Data Security Lead

Other Jobs To Apply

No other job posts for this day.

About the position Responsibilities • Help establish and own Discount Tire Data Security Program. • Develop and lead the organization's data security strategy to ensure protection of sensitive, regulated, and proprietary data. • Implement data classification, data governance, and lifecycle management policies. • Ensure alignment with NIST CSF 2.0 and CIS TOP18 cybersecurity frameworks and data privacy regulations (CCPA and PCI DSS). • Plan and develop security measures to safeguard information against accidental or unauthorized modification, destruction, or disclosure. • Lead the deployment and management of Data Security tools (MS Purview, Cyera Omni DLP and Cyera DSPM), encryption, and tokenization solutions. • Monitor for data exfiltration, leakage, or unauthorized access across on-premises and cloud environments. • Partner with cloud security and infrastructure teams to ensure secure storage, transfer, and access to data. • Serve as the subject matter expert for data protection in support of internal and external audits. • Collaborate with compliance teams to maintain adherence to regulatory requirements and industry certifications. • Maintain records of data security incidents and oversee the investigation and remediation process. • Provide technical guidance and mentorship to cybersecurity analysts and engineers focusing on data security. • Partner with business units (Information Lifecycle Management - ILM) to integrate data security controls into projects and initiatives. • Conduct data security training and awareness sessions to reduce the risk of human error. • Performs other related responsibilities and special projects as assigned, which may include cross-functional initiatives, process improvements, or temporary assignments to support organizational goals and evolving business needs. • Architects, designs, implements, maintains and operates information system security controls and countermeasures. • Analyzes and recommends security controls and procedures in acquisition, development, and change management lifecycle of information systems, and monitors for compliance. • Analyzes and recommends security controls and procedures in business processes related to use of information systems and assets, and monitors for compliance. • Monitors information systems for security incidents and vulnerabilities; develops monitoring and visibility capabilities; reports on incidents, vulnerabilities, and trends. • Responds to information system security incidents, including investigation of, countermeasures to, and recovery from computer-based attacks, unauthorized access, and policy breaches; interacts and coordinates with third-party incident responders, including law enforcement. • Administers authentication and access controls, including provisioning, changes, and deprovisioning of user and system accounts, security/access roles, and access permissions to information assets. • Analyzes trends, news and changes in threat and compliance environment with respect to organizational risk; advises organization management and develops and executes plans for compliance and mitigation of risk; performs risk and compliance self-assessments and engages and coordinates third-party risk and compliance assessments. • Analyzes and develops information security governance, including organizational policies, procedures, standards, baselines and guidelines with respect to information security and use and operation of information systems. • Develops and administers, or provides advice, evaluation, and oversight for, information security training and awareness programs. • Coaches and mentors' level, I and II. • Other duties as assigned Requirements • This position requires a minimum of 5 years' experience in information security with a focus on data security or data protection. • Proven experience with DSPM and DLP, encryption technologies, data governance, and cloud security solutions. • Excellent communication and collaboration skills with the ability to influence technical and non-technical stakeholders. • Demonstrated ability to operate independently in a greenfield or rapidly maturing environment. • Proficiency with bolthires Purview, Cyera DSPM and Cyera Omni DLP (or similar). • Experience with cloud data security controls in AWS and Azure environments. • Strong understanding of data privacy regulations and compliance frameworks. • Strategic thinking with a risk-based approach to data protection. • Strong problem-solving and incident response capabilities. • Effective communication and ability to influence stakeholders at all levels. • Detail-oriented with excellent organizational skills. • This position requires a minimum of 5 years progressively responsible information technology experience. • Minimum of 5 years hands-on experience with security tools including, but not limited to, reverse proxies, intrusion prevention, malware detection, and vulnerability management. Corporate retail experience is preferred. • Proven expertise with any combination of the following: secure coding, threat modeling, identity management and authentication, cryptography, penetration testing, authentication and security protocols, system administration and network security is necessary. • An understanding of Web services and experience with multiple programming languages (such as, JSON, Java, C++, Ruby, Python, Perl, etc.) is preferred. Expert knowledge of TCP/IP, common protocols and standards is necessary. • Demonstrated experience analyzing large data sets and unstructured data for the purpose of identifying trends and anomalies indicative of malicious activity, as well as demonstrated capability to learn and develop new techniques is crucial. • Proven ability to manage productive relationships with vendors and internal stakeholders. Ability to proactively educate stakeholders on security best practices. Expert ability to communicate across all levels of IT, present complex ideas concisely and clearly articulate technical ideas both verbally and in writing is necessary. • Intermediate skills with bolthires office, including skills with Word, Excel, PowerPoint and Visio is necessary. • Ability to identify complex problems, review information to develop and evaluate options then recommend solutions is essential. • Expert collaboration, influencing and negotiation skills are required. • Able to work efficiently and accurately under pressure, meet deadlines, present a professional demeanor and work well independently is essential. • In addition, troubleshooting and organizational skills with a can-do attitude and the ability to adjust to changing requirements are essential • Superior customer service skills are essential including the ability to manage and respond to different customer situations while maintaining a positive and friendly attitude. • Maintaining confidentiality, treating others with respect and upholding Company values are key attributes. Nice-to-haves • Master's degree or MBA preferred. • Professional certifications are a plus. Preferred Certifications: CISSP, CISM, CCSP, or CDPSE (ISACA Data Privacy Solutions Engineer) • Corporate retail experience is preferred. Apply tot his job Apply tot his job Apply tot his job

Back to blog

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...