ago
Singapore TikTok Full timeResponsibilities TikTok is the leading destination for short-form mobile video. At TikTok, our mission is to inspire creativity and bring joy. TikTok's global headquarters are in Los Angeles and Singapore, and its offices include New York, London, Dublin, Paris, Berlin, Dubai, Jakarta, Seoul, and Tokyo. Why Join Us Creation is the core of TikTok's purpose....
-
Information Security Threat Analyst
3 days ago
Singapore Citi Full time**Overview of the Organization:**Citi, a leading global bank, operates in over 160 countries and jurisdictions. The organization provides a wide range of financial products and services to consumers, corporations, governments, and institutions.The company's Enterprise Operations & Technology teams play a critical role in creating economic value that is...
-
Information Security engineer
1 week ago
Singapore CAREERALLY PTE. LTD. Full timeRoles & Responsibilities Attractive Bonuses Good career progression Near MRTJob Description:Responsible for threat intelligence, anomaly hunting, and digital forensics, analyzing data to identify threats and provide actionable intelligence. Conduct threat modeling, research on emerging threats, and forensic investigations while supporting incident response....
-
Information Security Analyst
10 hours ago
Singapore Hays Full timeInformation Security Analyst Hays Singapore is looking for an Information Security Analyst to perform threat hunting and to understand latest threats to improve overall the SOC operation. - Investigate and review computer intrusions, identification of new indicators of compromise (IOCs), and tactics, techniques, and procedures (TTPs) in support of threat...
-
Information Security Analyst
11 hours ago
Singapore Citi Full timeOverview of the Organization: Citi, the leading global bank, has approximately 200 million customer accounts and does business in more than 160 countries and jurisdictions. Citi provides consumers, corporations, governments, and institutions with a broad range of financial products and services, including consumer banking and credit, corporate and investment...
-
IT Threat Intelligence Specialist
4 weeks ago
Singapore CAREERALLY PTE. LTD. Full timeRoles & Responsibilities Good career progression Near MRT Family Friendly EnvironmentJob Description:Responsible for threat intelligence, anomaly hunting, and digital forensics, analyzing data to identify threats and provide actionable intelligence. Conduct threat modeling, research on emerging threats, and forensic investigations while supporting incident...
-
Deputy Director, Information Security
10 hours ago
Singapore Ensign InfoSecurity Full timeEnsign is hiring ! **Responsibilities**: - Development and implementation of security policies, standards and procedures - Drive Governance, Risk and Compliance processes, to automate and continuously monitor information security controls, exceptions, risks and testing. - Develop and implement frameworks for incident handling management, vulnerability...
-
Manager, Information Security Department
1 day ago
Singapore KRIS INFOTECH PTE. LTD. Full timeThe Manager of the Information Security Department is responsible for the organization's efforts to protect its information assets and ensure the security of its information systems. - This position requires a proactive approach to developing and implementing security policies, conducting security assessments, and responding to incidents. - The role involves...
-
Information Security Analyst
10 hours ago
Singapore DBS Bank Limited Full timeCompany OverviewDBS Bank Limited is a leading financial institution that enables and empowers its customers with innovative banking solutions. Our Group Technology department plays a vital role in delivering these solutions by managing the bank's operational processes and providing multiple banking delivery channels.Job DescriptionWe are seeking a dedicated...
-
IT Security Analyst
4 weeks ago
Singapore CAREERALLY PTE. LTD. Full timeRoles & Responsibilities Good career progression Near MRT Family Friendly EnvironmentJob Description:Responsible for threat intelligence, anomaly hunting, and digital forensics, analyzing data to identify threats and provide actionable intelligence. Conduct threat modeling, research on emerging threats, and forensic investigations while supporting incident...
-
Information Security Professional
2 days ago
Singapore DBS Bank Limited Full timeAbout This Role:We are looking for a highly skilled and experienced individual to join our Data Protection Program as a Data Protection Specialist. In this role, you will be responsible for analyzing and mitigating data loss risks within DBS Bank Limited.You will work closely with stakeholders to develop and refine DLP detection use cases, ensuring seamless...
-
Information Security Analyst
3 weeks ago
Singapore PROFICIO PTE. LTD. Full timeRoles & ResponsibilitiesDescriptionProficio is one of the fastest growing Managed Detection and Response (MDR) providers (formerly MSSP) in America, providing 24×7 security analysis and monitoring services to mid to large-sized enterprises. Our growth is being fueled by the rapid rise in cloud-based services, the acceptance of the Software-as-a-Service...
-
Staff Threat Hunter
10 hours ago
Singapore SENTINEL LABS PTE. LIMITED Full time**About Us**: SentinelOne is defining the future of cybersecurity through our XDR platform that automatically prevents, detects, and responds to threats in real-time. Singularity XDR ingests data and leverages our patented AI models to deliver autonomous protection. With SentinelOne, organizations gain full transparency into everything happening across the...
-
Customer Marketing Manager, APAC
2 days ago
Singapore Insider Full timeBefore jumping in on all the information about the role and what you can bring to the table, let us introduce ourselves real quick. About us We are Insider, a B2B SaaS company that drives growth for its clients around the world. We are the #1 AI-native platform for Customer Experience and Marketing—offering marketers a single platform to deliver unique...
-
IT Threat Intelligence Specialist
4 weeks ago
Singapore CAREERALLY PTE. LTD. Full timeRoles & Responsibilities☑ Good career progression☑ Near MRT☑ Family Friendly EnvironmentJob Description: Responsible for threat intelligence, anomaly hunting, and digital forensics, analyzing data to identify threats and provide actionable intelligence. Conduct threat modeling, research on emerging threats, and forensic investigations while...
-
IT Security Analyst
1 week ago
Singapore CAREERALLY PTE. LTD. Full timeRoles & Responsibilities Good career progression Near MRT Family Friendly EnvironmentJob Description:Responsible for threat intelligence, anomaly hunting, and digital forensics, analyzing data to identify threats and provide actionable intelligence. Conduct threat modeling, research on emerging threats, and forensic investigations while supporting incident...
-
Agency Chief Information Security Officer
3 weeks ago
Singapore ETHOS SEARCH ASSOCIATES PTE. LTD. Full timeRoles & ResponsibilitiesResponsibilitiesProduce cyber security strategies and work plan, policies, standards and guidelines Support digitalisation planning and aligning with ICT security strategy goals and policy baselines. Perform regular Gap analysis. Oversee ICT security matters (approving and tracking ICT security work plan and resourcing, monitoring...
-
Endpoint Security
1 day ago
Singapore Crypto.com Full timeWe are looking for an intermediate level security specialist to join our Global Cyber Fusion Center. The role will support our continuous threat monitoring, hunting & response capabilities; and be a key contributor to key endpoint security projects & initiatives. **Responsibilities**: - Threat Monitoring Investigations - deep dive into Tier 1 & Tier 2...
-
Cyber Security engineer
1 week ago
Singapore CAREERALLY PTE. LTD. Full timeRoles & Responsibilities Attractive Bonuses Good career progression Near MRTJob Description:Responsible for threat intelligence, anomaly hunting, and digital forensics, analyzing data to identify threats and provide actionable intelligence. Conduct threat modeling, research on emerging threats, and forensic investigations while supporting incident response....