Jobs and Careers
SY

VP, Insider Risk Management Leader

Synchrony
United Statesfull_timeVerifiedPosted 18 Jul 2024
💰 $170,000/yr

About the role

Job Description:

Role Summary/Purpose:

The Insider Risk Management Leader is responsible for leading efforts to identify and reduce cyber insider risks to Synchrony. The Leader sets the strategy, processes, and governance, for a team of analysts responsible for developing methodologies to identify and detect areas of insider risk and for the conduct of insider investigations supporting cross-business stakeholders including those in information security, physical security, Legal, and Human Resources. Additionally, the Leader is responsible for maintenance and execution of Synchrony’s eDiscovery capabilities and forensics activities supporting insider investigations and Legal requirements. The leader is a senior-practitioner, capable of effectively interacting with senior leaders across the company and motivated to mentor colleagues in Insider Risk and investigations tradecraft.

We’re proud to offer you choice and flexibility. At Synchrony, our way of working allows you to have the option to work from home, near one of our Hubs or come into one of our offices. Occasionally you may be required to commute to our nearest office for in person engagement activities such as business or team meetings, training and culture events.

Essential Responsibilities:

  • Oversee the end-to-end process of investigating data-loss-prevention (DLP) alerts and stakeholder provided cases requiring cyber-investigative support. The leader is responsible for proper intake, investigation (to include employee interviews as necessary), documentation, and provision of outcomes to stakeholders.

  • Oversee analysts responsible for DLP alert review, disposition, and escalation; aid in design of DLP alerting strategies.

  • Provide governance of Synchrony’s Insider Risk program, to include leadership of the Insider Risk Working Group and Steering Committee.

  • Interface with, and satisfy requirements from, senior stakeholders across the business who require Insider Risk Management support to include those in Legal (including Ombuds), Human Resources, Physical Security, and Information Security.

  • Advise on user and entity behavioral detection methods and use-cases for implementation by partner Cyber Operations teams.

  • Identify areas of insider risk and escalate identified risks through proper forums allowing for documentation and remediation.

  • Responsible for maintaining operational capability of eDiscovery and forensics platforms to ensure their availability and for responding to customer requests for eDiscovery and forensics support.

  • Provide expert counsel and specialized resources, in such areas as artifact collection and forensics, during cyber incident response activities.

  • Identify opportunities for process and capability improvements utilizing technology and automation. Levy formal and technically comprehensive requirements allowing for evaluation and execution.

  • Provide mentorship, training and oversight to direct reports, ensuring high-quality team deliverables and enabling career and technical growth of subordinates.

  • Advise on Cyber Operations budget.

  • Perform other duties and/or special projects as assigned.

Qualifications/Requirements:

  • Bachelor’s degree in Computer Engineering or related field, with a minimum of 7 years of experience in Information Technology or in lieu of Bachelor’s degree, High School diploma and 10 years of Information Technology experience

  • Prior experience conducting human interviews in person and over the phone.

  • Prior experience conducting or leading forensics investigations.

  • Prior experience developing executive-level presentations and speaking to large groups.

  • Highly analytical, detail-oriented, and strong problem solving with a common-sense approach to resolving problems.

  • For internal Synchrony applicants, a minimum of 18 months in company and 12 months in current role is a must. Employees in active CAP/PIP are not eligible to apply for the role. Employees with performance rating of CT or OC are only eligible.

Desired Characteristics:

  • One or more relevant security certifications (SANS GCIH, GCIA, GCFE, GCFA, or comparable)

  • Prior experience supporting investigations teams or law enforcement

  • Currently hold or have previously held a Security Clearance

  • Must have expertise and exposure in SOAR, DLP, UEBA, SIEM, and Forensics Tooling

  • Must have experience in performing forensics on on-prem systems and public cloud (e.g., AWS, Azure, GCP)

  • Strong interpersonal and critical thinking skills.

  • <

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Synchrony

View company profile →