- Collaborate with IT, identity management, endpoint security, legal, human resources and compliance teams to design pragmatic controls that reduce insider risk while supporting business priorities.
- Develop, implement and maintain Data Loss Prevention (DLP) and insider risk monitoring capabilities, translating scenarios and use cases into detection requirements, control requirements, response procedures and measurable risk indicators, with a focus on accidental data exposure, data exfiltration, policy violations, abuse of privileges and suspicious user behavior.
- Configure and tune controls related to insider risk, DLP and user activity monitoring using platforms such as Microsoft Purview, Microsoft Sentinel, Microsoft Defender for Endpoint and other similar tools.
- Support the full lifecycle of insider risk investigations, including alert triage, analysis, documentation and escalation of high-risk cases. This includes evidence collection, maintaining rigorous documentation, and participating in post-incident reviews.
- Develop dashboards, metrics and reports to communicate trends in insider risk, alert quality, control effectiveness, and progress of remediation efforts to security leadership.
- Contribute to awareness programs, guidelines and operational procedures aimed at reducing accidental insider risk and promoting secure handling of sensitive information.
Requirements
- Minimum of 3 years' experience in Data Loss Prevention (DLP), insider risk management, incident response, threat detection or a related field.
- Good understanding of Security Operations Center (SOC) operations, including alert triage, investigation processes, escalation mechanisms and security incident documentation.
- Experience with DLP solutions, insider risk management tools, endpoint detection, cloud security or user activity monitoring.
- Knowledge of sensitive data protection principles, including data classification, secure data handling, access governance, least privilege and data exfiltration risks.
- Ability to analyze logs, alerts, user behavior, file activity, access patterns and other telemetry to assess risk and recommend appropriate actions.
- Sound judgment in handling sensitive investigations, confidential information and employee-involved situations.
- Excellent written and verbal communication skills, with the ability to explain technical findings to both technical and non-technical audiences.
- Fluent in French and English, both written and spoken.
Core Competencies
Demonstrates expertise in Data Loss Prevention (DLP) and insider risk management, with a strong focus on incident response, threat detection, and the ability to analyze user behavior and telemetry. Proficient in configuring and tuning security controls while effectively communicating findings to diverse audiences.
Highest-signal resume keywords
- Data Loss Prevention (DLP)
- Insider Risk Management
- Incident Response
- Security Operations Center (SOC) Operations
- Fluent in French and English
ATS Optimization Keywords
Hard Skills
- Data Loss Prevention (DLP)
- Insider Risk Management
- Incident Response
- Threat Detection
- Log Analysis
- User Activity Monitoring
- Data Classification
- Access Governance
- Data Exfiltration Risks
- Security Incident Documentation
Soft Skills
- Excellent Written Communication
- Excellent Verbal Communication
- Sound Judgment
Industry Keywords
- Insider Risk
- Sensitive Data Protection
- Accidental Data Exposure
- Policy Violations
- Suspicious User Behavior
Tools & Technologies
- Microsoft Purview
- Microsoft Sentinel
- Microsoft Defender for Endpoint