Hiring.Camp

Information Security Spec II

En Biorad

·

Oct 1, 2024

Location
Remote, IN
Workplace
Remote
Type
Full-time
Department
IT
Closing date
Today
Source
iCIMS

Description

Overview

This position is responsible for protecting Bio-Rad’s data and cloud estate and for leading high-severity security incident response outside US hours. The role owns the enterprise Data Loss Prevention (DLP) program, responsible for cloud security (AWS and Azure), and acts as the senior escalation point for security alerts in the non-US time zone. The ideal candidate will have a bachelor’s degree in Computer Science, Information Security or a closely related subject; an advanced degree is preferred. The position requires strong collaboration skills and the ability to work effectively with IT infrastructure, application teams, business users and managed security service providers.

 

This position is responsible for protecting Bio-Rad’s data and cloud estate and for leading high-severity security incident response outside US hours. The role owns the enterprise Data Loss Prevention (DLP) program, responsible for cloud security (AWS and Azure), and acts as the senior escalation point for security alerts in the non-US time zone. The ideal candidate will have a bachelor’s degree in Computer Science, Information Security or a closely related subject; an advanced degree is preferred. The position requires strong collaboration skills and the ability to work effectively with IT infrastructure, application teams, business users and managed security service providers.

ROLE RESPONSIBILITIES

  • Own and manage the enterprise Data Loss Prevention (DLP) program end to end – policy design and changes, exception handling, new functionality and rollout – in partnership with Legal and data owners.
  • Define and enforce protection for high-risk company assets by implementing enterprise DLP controls aligned to Legal and regulatory requirements, and maintain a quarterly-reviewed inventory of protected assets with Legal.
  • Reduce Azure/AWS security risk by performing cloud security assessments and remediating all identified findings.
  • Support Azure cloud security engineering work, including Microsoft Graph API automation, secure configuration, and identity and workload hardening.
  • Serve as the security alert lead contact for the non-US time zone for all High and Critical cases, owning end-to-end handling of complex and high-risk incidents through documented closure within SLA.
  • Increase L2 support team’s effectiveness through standardized SOPs, expert guidance, structured escalation support and automation playbooks that shift work left to L2 and reduce escalation volume.
  • Act as integration owner and backup contact for the 3rd party managed detection and response service.
  • Ensure Information Security operations remain compliant with ISO 27001, data privacy regulations and other applicable requirements; support internal audit, FedRAMP and Legal requests.
  • Support Information Security special projects and act as designated backup across key security and GIT domains, building T-shaped skills across the function.
  • Prepare reports, technical presentations and KPI/metrics reporting for management decision-making

Snapshot of the Candidate’s Day: (Describe in a short paragraph, what a day in the life of this role might look like)

  • Reviewing and monitoring security logs for our networks and cloud infrastructure to identify and investigate any potential security threats or vulnerabilities.
  • DLP program – reviewing what the system blocked, tuning policies, and working through exception requests from the business
  • Communicating specific security needs and recommending appropriate security measures.
  • Reviewiong configuration of security tools such as firewalls, intrusion detection systems, and encryption technologies to protect our networks and data.
  • Keeping up-to-date on the latest security threats and technologies.
  • Assessing and testing networks and cloud infrastructure for vulnerabilities and suggesting remediation steps.
  • Reviewing and Auditing Azure and AWS Security Groups to ensure they are configured in a secure and compliant manner.
  • Responding to security incidents and resolve them. Reporting in multiple report formats.
  • Collaborating with other security experts and stakeholders to improve overall security posture.

 

How the Candidate Will Make an Impact: (Top 5 bullet points outlining the responsibilities and challenges of the role that allow candidates to make impact)

 

  • Own Bio-Rad’s DLP program and reach full coverage of data labeled Confidential and Restricted, cutting repeat policy violations by improving policies based on what the system actually blocks.
  • Measurably reduce Azure cloud risk by assessing the estate and closing every Critical and High finding within 90 days of identification.
  • Be the escalation point the business relies on outside US hours, leading High and Critical incidents from detection to documented closure within SLA.
  • Make the L2 team materially stronger through SOPs, coaching and automation playbooks that shift work left and reduce escalations.
  • Keep Information Security operations audit-ready against ISO 27001, data privacy regulations and customer commitments.

 

What the Candidate Brings: (Top 5 required attributes, skills, and work experience)

 

  • Deep, hands-on data protection experience – enterprise DLP policy design, tuning and exception management, plus data classification and labeling, ideally with Microsoft Purview.
  • Strong Azure cloud security skills – assessment, secure configuration, identity and workload protection, remediation at scale, and automation via Graph API and scripting.
  • Proven incident response leadership at L2 support team with an MSSP or 24x7 SOC, owning High and Critical cases end to end.
  • Excellent judgment and communication – able to explain risk and trade-offs to Legal, business stakeholders and executives, and to write SOPs that others can follow.

Qualifications:

 

  • Eight (8) or more years of relevant information security experience, including hands-on ownership of an enterprise security program.
  • Bachelor’s degree in Information Security, Computer Science or a related field; or equivalent work experience required.
  • Demonstrated experience owning an enterprise DLP program – Microsoft Purview DLP and Information Protection preferred – including policy authoring, tuning, exception management and sensitivity labeling of Confidential and Restricted data.
  • Proven experience designing, assessing and remediating Azure cloud security controls (Defender for Cloud, Entra ID, Azure Policy, network and workload security) against compliance and industry best practice; AWS exposure an advantage.
  • Hands-on incident response experience at L2/L3, including ownership of High and Critical cases through closure alongside an MSSP or 24x7 SOC partner, and authorship of SOPs, runbooks and automation/SOAR playbooks. Incident report writing skills.
  • Working knowledge of Microsoft Graph API and scripting automation (PowerShell, Python) applied to  security operations.
  • Knowledge of information security and data privacy laws and frameworks – ISO 27001, GDPR and similar – and experience supporting internal and external audits.
  • Professional certification preferred: CISSP, CCSP, AZ-500, SC-400, GCIH or equivalent.
  • Eight or more years in information security, with working knowledge of ISO 27001 and data privacy requirements, and willingness to cover non-US-hours escalation for global incidents.
  • Strong written and verbal communication; able to work with Legal, business stakeholders and global IT teams, and available to cover High and Critical escalations in the non-US time zone.

 

Who We Are: For 70 years, Bio-Rad has focused on advancing the discovery process and transforming the fields of science and healthcare. As one of the top five life science companies, we are a global leader in developing, manufacturing, and marketing a broad range of high-quality research and clinical diagnostic products. We help people everywhere live longer, healthier lives. Recently voted a Best Place to Work, Bio-Rad offers a unique employee experience with collaborative teams that span the globe. Here, you are supported by leadership to build your career and are empowered to drive change that makes an impact you can see.

 

Benefits: Bio-Rad's biggest asset is its people, and the reason why our Total Rewards deliver programs that provide value, quality, and inclusivity while satisfying the diverse needs of our evolving workforce. Our robust offerings serve to enrich the overall health, wealth, and wellbeing of our employees through the various stages of an employee’s work and life cycle. We’re proud to offer a variety of options, including competitive insurance plans for you and your immediate family, Annual Health checkup , Marriage Leave, Paternity Leave ,Employee Assistance Programme , extensive learning and development opportunities, and more.

 

EEO Statement: Bio-Rad is an Equal Employment Opportunity/Affirmative Action employer, and we welcome candidates of all backgrounds. Veterans, people with disabilities, and people of all races, ethnicities, genders, ages, and orientations are encouraged to apply. 

 

Agency Non-Solicitation: Bio-Rad does not accept agency resumes, unless the agency has been authorized by a Bio-Rad Recruiting Representative. Please do not submit resumes unless authorized to do so. Bio-Rad will not pay for any fees related to unsolicited resume.

Skills

PythonAWSAzureGitSOCComplianceLoss PreventionGDPRISO 27001CISSP

Similar Jobs

30

Information Security Specialist

Text key word ''Agropur'' to 608-564-5884 to apply by SMS!·St-Hubert Campus, Canada

1d ago

Specialist, Information Security

Mdlz·Remote Worker - India·Remote

2d ago

Information Security Specialist

Canyon Aeroconnect·Prescott, Arizona

1w ago

Information Security Specialist

Start Campus·Lisbon

1w ago

Information Security Specialist

KOS International Holdings·Hong Kong

2w ago

Information Security Specialist

Tabby·KSA

3w ago

Information Security Specialist

Clydeco·Glasgow, UK·Hybrid

3w ago

Information Security Specialist

Td·One Molesworth Street, Dublin·Hybrid

4w ago

Information Security Specialist

Booz Allen Hamilton·Omaha, NE

1mo ago

Information Security Specialist

MRIGlobal·MRIGlobal, 1180 Seminole Trail

2mo ago

Information Security Specialist

PEMCCO·Washington, District of Columbia

2mo ago

Information Security Specialist

Marmon is·USA_IL_Carol Stream_355 Kehoe Blvd, US

2mo ago

Information Security Specialist

Itron here·Budapest, Hungary·Hybrid

2mo ago

Information Security Specialist

Work With Us·CAN - Ontario - Remote, Canada +1·Remote

3mo ago

Specialist, Information Security

Resmed·CA Canada·Hybrid

4mo ago

Specialist, Information Security

Pearson·Bangalore, Karnataka·Hybrid

6mo ago

Information Security Specialist

Db·Bucharest, 6A Dimitrie Pompeiu Blvd

1y+ ago

Information Security Specialist

Counterpart·Arlington, VA

1y+ ago

Information Security Specialist - Issue Management Governance and Reporting

Td·310, 320 Front Street West Corporate·Onsite

1d ago

GRC Specialist (Information Security, Privacy and Business Continuity)

KALSOFT·Riyadh, Ar Riyad

2d ago

Information Security Specialist (US)

Td·Mt Laurel - Technology Center - 17000 Horizon Way, Mount Laurel·Onsite

2d ago

Sr Information Security Specialist (US)

Td·13024 Ballantyne Corporate Place, Charlotte +1·Onsite

2d ago

Information Security Specialist (Senior-Level)

" Link Solutions, Inc."·Orlando, FL

2d ago

Information Security Specialist (Intermediate-Level)

" Link Solutions, Inc."·Orlando, FL

2d ago

Information Security Specialist (US) - Technology Resilience

Td·Mt Laurel - Technology Center - 17000 Horizon Way, Mount Laurel +2·Hybrid

5d ago

Senior Specialist, Information Security Analyst

0101022-GIA PROD US LOS ANGELES·Pittsburgh, PA

1w ago

Information Security Specialist (US) - Fusion Incident Management

Td·Remote Sacramento, US +2·Remote

1w ago

Information Security Specialist (w/m/d)

Mbda·Schrobenhausen, Germany·Hybrid

1w ago

Senior Information Security Specialist

Dev Technology·Ashburn, VA +1·Hybrid

2w ago

Specialist, Information Security and Privacy

Mindtickle·Pune, Maharashtra +1·Onsite

3w ago