Data Security Analyst
As Discovery Inc’s portfolio continues to grow – around the world and across platforms – the Global Technology & Operations team is building media technology and IT systems that meet the world class standard for which Discovery is known. GT&O builds, implements and maintains the business systems and technology that are critical for delivering Discovery’s products, while articulating the long-term technology strategy that will enable Discovery’s growing pay-TV, digital terrestrial, free-to-air and online services to reach more audiences on more platforms.
Within our Information Security team, there has never been a busier or more urgent time to obtain the best talent we can for a function so critical to Discovery. In light of the constant threats and attacks occurring in companies across the globe, and across all industries, the Information Security Team at Discovery is a growing group of cyber security professionals, that are using the latest tools and resources to protect the assets from our internal infrastructure to the shows we broadcast across the globe on Discovery Channel, HGTV, Food Network, Animal Planet, Discovery ID, TLC, EuroSport and more. From the US to Singapore, India to LA, we are tasked with protecting, training, and implementing the best of the best in tools, resources, monitoring, threat detection, and more.
The Data Security Analyst will play a key role in supporting the activities related to managing and detecting/preventing the unauthorized retention, distribution, and use of Discovery’s data through the Data Security Program. The Data Security Analyst is a technology and process focused security professional with an emphasis in information security, data discovery, data classification, data security/privacy compliance and remediation. The Analyst will review, assess, recommend and implement policy and technical controls to ensure the Discovery’s Data Security program is effective.
1. Support data security initiatives across both InfoSec Department and Privacy Office
2. Respond to day-to-day requests from Data Security, Information Security Team, and the CISO such as advising on enterprise-wide initiatives
3. Design, implement, and support GDPR/CCPA compliance and data security controls for Discovery Global
4. Monitor and analyze the results, trends, patterns, and events from Data Security and Privacy Compliance Tools (e.g., SAS, OneTrust, BigID, etc.) in addition to other tools (e.g., Splunk/QRadar) to enforce Data Privacy and Security requirements
5. Proactively recognizes potential data security and compliance issues through reviews and analyses
6. Develop and maintain Data Flow Diagrams for new and critical business and IT processes and services
7. Perform periodic Data Discovery Scan and mapping for Critical Discovery Data (e.g., PCI, GDPR/CCPA, etc.) and work with data owners to identify gaps and propose solutions.
8. Develop and implement data security standard operating procedure (SOP) and enforce requirements.
9. Provide data security requirements and guidance on secure software development and deployment
10. Evaluate, recommend, and implement data security solutions through open-source and COTS tools
11. Coordinate with business and IT teams, as a SME/InfoSec liaison, supporting data security initiatives
12. Recommend, install, manage, and maintain (e.g., policy, rules, and tuning) Data Security/Privacy Tools (i.e., PET) when deployed and as appropriate
13. Assist with implementation of counter-measures or mitigating data security controls as necessary
* Bachelor’s degree from an accredited university in business or IT security related discipline
* 3+ years of progressive experience with increasing responsibilities within Information Security Dept. (e.g., Cyber SecOps, Security Architecture & Engineering, and/or Data Security/Forensic Analysis)
* An In-depth understanding of privacy compliance programs such as General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), Payment Card Industry Data Security Standard (PCI-DSS), etc.
* Strong working knowledge and experience with data security compliance, control design, and processes
* Expert-level knowledge of data security and privacy enhancing technologies and tools
* 2+ years of professional experience, supporting Cybersecurity Operation program(s) using security solutions such as enterprise data loss prevention tools, data encryption technologies, SIEM, EDR, etc.
* Must have a strong foundation of Network and Security skills, fundamental knowledge of Windows, Linux operating systems, networking protocols and network traffic analysis, etc.
* Independent tasking and project completion with little supervision is a must
* Excellent analytical and problem-solving skills as well as interpersonal skills to interact with users, team members and senior management
* Investigates, interprets, and responds to technical and/or complex IT security data
* Demonstrated ability to work within matrixed resources in a team environment. Possesses strong organizational, time management and diplomacy skills
* Working knowledge and experience in creating policies and technical documents (SOPs) as necessary
* Must have the legal right to work in the United States
* Desirable certifications include CIPP (US/E), CIPT, CIPM, CISSP, GCFE/GCFA, GCIH, CEH, OSCP, CHFI
* 2+ years of data security or security architecture and engineering experience
* 1+ years of security experience with cloud security environments
* Working knowledge with digital forensic tools such as Encase, SIFT Workstation, etc.
* Working knowledge and experience in leading and performing data security, data privacy discussions, reviews, and IT/security audits
* Working knowledge and experience in developing and reporting performance and risk metrics (e.g., KPIs/KRIs – Status Reporting and Dashboard for senior management)