Risk Detection

2 days ago


Singapore ByteDance Full time

Responsibilities
About the Company
Founded in 2012, ByteDance's mission is to inspire creativity and enrich life. With a suite of more than a dozen products, including TikTok as well as platforms specific to the China market, including Toutiao, Douyin, and Xigua, ByteDance has made it easier and more fun for people to connect with, consume, and create content.
Why Join Us
Creation is the core of ByteDance's purpose. Our products are built to help imaginations thrive. This is doubly true of the teams that make our innovations possible.
Together, we inspire creativity and enrich life - a mission we aim towards achieving every day.
To us, every challenge, no matter how ambiguous, is an opportunity; to learn, to innovate, and to grow as one team. Status quo? Never. Courage? Always.
At ByteDance, we create together and grow together. That's how we drive impact - for ourselves, our company, and the users we serve.
Join us.
About the Team
The Internal Threat Management team is responsible for managing and mitigating information security risks posed within the organisation. To ensure that the company's risk management and governance strategies are up to date and aligned across the organisation, this team is responsible for regular industry benchmarking and working with stakeholders from cross-functional teams to perform regular risk assessments and align risk mitigation strategies. This team is also responsible for managing the optimization, operation, training, and data analysis of the internal threat platform and UEBA (User and Entity Behavior Analytics) and DLP (Data Loss Prevention) platforms within the company.

**Responsibilities**:
**1. Internal Threat Risk Detection & DLP Rule Development**:

- Collaborate with cross-functional teams, including security operations, IT, HR, legal, and business units, to gather requirements for detecting and mitigating internal threats.
- Develop, implement, and fine-tune DLP rules and policies, aligned with risk appetite, regulatory compliance requirements and industry best practices, focused on preventing insider threats, including data exfiltration, unauthorized access, and policy violations.

**2. Monitoring & Identifying Internal Threats**:

- Use security monitoring tools (e.g., SIEM, UEBA, EDR) to detect suspicious activity and potential insider threats such as unauthorized access, privilege abuse, data leakage, and policy violations.
- Analyze user behavior patterns and identify anomalous activities that may indicate insider threats, including both malicious and negligent behaviors.

**3. Risk Assessment & Prioritization**:

- Assess the identified risks from internal threat detection tools and prioritize them based on business impact, severity, and organizational risk appetite.
- Perform regular risk assessments to ensure DLP rules and internal monitoring mechanisms remain aligned with evolving organizational risks, security posture, and compliance requirements.

**4. DLP Rule Maintenance, Tuning, and Enhancement**:

- Continuously monitor and evaluate the effectiveness of existing DLP policies and rules to minimize false positives and enhance detection accuracy.
- Adjust DLP policies and monitoring rules based on new threat intelligence, evolving internal threat tactics, and changes in business requirements.
- Stay updated with the latest trends in insider threats, industry best practices, and regulatory changes to ensure that DLP rules and internal monitoring strategies evolve accordingly.

**5. Collaboration & Stakeholder Communication**:

- Work closely with internal teams (e.g., HR, Security) to ensure that insider threat detection efforts are aligned with organizational policies, employee rights, and legal requirements.
- Engage with business stakeholders to understand their concerns, gather insights, and provide risk-related recommendations regarding insider threats.

**6. Reporting, Documentation & Continuous Improvement**:

- Document internal threat detection methodologies, DLP policies, and investigation findings to maintain a clear record of risk management activities and responses.
- Provide regular reports on DLP rule performance, internal threat trends, and the effectiveness of risk mitigation strategies to senior management and key stakeholders.
- Contribute to the creation and improvement of internal threat management playbooks, response plans, and risk mitigation strategies to ensure organizational resilience.

**Qualifications**:
Minimum Qualifications
- Bachelor's degree or above, with a preference for majors in Information Security, Computer Science, Information Technology, privacy, risk or a related field. Professional certifications such as CISSP, CISM, CRISC, or CGEIT are highly desirable.
- Minimum of 5 years of work experience, with at least 3 years of team management experience and a preference for experience in risk management and insider threat program
- Strong experience in data analysis and the ability to extract insights from complex r



  • Singapore Meta Full time

    **Detection Specialist, GRO Responsibilities**: - Support in the development and execution of the GRO Detection team strategy, operating model and objectives - Independently lead a functional area of the team including setting goals and coaching individuals assigned to that area - Proactively evaluate, plan and execute complex initiatives centered on the...


  • Singapore UBS AG Full time

    Roles & ResponsibilitiesYour role :Are you deeply motivated by the ever-evolving world of Cyber Security?Eager to take an active role in shaping the global UBS Cyber Defense environment?Do you thrive in a fast-paced environment where your skills make a tangible impact?If yes, then come and join us, as a SIEM Detection Analyst expert to • design, develop,...


  • Singapore Meta Full time

    **Global Response Operations - Detection Responsibilities**: - Drive the scoping & development of signals for key problem areas/abuses - Identify emerging risks using on-platform and off-platform signals, through monitoring & analysis - Conduct investigations to understand potential emerging trends and evolving risks in priority areas - Work...


  • Singapore FACEBOOK SINGAPORE PTE. LTD. Full time

    The Global Response Operations organisation within Global Operations responds to real-time crises, proactively identifies and evaluates emerging risks, conducts risk-related investigations, and assesses what we could be doing to best benefit our community. By understanding and consistently managing incidents and real-time crises to resolution, the...


  • Singapore Chevron Full time

    Chevron’s strategy is straightforward: be a leader in efficient and lower carbon production of traditional energy, in high demand today and for decades to come, while growing lower carbon businesses that will be a bigger part of the future. To achieve these goals, we’ll build on the assets, experience, capabilities, and relationships we’ve developed...

  • Technical Consultant

    2 weeks ago


    Singapore Risk Solutions Full time

    About the Business LexisNexis Risk Solutions is the essential partner in the assessment of risk. Within our Business Services vertical, we offer a multitude of solutions focused on helping businesses of all sizes drive higher revenue growth, maximize operational efficiencies, and improve customer experience. Our solutions help our customers solve difficult...


  • Singapore JPMorganChase Full time

    Embrace the challenge of maintaining robust digital security, driving operational excellence, and implementing cutting-edge solutions in cybersecurity. As a Security Operations Vice President in Cybersecurity & Tech Controls, you will contribute significantly to safeguarding the organization's digital assets and infrastructure by proactively detecting,...

  • Software Engineer

    4 days ago


    Singapore TikTok Full time

    Software Engineer (Security and Detection) - Global Security Organisation Overview TikTok's Global Security Organization (GSO) aims to build and earn trust by reducing risk and securing our businesses and products. The Insider Trust team focuses on detection, investigation, and response workflows. This role leads the detection engineering strategy to...


  • Singapore TikTok Full time

    Responsibilities Mitigate ongoing risks on TikTok Livestream by developing and implementing tactical strategies and methods to detect and enforce risky content at scale across entities; leveraging technical solutions such as SQL, Python, and machine learning. Investigate risky Livestreams and understand the abuse landscape; uncover key insights towards...

  • Technical Consultant

    2 weeks ago


    Singapore LexisNexis Risk Solutions Full time

    About the Business LexisNexis Risk Solutions is the essential partner in the assessment of risk. Within our Business Services vertical, we offer a multitude of solutions focused on helping businesses of all sizes drive higher revenue growth, maximize operational efficiencies, and improve customer experience. Our solutions help our customers solve difficult...