Skip to content
← Back to job listings

TECHNICAL LEAD, IT SECURITY (INFOSEC) OPERATIONS - DLP & DSPM

bdc · Montreal, Canada

Software DevelopmentExternal listingfull-timeabout 1 hour ago

About The Role

We are banking at another level.

Choosing BDC as your employer means working in a healthy, inclusive, and skilled workplace that puts forward the best conditions to bring together unique teams where employees are empowered to act. It also means being at the centre of ambitious economic and financial projects to see further and to do things differently, to fuel the success of Canadian entrepreneurs.

Choosing BDC as your employer also means

  • Flexible and competitive benefits , including an Employee Savings and Investment Plan where BDC matches part of your voluntary contributions, a Defined Benefit Pension Plan, a $750 wellness and health care spending account, to name a few
  • In addition to paid vacation each year, five personal days , sick days as necessary , and our offices are closed from December 25 to January 1
  • A hybrid work model that truly balances work and personal life
  • Opportunities for learning , training and development , and much more...

Explore the BDC Way in our Culture Book

POSITION OVERVIEW

The Technical Lead is responsible for day-to-day security and data protection operations to ensure that BDC’s technology environment is well protected. The selected candidate coordinates activities, manages incident response, designs processes, drafts procedures, and provides recommendations for the secure adoption of artificial intelligence and the transition to a data-centric security model.

The Technical Lead will work within the Agile SCRUM collaboration framework and support the Product Owner in defining the roadmap for DLP and DSPM services. The Technical Lead will serve as a subject matter expert within their squad and with other stakeholders.

CHALLENGES TO BE MET

  • Develop and document processes and procedures related to information protection operations.
  • Regularly monitor and analyze all systems and application logs to identify suspicious activity and recommend solutions to eliminate or mitigate risks.
  • Monitor the effectiveness of DLP controls to prevent data exfiltration, while reducing false positives and the impact on operations.
  • Generate dashboards, metrics, and statistics based on application logs and propose data models to support KPIs.
  • Identify and propose solutions to mitigate data exposure risks in alignment with security requirements.
  • Develop and implement policies, procedures, and detection rules by monitoring trends, international news, current threats, and internal observations of behaviors requiring improvement.
  • Assess protection gaps and recommend compensatory and additional controls to continuously improve the security posture.
  • Work with the vendor to ensure that data loss prevention (DLP) rules are appropriate and functioning as intended.
  • Monitor and mitigate internal threat alerts and document investigations while maintaining a high level of confidentiality.
  • Secure the adoption of artificial intelligence, including monitoring the data used by AI agents and assistants.
  • Respond to emergency situations as needed to identify, assess, and mitigate critical data protection issues.
  • Provide technical leadership and operational governance by serving as a point of reference for DSPM practices.
  • Serve as a technical point of reference for the PO to prioritize risks and plan/guide strategic initiatives

WHAT WE ARE LOOKING FOR

Technical Skills and Required Qualifications

  • Expertise in data leak prevention strategies, processes, and technologies, as well as in optimizing detective and preventive controls.
  • Ability to analyze risks, conduct gap analyses, and recommend mitigation measures proportional to threats and requirements.
  • Expertise in risks related to AI agents, generative models, and data consumed or exposed by enterprise AI platforms.
  • Ability to serve as a subject matter expert and influence decisions
  • Knowledge of regulatory requirements, security controls, and information governance principles applicable to the financial and defense sectors.
  • Ability to explain technical concepts in an accessible, educational manner and to translate operational findings into a roadmap for business value creation.
  • Ability to communicate effectively in both official languages
  • Leadership, autonomy, vigilance, teamwork, ability to see the big picture, discretion, and a sense of confidentiality.
  • Sense of priorities, understanding of issues, criticality, and impact
  • Attention to detail in drafting documentation and processes related to the practice

Experience

  • 5 or more years of experience in cybersecurity, including a significant portion in the field of data protection.
  • 5 or more years of hands-on experience with enterprise DLP solutions, including the implementation, operation, and optimization of DLP and DSPM controls.
  • At least 3 years of experience with one of the following tools: O365 – PureView, Symantec WSS CASB, CrowdStrike, or other similar tools/services.
  • Experience in executing DLP transformation or migration programs, including gap analyses, compensating controls, and transition risk management.
  • Experience with data protection in cloud, SaaS, and hybrid environments, including sensitive data discovery, governance, and modern security models.

Assets

  • One of the following certifications: GSEC, GPPA, GCIA, GCWN, GMON, GCDA, OSCP
  • Familiarity with cybersecurity frameworks such as ATT&CK, Cyber Kill Chain, and the Diamond Model
  • Knowledge of the SCRUM collaboration model; proficiency in Azure DevOps
  • Expertise in DSPM and the application of Zero Trust principles.
  • Knowledge of open source
  • Experience in the banking sector and/or at BDC (significant asset)

Proudly one of Canada’s Top 100 Employers and one of Canada’s Best Diversity Employers , we are committed to fostering a diverse, equitable, inclusive and accessible environment where all employees can thrive and feel empowered to bring their whole selves to work. If you require an accommodation to complete your application, please do not hesitate to contact us at accessibility@bdc.ca .

While we appreciate all applications, we advise that only the candidates selected to participate in the recruitment process will be contacted.

This is an external listing. JobSpring does not represent or verify the employer. Report this listing