Deskripsi Pekerjaan
Join the elite security team at Trip.com Group as an Advanced Security Engineer and become a guardian of our global travel ecosystem. We are looking for a visionary leader to spearhead our Data Security initiatives, focusing on protecting sensitive traveler data and corporate assets using cutting-edge Data Loss Prevention (DLP) technologies. In this pivotal role, you will bridge the gap between security engineering and business operations, ensuring that our expansive infrastructure remains resilient against evolving cyber threats. You will have the opportunity to work in the heart of Singapore's business district (Raffles Place) and influence security policies that impact millions of users worldwide.
As a Data Security Leader, you will be responsible for architecting robust defense mechanisms, conducting deep-dive threat analysis, and leading incident response strategies. We value a culture of continuous improvement and innovation, where your expertise in identifying vulnerabilities and implementing proactive controls will directly enhance our risk posture. If you are passionate about safeguarding the future of travel and possess a knack for complex problem-solving, this is your chance to make a significant impact at a Fortune Global 500 company.
Tanggung Jawab
- Design, implement, and maintain comprehensive Data Loss Prevention (DLP) solutions to mitigate data leakage risks across endpoints, cloud environments, and network channels.
- Conduct regular security assessments, vulnerability scanning, and threat modeling to proactively identify and remediate security weaknesses within the infrastructure.
- Lead incident response efforts, including root cause analysis, containment strategies, and post-incident reporting for security breaches or anomalies.
- Monitor security alerts and logs using SIEM tools (e.g., Splunk, QRadar) to detect suspicious activities and ensure real-time visibility into the security landscape.
- Ensure strict compliance with global data protection regulations, including GDPR, CCPA, and local data privacy laws applicable to Singapore.
- Collaborate closely with software development teams to integrate security controls and secure coding practices into the Software Development Life Cycle (SDLC).
- Perform threat hunting and penetration testing to validate the effectiveness of existing security controls and defensive measures.
Kualifikasi
- Bachelor’s degree in Computer Science, Information Security, Cybersecurity, or a related technical field.
- Minimum of 5-7 years of progressive experience in Information Security, with a strong focus on DLP, network security, and cloud security architectures.
- Professional certifications such as CISSP, CISM, CEH, Security+, or CCSP are highly preferred.
- Hands-on experience with DLP tools (e.g., Forcepoint, Symantec DLP, McAfee DLP) and SIEM platforms (e.g., Splunk, ELK Stack).
- Strong understanding of cloud security principles and hands-on experience securing AWS or Azure environments.
- Proficiency in scripting languages like Python or Bash for automating security tasks and tooling.
- Excellent communication skills with the ability to present complex security concepts to non-technical stakeholders.