Capgemini logo
Capgemini

Get the Future You Want

Senior Information Security Analyst - DLP (Data Loss Prevention)

Security AnalystSecurity AnalystFull TimeRemoteSeniorTeam 10,001+Since 1967H1B SponsorCompany SiteLinkedIn

Location

Brazil

Posted

51 days ago

Salary

0

Seniority

Senior

No structured requirement data.

Job Description

Senior Information Security Analyst - DLP (Data Loss Prevention)

Capgemini

Role Description Você é apaixonado(a) por tecnologia, inovação e quer fazer parte de um ambiente inclusivo, colaborativo e em constante evolução? Então essa oportunidade é para você! Na Capgemini, valorizamos o equilíbrio entre vida pessoal e profissional. Por isso, oferecemos modelos de trabalho flexíveis. Nosso objetivo é proporcionar a melhor experiência para você, respeitando seu estilo de vida e promovendo bem-estar. Qualifications - Experiência com Prevenção de Vazamento de Dados (Data Loss Prevention – DLP) - Conhecimento em mapeamento de fluxos de dados e identificação de informações sensíveis - Capacidade de definir e implementar políticas de DLP alinhadas a normas de segurança da informação - Vivência na configuração, parametrização e administração de soluções DLP, como: - Microsoft Purview - Netskope (ou ferramentas equivalentes) - Experiência no monitoramento de alertas, análise de incidentes e ajuste de regras para redução de falsos positivos - Conhecimento em controles de acesso, classificação da informação e proteção de dados - Apoio a auditorias internas e externas, elaboração de relatórios e evidências de conformidade - Familiaridade com requisitos regulatórios e boas práticas de segurança da informação Requirements - Experiência prévia em ambientes corporativos de grande porte - Atuação em projetos de compliance, governança ou privacidade de dados - Conhecimento em frameworks e normas como LGPD, ISO 27001, SOC, PCI-DSS Benefits Na Capgemini, liberamos a energia humana por meio da tecnologia para construir um futuro mais inclusivo, sustentável e inovador. Se você compartilha desses valores, venha transformar o mundo com a gente!

Related Job Pages

More Security Analyst Jobs

Mastercard logo

Senior Security Monitoring and Response Analyst

Mastercard

Founded in 1966, Mastercard is a worldwide transaction, payment-processing, and consulting company best known for its line of personal and business credit cards. As an employer, Ma

Security Analyst52 days ago
Full TimeRemoteTeam 38,800Since 1966

Our Purpose Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we're helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential. Title and Summary Senior Security Monitoring and Response Analyst Who is Mastercard? Mastercard is a global technology company in the payments industry. Our mission is to connect and power an inclusive, digital economy that benefits everyone, everywhere by making transactions safe, simple, smart, and accessible. Using secure data and networks, partnerships and passion, our innovations and solutions help individuals, financial institutions, governments, and businesses realize their greatest potential. Our decency quotient, or DQ, drives our culture and everything we do inside and outside of our company. With connections across more than 210 countries and territories, we are building a sustainable world that unlocks priceless possibilities for all. Overview The Security Operations Center Incident Response (SOCIR) is a high-performance team responsible for security monitoring and response using advanced toolsets. The team is available 24/7 though a globally distributed operational team. The Security Monitoring and Response Senior Analyst is an integral member of the SOC's Incident Response team, providing direct support for security incidents and general security operations. • Do you want to be part of the team handling complex technical monitoring and response functions during a security incident?• Have you provided technical leadership or oversight to junior analysts?• Do you want to improve security operations through technical projects and data analysis? Core Skills: • Takes ownership of Incidents reported to the Incident Response Team end to end. • Performs technical analysis for security Incidents, including for cases of malware, web attacks, lateral movement, and other ad hoc issues as they arise. • Communicate INC updates and engage necessary stakeholders while responding to incidents • Maintain on-call hours to handle escalated events after hours and maintain the ability to provide rare emergency coverage in the SOC if needed. • Conduct After action review (AAR) sessions and share lesson learnt with stakeholders. • Lead and conduct threat hunting activities. • Understand and utilize scripting skills to automate investigation and analysis. Incident Response Process: • Understand NIST and other IR standards such as CIS, ISO/IEC 27305 and SANS • Able to implement IR Playbook in unknown situations and improve the playbook while acting with urgency on ongoing incident • Review existing playbooks and runbooks and make improvements and suggest changes • Develop new runbooks and identify automation scenarios Technology and Growth: • Identify and lead projects with the focus of making technological improvements to SOC operations. • Participate in SOC metric and reporting improvements • Mentor and coach SOC Tier 1 staff members to assist with improving operations and increasing their capabilities. • Master and become subject matter expert on key security concepts such as Cloud monitoring and response, Identify and Access Management, Malware and Forensics, Incident response and communications Requirements • Proven experience in a Security Operations Center (SOC) or Incident Response role• End-to-end ownership of security incidents, from detection through containment, resolution, and post-incident review• Strong technical investigation and analysis skills with hands-on experience investigating malware incidents, web attacks, lateral movement and suspicious network activity• Ability to work regular hours including on-call and after-hours incident escalation• Working knowledge of incident response frameworks and standards (e.g. NIST, SANS, CIS, ISO/IEC)• Experience using IR playbooks and runbooks during live incidents, including adapting them to unfamiliar scenarios• Solid understanding of core security concepts i.e. incident response and communications, malware analysis and digital forensics and Identity and Access Management (IAM)• Ability to clearly communicate incident status, risks, and actions to technical and non-technical stakeholders• Experience leading or contributing to After Action Reviews (AARs) and documenting lessons learned• Strong sense of ownership, urgency, and accountability during high-impact incidents Corporate Security Responsibility All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must: - Abide by Mastercard's security policies and practices; - Ensure the confidentiality and integrity of the information being accessed; - Report any suspected information security violation or breach, and - Complete all periodic mandatory security trainings in accordance with Mastercard's guidelines.

Australia
GuidePoint Security logo

Application Security Analyst- Remote (Anywhere in the U.S.)

GuidePoint Security

We help organizations make smarter cybersecurity decisions that minimize risk.

Security Analyst52 days ago
Full TimeRemoteTeam 201-500H1B Sponsor

GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. By taking a three-tiered, holistic approach for evaluating security posture and ecosystems, GuidePoint enables some of the nation’s top organizations, such as Fortune 500 companies and U.S. government agencies, to identify threats, optimize resources and integrate best-fit solutions that mitigate risk. GuidePoint Security offers an inclusive set of Application Security services, including Application Security Assessments for various application types (web, mobile, IoT, thick client), Threat Modeling, Source Code Reviews, Application Architecture Reviews, Application Security Program Management, Secure Development Training, and Secure SDLC Implementation. The Application Security Analyst joins GuidePoint’s elite team of Application Security experts to deliver the aforementioned services, which involves performing engagements, communicating with clients, delivering comprehensive reports, and providing thought leadership within the Application Security space. You will spend your time focusing on challenging projects and solving complex problems. Our clients will rely on your experience, adaptability, and creativity to protect their business applications and mature their Application Security capabilities. GuidePoint Security’s Application Security team's offerings consistently evolve with the security industry and risks that modern environments face. Role Requirements - Assist with the delivery of Application Security services, including but not limited to Application Security Assessments for various application types (web, mobile, IoT, thick client), Threat Modeling, Source Code Reviews, Application Architecture Reviews, Secure Development Training, and Secure SDLC Implementation - Assist with authoring assessment deliverables that are tailored to both technical and managerial audiences and fully detail the technical execution, core deficiencies, business impact, and realistic remediation strategies - Contribute to Application Security research projects - Contribute to marketing initiatives via activities such as research, speaking at industry conferences, authoring blog articles and whitepapers, webinars, and contributing to security tools - Utilize automation, orchestration, and scripting to reduce manual processes, improving overall efficiency while also enabling new capabilities to meet the rapidly changing needs of our clients - Perpetually strengthen relevant skills, knowledge, and abilities to stay at the forefront of the information security industry. - Foster client relationships by providing support and information - Maintain a strong desire to learn, adapt, and improve along with a rapidly-growing company - Perform other duties as assigned Education, Credentials, and Experience - Experience with testing tools such as Burp Suite, Postman, Netsparker, sqlmap, DirBuster, OpenSSL, etc. - Experience reviewing source code written in JavaScript, Python, Java, C++, PHP, or C#. - Internal operational DevSecOps experience is preferred. - InfoSec community involvement, such as conference speaking, blog/whitepaper authoring, and podcast speaking/producing experience, is strongly preferred. - Standard industry certifications are preferred. - Minimum of two (1) years of experience performing Application Security assessments or an understanding of Application Security assessments. - Minimum of one (1) year of experience in an enterprise-level consulting services role - Over four (4+) combined years of IT and information security experience are preferred. - Internal operational (non-consulting) experience is strongly preferred. We use Greenhouse Software as our applicant tracking system and Zoom Scheduler for HR screen request scheduling. At times, your email may block our communication with you. Please be sure to check your SPAM folder so that you don't miss updates on your application. Why GuidePoint? GuidePoint Security is a rapidly growing, profitable, privately-held value added reseller that focuses exclusively on Information Security. Since its inception in 2011, GuidePoint has grown to over 1,200 employees, established strategic partnerships with leading security vendors, and serves as a trusted advisor to more than 6,200 customers. Firmly-defined core values drive all aspects of the business, which have been paramount to the company’s success and establishment of an enjoyable workplace atmosphere. At GuidePoint, your colleagues are knowledgeable, skilled, and experienced and will seek to collaborate and provide mentorship and guidance at every opportunity. This is a unique and rare opportunity to grow your career along with one of the fastest growing companies in the nation. Some added perks…. - Remote workforce primarily (U.S. based only, some travel may be required for certain positions, working on-site may be required for Federal positions) - Group Medical Insurance options: Zero Deductible PPO Plan (GuidePoint pays 90% of the premium for employees and 70% for family plans (spouse/children/family) or High Deductible Health Plan with HSA (GuidePoint pays 100% of the employees premiums and 75% for family plans (spouse/children/family). If you choose the High Deductible / HSA plan, GPS will contribute in 4 equal quarterly installments: ($850 per EE annually / $1750 per family annually (includes spouse/children/family options) - Group Dental Insurance: GuidePoint pays 100% of the premium for employees and 75% of family plans - 12 corporate holidays and a Flexible Time Off (FTO) program - Healthy mobile phone and home internet allowance - Eligibility for retirement plan after 2 months at open enrollment - Pet Benefit Option

United States
Job Closed

Senior Cyber Security Analyst, Application & Infrastructure

iRhythm Technologies

Founded in 2006, iRhythm Technologies fuses healthcare with technology to positively impact people's lives. The company's platform, ZIO by iRhythm, enables phys

Security Analyst52 days ago

• Perform application security assessments across software products, cloud services, and supporting infrastructure. • Provide security input to threat models, including identification of risks, mitigations, and residual risk. • Plan, coordinate, and manage penetration testing activities, including scoping, execution, and remediation tracking. • Review, analyze, and interpret penetration test and vulnerability assessment results. • Partner with IT and engineering teams to validate findings, recommend mitigations, and track remediation to closure. • Support preparation of cybersecurity documentation for regulatory submissions, including FDA 510(k) filings and NIST requirements. • Apply NIST-based cybersecurity frameworks and guidance to application, infrastructure, and product security efforts. • Partner with the Product Security team to align application security practices with product risk management processes. • Contribute technical input to security artifacts such as threat models, vulnerability assessments, and cybersecurity risk documentation. • Collaborate with engineering, quality, and regulatory stakeholders to ensure security requirements are understood and addressed. • Contribute to continuous improvement of application security processes, standards, and documentation. • Assist in responding to internal and external security assessments, audits, and regulatory inquiries related to cybersecurity.

United States
$127K - $165K / year
Computer Task Group, Inc logo

Senior Mainframe Security Analyst

Computer Task Group, Inc

CTG, a Cegeka company, is at the forefront of digital transformation, providing IT and business solutions that accelerate project momentum and deliver desired value. Over nearly 60 years, we have earned a reputation as a faster and more reliable, results-driven partner. Our vision is to be an indispensable partner to our clients and the preferred career destination for digital and technology experts. CTG leverages the expertise of over 9,000 team members in 19 countries to provide innovative solutions. Together, we operate across the Americas, Europe, and India, working in close cooperation with over 3,000 clients in many of today's highest-growth industries. For more information, visit www.ctg.com . Our culture is a direct result of the people who work at CTG, the values we hold, and the actions we take. In other words, our people define our culture. It's a living, breathing thing that is renewed every day through the ways we engage with each other, our clients, and our communities. Part of our mission is to cultivate a workplace that attracts and develops the best people. CTG will consider for employment all qualified applicants including those with criminal histories in a manner consistent with the requirements of all applicable local, state, and federal laws. CTG is an Equal Opportunity Employer. CTG will assure equal opportunity and consideration to all applicants and employees in recruitment, selection, placement, training, benefits, compensation, promotion, transfer, and release of individuals without regard to race, creed, religion, color, national origin, sex, sexual orientation, gender identity and gender expression, age, disability, marital or veteran status, citizenship status, or any other discriminatory factors as required by law. CTG is fully committed to promoting employment opportunities for members of protected classes.

Security Analyst52 days ago
Full TimeRemoteTeam 5,001-10,000

CTG is seeking to fill a Senior Mainframe Security Analyst position for our client. Location: Remote (occasional travel to Raleigh, NC at client’s expense)Duration: 12 months Duties: - Maintain and enhance the security posture of the IBM System z mainframe environment, including installation and configuration of RACF, encryption, key management, and certificate management solutions - Remediate incidents, vulnerabilities, and service requests within established SLAs - Develop and maintain comprehensive reporting frameworks that reflect current security posture, policy alignment, project progress, and audit remediation status - Design and drive mainframe security initiatives based on risk assessments, security policies, and audit findings; collaborate cross-functionally to plan, test, and implement solutions - Translate complex technical security concepts into clear, consumable formats for IT leadership, business stakeholders, and audit teams - Lead and contribute to enterprise security discussions, including risk analysis, disaster recovery planning, training, and policy development/review - Support internal and external audits by preparing documentation, responding to inquiries, and addressing findings - Provide 24x7 production support for mainframe security-related issues as required Skills: - Deep expertise in IBM mainframe security, including RACF administration and architecture - Strong knowledge of z/OS, UNIX System Services (USS), z/Linux, Db2, and CICS security - Experience with IBM Trusted Key Entry (TKE) and enterprise encryption technologies - Proficiency in mainframe utilities and programming languages such as JCL, REXX, and CLIST - Solid understanding of Public Key Infrastructure (PKI), certificate lifecycle management, and encryption frameworks - Working knowledge of network security principles and client-server architectures - Strong analytical, problem-solving, and risk assessment capabilities - Excellent communication skills with the ability to present technical concepts clearly to diverse audiences - Ability to work independently while contributing effectively in a collaborative team environment Experience: - Minimum 5 years of experience in system architecture with a focus on information security and technology risk - Proven experience managing and securing IBM mainframe environments - Experience supporting audits and regulatory compliance initiatives - Demonstrated ability to work with minimal supervision and meet deadlines in a high-availability environment - Preferred: - 7+ years of experience in systems architecture focused on security - Experience with SailPoint identity governance integration - Experience with Venafi for certificate and key management - Experience mentoring and coaching junior technical staff - Professional certifications such as CISSP or CISA Education: - Bachelor’s degree or Associate’s degree in Computer Science, Information Systems, or a related field; or equivalent work experience - Preferred: CCUE Certification and 5 consecutive years of full-time SECU service Excellent verbal and written English communication skills and the ability to interact professionally with a diverse group are required. CTG does not accept unsolicited resumes from headhunters, recruitment agencies, or fee based recruitment services for this role. To Apply: To be considered, please apply directly to this requisition using the link provided. For additional information, please contact Malti Jha at Malti.Jha@ctg.com. Kindly forward this to any other interested parties. Thank you! The expected base salary for this position ranges from $56.00 to $65.00/hour. Salary offers are based on a wide range of factors including relevant skills, training, experience, education, market factors, and where applicable, licensure or certifications obtained. In addition to salary, a competitive benefit package is also offered. About CTG CTG, a Cegeka company, delivers IT and business solutions that enhance clients’ digital agility, empowering them to seize new opportunities and overcome any challenge. Backed by more than 60 years’ experience and a commitment to being a reliable, results-driven partner, we work shoulder to shoulder with clients to shape digital together. Our vision is to be an indispensable partner to our clients and the preferred career destination for digital and technology experts. With more than 9,000 team members in over 15 countries, we combine global expertise with local insight to deliver innovative solutions. We operate across the Americas, Europe, and India, working with over 3,000 clients in many of today's highest-growth industries. Together, we shape what’s next—working shoulder to shoulder to deliver impactful solutions for our clients and society. Our culture is built by the people who work at CTG, the values we hold, and the actions we take. It's a living, breathing thing that is renewed every day through the ways we engage with each other, our clients, and our communities. At CTG, you’ll find a workplace where you are encouraged to grow, supported in your ambitions, and empowered to shape your own career journey. For more information, visit www.ctg.com. CTG will consider for employment all qualified applicants including those with criminal histories in a manner consistent with the requirements of all applicable local, state, and federal laws. CTG is an Equal Opportunity Employer. CTG will assure equal opportunity and consideration to all applicants and employees in recruitment, selection, placement, training, benefits, compensation, promotion, transfer, and release of individuals without regard to race, creed, religion, color, national origin, sex, sexual orientation, gender identity and gender expression, age, disability, marital or veteran status, citizenship status, or any other discriminatory factors as required by law. CTG is fully committed to promoting employment opportunities for members of protected classes.

United States
$56 - $65 / hour