What are the 3-4 non-negotiable requirements of this position?
5+ years of experience with building or leading a Data Loss Prevention (DLP) program or team 5+ Experience developing DLP product and strategy roadmaps, including research, planning, and stakeholder engagement. 5+ Experience analyzing and tuning DLP signatures, rules, or use cases Experience writing and updating corporate policies and standards to reflect data protection and DLP strategy, requirements, and processes Experience with assessing and identifying gaps in security controls, processes, systems and providing recommendations Experience with security control design and configuration in cloud environments Experience identifying and selecting strategic options, and identifying resources to meet the defined objectives
What are the nice-to-have skills?
Experience with security control design and configuration in cloud environments Experience identifying and selecting strategic options, and identifying resources to meet the defined objectives Experience in the process of analyzing data to identify trends or relationships to inform conclusions about the data
Describe how this position fits in your organization.
SME overseeing DLP program
What is exciting about this opportunity? Please include team and company culture.
Senior level position that will oversee large scale security initiatives
Is there additional variable compensation?
Annual bonus
There is a possibility for sponsorship.
No
There is equity in this position.
No
Is relocation available?
No
Is this a new position, or a backfill?
Backfill
This position has direct reports.
No
Work hours are flexible.
Yes
Job req ID : REF12140V
Job description
The Information Security Technology - Engineering - Principal role will offer you the flexibility to make each day your own, while working alongside people who care so that you can deliver on the following responsibilities :
- Drive strategy and execution of Fannie Mae's Data Loss Prevention (DLP) Program in collaboration with a wide range of stakeholders.
- Provide DLP input on design and configuration of security controls across multiple capabilities including firewall, proxy, endpoint, and messaging.
- Assess and influence risk-based prioritizations for DLP and other security controls.
- Advise on and assist with security, data, and technology initiatives that impact the entire organization.
- Act as mentor and advisor to other senior colleagues in the Information Security Engineering and Operations practice area.
- Determine the needs of diverse and complex customer groups which requires applied understanding and resolution of complex or unusual business issues.
- Design and develop technical solutions across simultaneous projects or workstreams, which may include leading matrixed teams.
Qualifications
THE EXPERIENCE YOU BRING TO THE TEAM
Minimum Required Experiences
8 yearsDesired Experiences
Bachelor degree or equivalentCISSPSkills
5+ years of experience with building or leading a Data Loss Prevention (DLP) program or team5+ Experience developing DLP product and strategy roadmaps, including research, planning, and stakeholder engagement.5+ Experience analyzing and tuning DLP signatures, rules, or use casesExperience writing and updating corporate policies and standards to reflect data protection and DLP strategy, requirements, and processesExperience with assessing and identifying gaps in security controls, processes, systems and providing recommendationsExperience with security control design and configuration in cloud environmentsExperience identifying and selecting strategic options, and identifying resources to meet the defined objectivesExperience in the process of analyzing data to identify trends or relationships to inform conclusions about the dataExperience in thought leadership, training, workforce assessment, and workforce developmentExperience related to Relationship Management including managing and engaging stakeholders, customers, and vendors, building relationship networks, contracting, etc.Skilled in cloud technologies and cloud computingExperience related to Security including designing and evaluating security systems, identifying security threats, securing computers, assessing vulnerability, etc.Experience to Governance and Compliance including creating policies, evaluating compliance, conducting internal investigations, developing data governance, etc.Experience related to Influencing including negotiating, persuading others, facilitating meetings, and resolving conflict