DLP analyst -Data Protection and Application Security
Experience 5+Years
Location Qatar
Duration 1Yr Contract
Job overview The Data Protection and Application Security Analyst will be vital in safeguarding the company's data and applications, both at endpoints and within cloud environments. The role ensures security and privacy compliance of data across various platforms and applications, including SaaS-based solutions. This includes engaging in security assurance activities throughout the application development lifecycle or deployment, embedding best practices for both security and data privacy. This role requires staying updated with data privacy trends and legislation, ensuring our systems and policies meet the highest data protection standards. Key Roles & Responsibilities Technical 1. Data Protection and Privacy:
- Data Sensitivity Management: Spearhead initiatives for identifying & classifying data, and applying appropriate controls based on data sensitivity.
- Data Loss Prevention: Implement and manage technologies like Proofpoint, devising strategies to safeguard against breaches.
- Insider Threat Mitigation: Actively manage internal threats to detect and reduce organizational risks.
- Policy implementation and Enforcement: Entrusted with implementing and upholding robust data security policies and standards throughout the company.
- Utilize Advanced Technical Measures: Implement a range of technical controls including encryption and masking, to safeguard sensitive data, ensuring robust protection against unauthorized access and data breacheds. 2. Incident Response:
- Incident Management: Lead incident response planning and execution, ensuring effective handling of data breaches.
- Cross-Functional Collaboration: Work with various teams to mitigate the impact of security incidents. 3. Data Privacy and Compliance:
- Comprehensive Privacy Assessments: Lead Privacy Impact Assessments to ensure compliance with data protection laws, analyzing how personal information is managed and mitigating potential risks.
- Policy Implementation and Vigilance: Enforce and regularly update data privacy policies across the organization, aligning with evolving legal standards and organizational needs.
- Monitoring and Training: Implement continuous monitoring and auditing processes to assess privacy controls, coupled with employee training programs to foster a culture of data privacy awareness.
- Cross-Functional Collaboration: Collaborate with various departments and engage with regulatory bodies to stay abreast of new regulations and integrate industry best practices into the organization's privacy program. 4. Application Security:
- Secure Development Advocacy: Lead the adoption of secure coding practices to prevent application-level threats, integrating security from the outset of the software development lifecycle.
- Vulnerability Oversight: Conduct targeted testing and code reviews to uncover and fix vulnerabilities efficiently, using both automated tools and manual inspections.
- Security Throughout SDLC: Embed security measures at every SDLC stage, ensuring security is a core component of software development and deployment.
- Assured Secure Rollouts: Ensure robust security processes for new software rollouts and updates. 5. Cloud and SaaS Security Management
- Cloud Security: Develop and implement security measures for safeguarding data across all cloud environments, including IaaS, PaaS and SaaS models.
- SaaS Security Oversight: Ensure that all SaaS applications comply with established security policies, and work closely with vendors to maintain high security standards
- Security and Risk Management: Conduct regular reviews and risk assessments for cloud and SaaS environments, adapting to emerging threats and technological changes to continuously protect organizational data. Assignments: 1. Strategic Cybersecurity Projects: Engage in key projects, leveraging expertise to enhance the company's cybersecurity. 2. Special Assignments: Undertake unique tasks to continually advance the cybersecurity strategy and roadmap. Communication 1. Internal Communication:
- Senior Cybersecurity Manager
- IT Department
- Business stakeholders Purpose:
- To investigate and to handle data breach and related cyber incidents.
- To ensure the effective implementation of cybersecurity strategies and policies.
- To deliver data protection and data privacy program and associated activities
- To manage and coordinate application related security engagements 2. External Communication:
- Vendors and Security Solution Providers
- National Cyber Security Agency
- Regulatory Bodies Purpose:
- Keep abreast of new security technologies and practices through engagement with external experts.
- Stay aligned with cybersecurity laws and regulations, liaising with relevant agencies and bodies. Minimum Qualification/Experiences/Skills Education & Professional Qualification:
- Minimum Bachelor's degree in Cybersecurity, Computer Science, Information Technology, computer engineering, or related field.
- Professional certifications in data protection and application security (e.g., CISSP, CISM) are preferred. Professional Experience: At least 5 years of experience in a cybersecurity role with a focus on data protection and application security. Geographic Experience: Experience in Middle East is preferred Computer Skills: Proficient in using cybersecurity and analytic tools, MS Office suite, and other relevant software. Language Skills: Fluent English (must have) Arabic (good to have) Market/Industry/Functional Knowledge: Solid understanding of the cybersecurity landscape, particularly in data protection and application security. Knowledge of the Offshore industry and related cybersecurity challenges is an asset Skills: application security,application,saas security,security assurance,cloud security,data protection,policy implementation,privacy compliance,insider threat mitigation,management,strategic cybersecurity projects,protection,incident management,cloud,privacy assessments,data sensitivity management,saas,data loss prevention,security,cybersecurity,data privacy,data