Risk Detection

5 days ago


Singapore ByteDance Full time

Responsibilities
About the Company
Founded in 2012, ByteDance's mission is to inspire creativity and enrich life. With a suite of more than a dozen products, including TikTok as well as platforms specific to the China market, including Toutiao, Douyin, and Xigua, ByteDance has made it easier and more fun for people to connect with, consume, and create content.
Why Join Us
Creation is the core of ByteDance's purpose. Our products are built to help imaginations thrive. This is doubly true of the teams that make our innovations possible.
Together, we inspire creativity and enrich life - a mission we aim towards achieving every day.
To us, every challenge, no matter how ambiguous, is an opportunity; to learn, to innovate, and to grow as one team. Status quo? Never. Courage? Always.
At ByteDance, we create together and grow together. That's how we drive impact - for ourselves, our company, and the users we serve.
Join us.
About the Team
The Internal Threat Management team is responsible for managing and mitigating information security risks posed within the organisation. To ensure that the company's risk management and governance strategies are up to date and aligned across the organisation, this team is responsible for regular industry benchmarking and working with stakeholders from cross-functional teams to perform regular risk assessments and align risk mitigation strategies. This team is also responsible for managing the optimization, operation, training, and data analysis of the internal threat platform and UEBA (User and Entity Behavior Analytics) and DLP (Data Loss Prevention) platforms within the company.

**Responsibilities**:
**1. Internal Threat Risk Detection & DLP Rule Development**:

- Collaborate with cross-functional teams, including security operations, IT, HR, legal, and business units, to gather requirements for detecting and mitigating internal threats.
- Develop, implement, and fine-tune DLP rules and policies, aligned with risk appetite, regulatory compliance requirements and industry best practices, focused on preventing insider threats, including data exfiltration, unauthorized access, and policy violations.

**2. Monitoring & Identifying Internal Threats**:

- Use security monitoring tools (e.g., SIEM, UEBA, EDR) to detect suspicious activity and potential insider threats such as unauthorized access, privilege abuse, data leakage, and policy violations.
- Analyze user behavior patterns and identify anomalous activities that may indicate insider threats, including both malicious and negligent behaviors.

**3. Risk Assessment & Prioritization**:

- Assess the identified risks from internal threat detection tools and prioritize them based on business impact, severity, and organizational risk appetite.
- Perform regular risk assessments to ensure DLP rules and internal monitoring mechanisms remain aligned with evolving organizational risks, security posture, and compliance requirements.

**4. DLP Rule Maintenance, Tuning, and Enhancement**:

- Continuously monitor and evaluate the effectiveness of existing DLP policies and rules to minimize false positives and enhance detection accuracy.
- Adjust DLP policies and monitoring rules based on new threat intelligence, evolving internal threat tactics, and changes in business requirements.
- Stay updated with the latest trends in insider threats, industry best practices, and regulatory changes to ensure that DLP rules and internal monitoring strategies evolve accordingly.

**5. Collaboration & Stakeholder Communication**:

- Work closely with internal teams (e.g., HR, Security) to ensure that insider threat detection efforts are aligned with organizational policies, employee rights, and legal requirements.
- Engage with business stakeholders to understand their concerns, gather insights, and provide risk-related recommendations regarding insider threats.

**6. Reporting, Documentation & Continuous Improvement**:

- Document internal threat detection methodologies, DLP policies, and investigation findings to maintain a clear record of risk management activities and responses.
- Provide regular reports on DLP rule performance, internal threat trends, and the effectiveness of risk mitigation strategies to senior management and key stakeholders.
- Contribute to the creation and improvement of internal threat management playbooks, response plans, and risk mitigation strategies to ensure organizational resilience.

**Qualifications**:
Minimum Qualifications
- Bachelor's degree or above, with a preference for majors in Information Security, Computer Science, Information Technology, privacy, risk or a related field. Professional certifications such as CISSP, CISM, CRISC, or CGEIT are highly desirable.
- Minimum of 5 years of work experience, with at least 3 years of team management experience and a preference for experience in risk management and insider threat program
- Strong experience in data analysis and the ability to extract insights from complex r



  • Singapore Bank of America Full time $120,000 - $250,000 per year

    Job Description:At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.Being a Great Place to Work is core to how we drive Responsible Growth. This includes our...


  • Singapore Meta Full time

    **Global Response Operations - Detection Responsibilities**: - Drive the scoping & development of signals for key problem areas/abuses - Identify emerging risks using on-platform and off-platform signals, through monitoring & analysis - Conduct investigations to understand potential emerging trends and evolving risks in priority areas - Work...


  • Singapore Chevron Full time

    Chevron’s strategy is straightforward: be a leader in efficient and lower carbon production of traditional energy, in high demand today and for decades to come, while growing lower carbon businesses that will be a bigger part of the future. To achieve these goals, we’ll build on the assets, experience, capabilities, and relationships we’ve developed...


  • Singapore BitMEX Full time

    BitMEX is the world's leading cryptocurrency derivatives trading platform, which has pioneered cryptocurrency trading through relentless commitment to change, and continues to set benchmarks for innovation, liquidity, and security today. As the world's most advanced peer-to-peer crypto-products trading platform and API, BitMEX gives knowledge, confidence,...

  • Workplace Safety

    3 days ago


    Singapore JL CABLE DETECTION PTE. LTD. Full time

    **About JL Cable Detection**: We are a **growing company**in the **Underground Cable and Utilities Detection**industry, specializing in trial trenching and cable detection work. While we may not be a startup, we operate with the same **dynamic energy, flexibility, and growth mindset**—always looking for ways to improve and innovate. As we expand our...


  • Singapore Tonik Full time

    Anti-Fraud Operations Analyst/Officer (Detections)Join to apply for the Anti-Fraud Operations Analyst/Officer (Detections)role at Tonik Anti-Fraud Operations Analyst/Officer (Detections)Join to apply for the Anti-Fraud Operations Analyst/Officer (Detections)role at Tonik Philippines - Operations Apply for this position As an Anti-Fraud Operations Analyst,...


  • Singapore TD Full time

    Job Description Role and Responsibilities We are seeking an experienced and technically proficient Senior Information Security Analyst (L9) to join the Cyber Threat Detection (CTD) team. This role will focus on developing and tuning detection alerts for the Cyber Security Operations Center (CSOC), with a strong emphasis on engineering use cases, alert...


  • Singapore GIC Full time

    Overview GIC is one of the world's largest sovereign wealth funds. With over 2,000 employees across 11 locations, we invest in more than 40 countries across asset classes and businesses. Working at GIC provides exposure to a network of industry leaders. As a leading global long-term investor, we work at the point of impact for Singapore's financial future...


  • Singapore GIC Private Limited Full time

    Press Tab to Move to Skip to Content Link Select how often (in days) to receive an alert: Create Alert Associate/AVP, Threat Detection Analyst, COO's Office Location: Singapore, SG Job Function: Chief Operating Officer's Office Job Type: Permanent GIC is one of the world's largest sovereign wealth funds. With over 2,000 employees across 11 locations around...


  • Singapore MUFG Bank, Ltd., Singapore Office Full time

    **Do you want your voice heard and your actions to count?** Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG), one of the world’s leading financial groups. Across the globe, we’re 150,000 colleagues, striving to make a difference for every client, organization, and community we serve. We stand for our values, building long-term...