アラートの作成
似たような求人をメールで送る

EY - Cybersecurity - Data Protection and Information Protection - Manager

At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all.

EY – Cybersecurity Manager, Data Protection & Information Protection

Overview

As a Manager in EY’s Cybersecurity practice, you will play a key role in delivering Data Protection, Information Governance, and Insider Risk Management services across multiple client environments. We are seeking cybersecurity professionals with expertise in enterprise Data Loss Prevention and Information Protection platforms, including Microsoft Purview, Forcepoint DLP, or equivalent technologies, covering data classification and sensitivity labelling capabilities.

The role involves implementing, administering, and optimizing enterprise data protection controls to safeguard sensitive information across endpoints, email, collaboration platforms, cloud services, and business applications. The successful candidate will work closely with business, compliance, legal, and security teams to support data governance, regulatory compliance, and information protection initiatives.

The Opportunity

We are seeking cybersecurity professionals with 12+ years of experience in Data Protection, Data Loss Prevention, Information Protection, Compliance, Data Governance, or Cybersecurity Consulting.

The ideal candidate will possess strong technical expertise in data classification, sensitivity labelling, DLP policy implementation, information governance, regulatory compliance, and enterprise data protection and security technologies.

Key Responsibilities

Data Loss Prevention

  • Deploy, configure, and administer enterprise Data Loss Prevention solutions such as Microsoft Purview DLP, Forcepoint DLP, or equivalent technologies.
  • Design and implement DLP policies across enterprise email, collaboration, cloud, endpoint, and productivity services, including Microsoft 365 services such as Exchange Online, SharePoint Online, OneDrive, Teams, and endpoints.
  • Configure detection rules for sensitive information types, keywords, document fingerprints, and custom classifiers.
  • Monitor DLP alerts, incidents, and policy violations.
  • Investigate data leakage events and support incident response activities.
  • Implement risk-based controls to prevent unauthorized sharing, transfer, or exposure of sensitive information.
  • Tune DLP policies to improve detection accuracy and reduce false positives.
  • Support regulatory compliance requirements through appropriate policy implementation and reporting.
  • Generate operational, risk, and compliance reports for stakeholders.

Data Classification & Labelling

  • Implement and administer enterprise sensitivity labels, classification policies, and information protection controls using Microsoft Purview or equivalent technologies.
  • Design and maintain enterprise data classification frameworks.
  • Configure automatic, recommended, and manual labelling strategies.
  • Implement data protection capabilities, including encryption, content marking, access restrictions, and usage controls.
  • Integrate information protection controls across enterprise collaboration, productivity, cloud, and information management workloads.
  • Support secure data sharing and collaboration initiatives.
  • Perform classification reviews and improve data governance controls.
  • Work with business stakeholders to identify and classify sensitive business information.

Data Encryption Management

  • Implement, administer, and support enterprise data encryption solutions such as IBM Guardium Data Encryption, Thales CipherTrust, or equivalent technologies across enterprise environments.
  • Configure and manage encryption policies for structured and unstructured data.
  • Support encryption deployments across on-premises, cloud, and hybrid environments.
  • Monitor encryption controls and ensure continuous protection of business-critical data.
  • Troubleshoot encryption-related issues and support operational activities.
  • Manage cryptographic key lifecycle processes, including generation, distribution, storage, rotation, archival, and destruction.
  • Administer enterprise key management systems and encryption key repositories.
  • Support encryption key governance and access controls.
  • Implement separation-of-duty principles for key management operations.

Cryptographic Security & Data Protection

  • Implement encryption controls for data at rest, data in transit, and data in use, where applicable.
  • Support database, application, file-level, and storage-level encryption initiatives.
  • Implement and maintain TLS/SSL security controls and certificate management processes.
  • Support Public Key Infrastructure integration and management activities.
  • Evaluate cryptographic configurations and identify security weaknesses.
  • Support secure data-sharing and information protection initiatives.
  • Assist in the implementation of tokenization, masking, and encryption-based data protection controls.

Information Protection Governance

  • Develop and maintain data classification standards and governance procedures.
  • Conduct data discovery and information protection assessments.
  • Support the implementation of information handling requirements aligned with organizational policies.
  • Collaborate with legal, compliance, privacy, and risk teams on data protection initiatives.
  • Support audit activities and compliance assessments.
  • Assist in defining information protection roadmaps and maturity improvement plans.
  • Provide recommendations for strengthening enterprise data protection controls.

Skills and Attributes for Success

  • Strong understanding of Data Loss Prevention and Information Protection concepts.
  • Experience with data classification, sensitivity labelling, encryption, and rights management.
  • Understanding of data governance and information lifecycle management principles.
  • Knowledge of enterprise data protection, security, and compliance platforms, including Microsoft 365 and other relevant technology ecosystems.
  • Familiarity with privacy and regulatory requirements.
  • Strong analytical and troubleshooting skills.
  • Excellent communication and stakeholder management capabilities.
  • Ability to manage multiple client engagements and priorities simultaneously.
  • Strong customer-focused and consulting-oriented approach.

To Qualify for the Role, You Must Have

  • B. Tech, M. Tech, or an equivalent degree in Cybersecurity, Computer Science, Information Security, or related disciplines.
  • 12+ years of relevant cybersecurity experience.
  • Hands-on experience with one or more of the following technologies or equivalent enterprise platforms:
    • Microsoft Purview Data Loss Prevention
    • Microsoft Purview Information Protection
    • Microsoft Purview Sensitivity Labelling
    • Forcepoint Data Loss Prevention
    • IBM Guardium Data Encryption
    • Thales CipherTrust
  • Experience implementing enterprise data protection and compliance controls.
  • Knowledge of enterprise security, information protection, and compliance capabilities across Microsoft 365 or comparable technology environments.
  • Understanding of data classification, data governance, and information lifecycle management.
  • Experience supporting compliance and audit requirements.
  • Strong verbal and written communication skills.
  • Experience with scripting, automation, and platform integration using PowerShell, Python, SQL, APIs, or Microsoft Graph is an advantage.

What We Look For

  • Professionals who are passionate about data protection, information governance, and regulatory compliance. Successful candidates will possess strong technical expertise, excellent analytical skills, and the ability to translate business requirements into effective information protection controls. A strong sense of ownership, customer focus, and commitment to delivering high-quality cybersecurity services will be key to success in this role.

EY | Building a better working world


EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.


Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate.


Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.

似たような求人

EY - Cybersecurity - Data Protection and Information Protection - Manager

企業サイトでの申請
Back to search page