Insider Risk & Data Loss Prevention Specialist
TechnologieDescription
Your team’s dynamic:
Genetec is looking for an Insider Risk and Data Loss Prevention Specialist to join its Information Security team. This team works along with business and technical teams to protect Genetec, its employees, and its customers from the bad actors of the world. They monitor Genetec’s networks and systems, ensuring the security of assets by investigating and responding to potential incidents.
The Insider Risk and Data Loss Prevention Specialist will work within the Security Operations Center to help reduce the risk of accidental and malicious insider activity across the organization. This role will partner with Security, IT, Legal, HR, Compliance, and business stakeholders to design, implement, monitor, and continuously improve cybersecurity controls that protect sensitive information, intellectual property, and critical business systems.
Your day at a glance
- Partner with our IT, Identity, Endpoint, Legal, HR, and Compliance teams to design practical controls that reduce insider risk in line with business priorities.
- Develop, implement, and maintain DLP and insider risk monitoring capabilities by translating scenarios into detection use cases, control requirements, response playbooks, and measurable risk indicators, with a focus on accidental data exposure, data exfiltration, policy violations, privilege misuse, and suspicious user behaviour.
- Configure and tune insider risk, DLP, and user activity monitoring controls using platforms such as Microsoft Purview, Sentinel, Defender for Endpoint, etc..
- Support the end-to-end lifecycle of insider risk investigations, including alert triage, analysis, documentation, and escalation of high-risk cases. This includes evidence collection, rigorous documentation, and participation in post-incident analysis.
- Develop dashboards, metrics, and reports to communicate trends in insider risk, alert quality, control effectiveness, and progress on remediation measures to security leadership.
- Contribute to the development of awareness programs, guidelines, and operational procedures to reduce accidental insider risk and promote secure handling of sensitive information.
What makes you an excellent candidate
- Minimum of 3 years of experience in Data Loss Prevention (DLP), Insider Risk Management, Incident Response, Threat Detection, or a related field.
- Strong understanding of the operations of a Security Operations Center (SOC), including alert triage, investigation processes, escalation mechanisms, and incident documentation.
- Experience with DLP solutions, Insider Risk Management, Endpoint Detection and Response (EDR), Cloud Security, or User Activity Monitoring tools.
- Knowledge of sensitive data protection principles, including data classification, secure data handling, access governance, the principle of least privilege, and data exfiltration risks.
- Ability to analyze logs, alerts, user behavior, file activities, access patterns, and other telemetry data to assess risks and recommend appropriate actions.
- Strong judgment in handling sensitive investigations, confidential information, and situations involving employees.
- Excellent written and verbal communication skills, with the ability to communicate technical results to both technical and non-technical audiences.
- Proficiency in both French and English, both spoken and written (this role requires interactions with our international colleagues and clients).
A plus if you have
- Hands-on experience with Microsoft Purview Insider Risk Management, Microsoft Purview Data Loss Prevention, Microsoft Defender XDR, Microsoft Entra ID, or other Microsoft security and compliance solutions.
- Ability to conduct live investigations on endpoints, including identifying and collecting key forensic artifacts, as well as offline analysis and remediation activities when required.
- Experience in creating detection rules, correlation queries, dashboards, automated playbooks, or investigation workflows on SIEM or SOAR platforms.
- Understanding of Role-Based Access Control (RBAC), audit logging, pseudonymization, and appropriate separation of duties within an Insider Risk Management program.
- Familiarity with common insider risk scenarios, including accidental information sharing, employee turnover risks, unusual downloads, external sharing, use of personal cloud storage, removable media use, and privilege misuse.
- Knowledge of security frameworks, regulatory requirements, and standards related to incident response, data protection, privacy, and information security.
Here’s what we offer!
- Competitive compensation package
- Tuition reimbursement program
- Flexible work schedule for a healthy work-life balance
- Subsidized meals at our amazing Bistro (Les Cordons Bleus)
- Free coffee and fruits
- Free parking for all employees
- Access to relaxation spaces (billiards, gaming consoles, foosball, chess, etc.)
- On-site fitness center with personal trainers, as well as several health and wellness workshops
If you want to see what our workplace looks like, here’s the link to our company video: https://youtu.be/EupvfTWhRww?si=OuODVl0xkIFqdPZA
We know that the diversity of our team members’ backgrounds and experiences brings great value to our organization. Even if you don’t check all the boxes, we encourage you to apply – your profile might surprise us!
*Thank you for your application, but please note that only selected candidates will be contacted. Headhunters and recruitment agencies are not allowed to submit resumes through this website or directly to managers.
Cette offre a été agrégée depuis indeed. Groupe Sentinella n'est pas l'employeur; postuler vous redirige vers le site original. Le texte intégral appartient à l'auteur de l'offre.
Envie qu'on travaille pour vous ?
Inscrivez-vous au banc de talents Sentinella. On vous contacte dès qu'un mandat correspond à votre profil — y compris des postes comme celui-ci.
Rejoindre le banc de talents