Cyber Security – Data Protection (Senior) (Multiple Positions), Ernst & Young U.S. LLP, Hartford, CT.
As part of a team, assist clients with defining technical and business requirements for data protection solutions. Help design and implement data protection governance, processes and technology to identify and protect the data that is most impactful to the business from a financial, operational, regulatory or reputational perspective. Deliver new systems and improvements to existing systems customized to meet the clients’ data protection needs. Devise methods to add new functionality to the existing technologies to address new threats and tactics. Produce new playbooks as threats change and new data protection tools and controls emerge, and train the clients’ end users. Participate in client meetings to advise clients on multiple data protection products and solutions including enterprise data loss prevention, data classification, digital rights management, cloud data loss prevention / cloud access security brokers, tokenization, file and database encryption.
Provide technical guidance and share knowledge with team members with diverse skills and backgrounds. Consistently deliver quality client services focusing on more complex, judgmental and/or specialized issues. Demonstrate technical capabilities and professional knowledge. Learn about EY and its service lines and actively assess and present ways to apply knowledge and services.
Full time employment, Monday – Friday, 40 hours per week, 8:30 am – 5:30 pm.
MINIMUM REQUIREMENTS:
Bachelor's degree in Computer Engineering, Technology Management, Information Systems, Engineering, Business Administration or related, and at least 2 years of experience including the below:
Must have 2 years of experience in Cybersecurity concepts and methods, including vulnerability assessments, data classification, privacy assessments, incident response, security policy creation, enterprise security strategies, architectures and governance.
Must have 1 years of cumulative experience in any of the following:
– Networking (TCP/IP or OSI model), operating system fundamentals (Windows, UNIX, or mainframe), security technologies (firewalls or IDS/IPS) and application programming/scripting languages (C, Java, Perl, or Shell);
– Technical architecture experience integrating data protection software into clients' infrastructure; network architecture design, implementation and administration;
– Operating systems, virtual machine environments, mainframe security packages, and relational database management systems.
Must have one of the following:
– 2 years of experience in 2 of the following areas:
o Data leakage/content monitoring and filtering;
o Secure messaging/email encryption;
o Mobile device security;
o Disk, file, device, and database encryption;
o Key management/Public Key Infrastructure (PKI);
o Data classification, data tagging, data labeling, and privacy policies;
o Digital Rights Management (DRM);
o Logging, monitoring, and security event management;
o Secure information storage.
– 2 years of experience in one of the following regulatory requirements and/or compliance issues affecting clients related to privacy and data protection: PCI DSS, GLBA, Basel II, EU Data Protection Directive, International Cross Border and United States State Data Privacy Laws.
Alternatively, employer will accept Master's degree in Computer Engineering, Technology Management, Information Systems, Engineering, Business Administration or related, and at least 1 year of experience including the below:
Must have 1 year of experience in Cybersecurity concepts and methods, including vulnerability assessments, data classification, privacy assessments, incident response, security policy creation, enterprise security strategies, architectures and governance.
Must have 1 year of cumulative experience in any of the following:
– Networking (TCP/IP or OSI model), operating system fundamentals (Windows, UNIX, or mainframe), security technologies (firewalls or IDS/IPS) and application programming/scripting languages (C, Java, Perl, or Shell);
– Technical architecture experience integrating data protection software into clients' infrastructure; network architecture design, implementation and administration;
– Operating systems, virtual machine environments, mainframe security packages, and relational database management systems.
Must have one of the following:
– 1 year of experience in 2 of the following areas:
o Data leakage/content monitoring and filtering;
o Secure messaging/email encryption;
o Mobile device security;
o Disk, file, device, and database encryption;
o Key management/Public Key Infrastructure (PKI);
o Data classification, data tagging, data labeling, and privacy policies;
o Digital Rights Management (DRM);
o Logging, monitoring, and security event management;
o Secure information storage.
– 1 year of experience in one of the following regulatory requirements and/or compliance issues affecting clients related to privacy and data protection: PCI DSS, GLBA, Basel II, EU Data Protection Directive, International Cross Border and United States State Data Privacy Laws.
Travel required to meet client needs up to 80%, of which 10% may be international.
Employer will accept any suitable combination of education, experience, or training.
Please apply on-line at ey.com/en_us/careers and click on “Careers – Job Search”, then “Search Jobs” (Job Number – 1410400).
- Continuous learning: You’ll develop the mindset and skills to navigate whatever comes next.
- Success as defined by you: We’ll provide the tools and flexibility, so you can make a meaningful impact, your way.
- Transformative leadership: We’ll give you the insights, coaching and confidence to be the leader the world needs.
- Diverse and inclusive culture: You’ll be embraced for who you are and empowered to use your voice to help others find theirs.