Insider Threat Lead, Security Governance and Compliance

2 days ago


Singapore ByteDance Full time

Insider Threat Lead, Security Governance and Compliance
Insider Threat Lead, Security Governance and Compliance
2 days ago Be among the first 25 applicants
Responsibilities
About the Team
The Internal Threat Management team is responsible for managing and mitigating information security risks posed within the organisation. To ensure that the company's risk management and governance strategies are up to date and aligned across the organisation, this team is responsible for regular industry benchmarking and working with stakeholders from cross-functional teams to perform regular risk assessments and align risk mitigation strategies. This team is also responsible for managing the optimization, operation, training, and data analysis of the internal threat platform and UEBA (User and Entity Behavior Analytics) and DLP (Data Loss Prevention) platforms within the company.
Responsibilities

  • Maintain a robust risk governance framework that supports internal threat management, ensuring it is aligned with the organization’s overall risk management and compliance strategies.
  • Establish and manage processes for risk assessment, control testing, and risk mitigation related to internal threats, ensuring that these processes are effective and aligned with industry best practices.
  • Develop and define key risk metrics to assess the effectiveness of internal threat detection and mitigation strategies
  • Continuously monitor and analyze internal threat data, identifying emerging trends, patterns, and areas of concern related to insider threats
  • Develop and deliver regular risk reports for senior management, providing insights on the status and effectiveness of internal threat programs, key risk indicators, and threat trends.
  • Work closely with internal stakeholders to ensure that policies and procedures are properly followed and that risk management processes are integrated across departments.

Qualifications
Minimum Qualifications

  • Bachelor's degree or above, with a preference for majors in Information Security, Computer Science, Information Technology, privacy, risk or a related field. Professional certifications such as CISSP, CISM, CRISC, or CGEIT are highly desirable.
  • Minimum of 5 years of work experience, with at least 3 years of team management experience and a preference for experience in risk management and insider threat program.
  • Strong experience in data analysis and the ability to extract insights from complex risk data to identify patterns and trends. Expertise in developing dashboards and reports that clearly communicate complex risk data to senior management and non-technical stakeholders.
  • Proficient in risk governance frameworks and best practices for internal threat management, including risk assessments, control testing, and compliance.
  • Solid understanding of insider threat risks, including data exfiltration, privilege abuse, policy violations, and insider fraud.
  • Strong communication skills, with the ability to translate complex risk-related information into clear, actionable insights for diverse audiences.

Preferred Qualifications

  • Familiarity with regulatory requirements related to data protection and internal threat management (e.g., GDPR, CCPA, HIPAA).
  • Experience with designing, implementation and operation of commercial or in-house UBA/UEBA solutions (e.g., Splunk, Exabeam) are highly desirable
  • Experience with threat modeling methodologies (e.g., STRIDE, PASTA) to analyze and assess security threats within software applications, systems, and networks.

About Us
Founded in 2012, ByteDance's mission is to inspire creativity and enrich life. With a suite of more than a dozen products, including TikTok, Lemon8, CapCut and Pico as well as platforms specific to the China market, including Toutiao, Douyin, and Xigua, ByteDance has made it easier and more fun for people to connect with, consume, and create content.
Why Join ByteDance
Inspiring creativity is at the core of ByteDance's mission. Our innovative products are built to help people authentically express themselves, discover and connect – and our global, diverse teams make that possible. Together, we create value for our communities, inspire creativity and enrich life - a mission we work towards every day.
As ByteDancers, we strive to do great things with great people. We lead with curiosity, humility, and a desire to make impact in a rapidly growing tech company. By constantly iterating and fostering an "Always Day 1" mindset, we achieve meaningful breakthroughs for ourselves, our Company, and our users. When we create and grow together, the possibilities are limitless. Join us.
Diversity & Inclusion
ByteDance is committed to creating an inclusive space where employees are valued for their skills, experiences, and unique perspectives. Our platform connects people from across the globe and so does our workplace. At ByteDance, our mission is to inspire creativity and enrich life. To achieve that goal, we are committed to celebrating our diverse voices and to creating an environment that reflects the many communities we reach. We are passionate about this and hope you are too.
Seniority level
Seniority level Not Applicable
Employment type
Employment type Full-time
Job function
Job function Other, Information Technology, and Management
Industries Technology, Information and Internet
Referrals increase your chances of interviewing at ByteDance by 2x
Get notified about new Security Lead jobs in
Singapore, Singapore .
Client Information Security Lead/Senior Manager (Infra Enterprise)
Senior Executive / Assistant Manager / Manager, Security Policy & Governance
Regional Security Associate Manager - Disney Cruise Line
Cyber Security Operations (CSO) - Asia Cluster Governance Lead
Senior Manager, Client Info Security (Applications)
Senior Information Technology Security Officer
Global Information Security, Risk and Governance Manager
Regional Manager, Business Security & Governance
Senior Information Security Incident Response Lead
IT Risk, Compliance and Security Manager
Chief Information Security Officer - Fintech
Sr Customer Success Manager - Identity Security - APAC
TDI – Chief Security Office (CSO) - APAC - Threat Intelligence Regional Lead - Vice President
Assistant Manager / Manager (Security Operations)
VP, Cyber Security Program Manager, COO's Office
Security Operations Manager, Data Center
We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
#J-18808-Ljbffr



  • Singapore ByteDance Full time

    Insider Threat Lead, Security Governance and Compliance Insider Threat Lead, Security Governance and Compliance 2 days ago Be among the first 25 applicants Responsibilities About the Team The Internal Threat Management team is responsible for managing and mitigating information security risks posed within the organisation. To ensure that the company's risk...


  • Singapore ByteDance Full time

    Insider Threat Lead, Security Governance and Compliance Insider Threat Lead, Security Governance and Compliance 2 days ago Be among the first 25 applicants ResponsibilitiesAbout the TeamThe Internal Threat Management team is responsible for managing and mitigating information security risks posed within the organisation. To ensure that the company's risk...


  • Singapore ByteDance Full time

    Insider Threat Lead, Security Governance and Compliance Insider Threat Lead, Security Governance and Compliance 2 days ago Be among the first 25 applicants Responsibilities About the Team The Internal Threat Management team is responsible for managing and mitigating information security risks posed within the organisation. To ensure that the company's...


  • Singapore ByteDance Full time

    **Location**: Singapore **Team**: Security **Employment Type**: Regular **Job Code**: A81144 **Responsibilities**: About the Team The team is responsible for managing and mitigating information security risks posed within the organisation. To ensure that the company's risk management and governance strategies are up to date and aligned across the...


  • Singapore ByteDance Full time $80,000 - $120,000 per year

    Location:SingaporeTeam:SecurityEmployment Type:RegularJob Code:A81144ResponsibilitiesAbout the TeamThe team is responsible for managing and mitigating information security risks posed within the organisation. To ensure that the company's risk management and governance strategies are up to date and aligned across the organisation, this team is responsible for...


  • Singapore ByteDance Full time

    Location: Singapore Team: Security Employment Type: Regular Job Code: A81144 Responsibilities About the Team The team is responsible for managing and mitigating information security risks posed within the organisation. To ensure that the company's risk management and governance strategies are up to date and aligned across the organisation, this...


  • Singapore ByteDance Full time

    Responsibilities About the Company Founded in 2012, ByteDance's mission is to inspire creativity and enrich life. With a suite of more than a dozen products, including TikTok as well as platforms specific to the China market, including Toutiao, Douyin, and Xigua, ByteDance has made it easier and more fun for people to connect with, consume, and create...


  • Singapore beBeeSecurity Full time $90,000 - $120,000

    Inside Threat Security SpecialistWe are seeking a highly skilled and experienced Inside Threat Security Specialist to join our team. This role will be responsible for managing and mitigating information security risks posed within the organization.Responsibilities:Develop and implement a robust risk governance framework that supports internal threat...


  • Singapore UBS Full time

    Singapore - Information Technology (IT) - Group Functions **Job Reference #** - 267237BR **City** - Singapore **Job Type** - Full Time **Your role** - Are you a cybersecurity professional with hands on experience identifying Insider threats? Do you routinely work closely with business, legal, compliance, and technology stakeholders to investigate...


  • Singapore INCOME INSURANCE LIMITED Full time

    The insider threat analyst is responsible for researching, triaging, and investigating anomalous events of concern using Behavior Analytical tools, Splunk, and other tools to determine potential malicious or risky insider activity. This analyst role will come under the IT Risk and Security department reporting to the Security Operations Manager. **Key...