24 Sep
|
liberty in asia pacific
|
Mumbai
24 Sep
liberty in asia pacific
Mumbai
We're hiring an IAM (Identity & Access Management) & DLP (Data Loss Prevention) Lead to establish and operationalize unified access governance and data loss prevention frameworks across our APAC insurance markets. Working from the global IAM and Data Security teams' policy references, you'll translate enterprise standards into practical, locally compliant frameworks – setting up local guidelines, SOPs, access certification processes, and DLP controls for each market. You'll partner closely with market CISOs to shape and execute the IAM and DLP roadmap, drive user access reviews across all account types, implement and tune DLP policies to protect sensitive data, and ensure the entire program is audit-ready against local regulatory expectations.
This role is ideal for someone who can balance global consistency with local regulatory reality across both access governance and data protection, and who takes pride in building durable, well-documented governance.
Access Governance Framework
- Establish an access governance framework for APAC, using the global IAM team's policies and standards as the authoritative reference point
- Adapt and operationalize global IAM principles to fit the APAC market context, leveraging the global team's capabilities, tooling, and patterns wherever possible
- Design a unified, consistent IAM framework that works across all in-scope APAC markets while accommodating local regulatory and operational differences
- Where global standards cannot be implemented as-is in a given market, raise, document, and manage formal security exceptions through the appropriate risk acceptance process
Data Loss Prevention (DLP) Framework
- Establish a DLP governance framework for APAC, aligned to the global Data Security team's policies and data classification standards
- Define and operationalize DLP policies across endpoint, email, cloud, and web channels to prevent unauthorized disclosure of sensitive and regulated data (PII, policyholder data, financial records, intellectual property)
- Adapt global DLP rules and detection logic to accommodate local data types, languages, and regulatory requirements specific to each APAC market
- Design and maintain data classification schemas and sensitive information types relevant to APAC insurance operations
- Where global DLP standards cannot be applied as-is, raise, document, and manage formal security exceptions through the appropriate risk acceptance process
DLP Policy Management & Tuning
- Develop, test, and deploy DLP policies using Microsoft Purview and Proofpoint across email, endpoints, cloud applications, and collaboration platforms
- Continuously monitor and tune DLP rules to reduce false positives while maintaining detection efficacy for true data exposure risks
- Define and manage DLP response actions (block, quarantine, notify, encrypt) appropriate to the sensitivity of the data and the regulatory context of each market
- Establish incident triage workflows for DLP alerts — including escalation paths, investigation procedures, and evidence preservation
- Conduct periodic reviews of DLP policy effectiveness and produce metrics on policy hits, incidents, trends, and remediation outcomes
Local Guidelines, SOPs & Procedures
- Develop and maintain local IAM and DLP guidelines, SOPs, and work instructions for each APAC market
- Ensure procedures clearly define roles, responsibilities, approval workflows, and escalation paths for both access governance and data protection
- Keep documentation current as global policy, local regulation, and tooling evolve
Access Certification & User Access Reviews
- Set up and run access certification and periodic user access review (UAR) processes covering all account types — standard user, privileged, service, shared, and third-party/vendor accounts
- Define review cadence, scope, ownership, and evidence requirements per market
- Track review completion, remediate identified access gaps and toxic combinations, and confirm closure
- Drive continuous improvement in certification quality, automation, and reviewer accountability
DLP Monitoring, Incident Response & Reporting
- Monitor DLP dashboards and alert queues, triaging and investigating potential data leakage incidents across all channels
- Coordinate with market CISOs, legal, compliance, and HR on confirmed DLP incidents, ensuring appropriate containment and remediation
- Maintain DLP incident records with full traceability — detection, investigation, response, root cause, and closure
- Produce periodic DLP reporting for market CISOs covering incident volumes, trends, top triggered policies, high-risk users/departments, and remediation status
- Drive user awareness and behaviour change through targeted engagement informed by DLP findings
Regulatory Compliance & Audit Readiness
- Identify and interpret IAM- and DLP-relevant regulatory requirements across MAS, HKIA, APRA, BNM, NFRA, and IRDAI (e.g., access control, segregation of duties, privileged access, periodic recertification, logging, data protection, cross-border data transfer, breach notification)
- Map local requirements into the access governance and DLP frameworks and ensure procedures demonstrably comply
- Maintain the IAM and DLP programs in a continuously audit-ready state — complete, current evidence; explicit traceability from control to procedure to execution
- Support internal audits, external audits, and regulatory inspections, and drive closure of any IAM- or DLP-related findings
Stakeholder Engagement & Reporting
- Partner with market CISOs to define, prioritize, and execute the IAM and DLP roadmap for each market
- Provide periodic reporting to market CISOs on progress, key risks, challenges, exceptions, and remediation status across both IAM and DLP
- Coordinate with the global IAM team, Data Security team, local IT, application owners, HR, and risk/compliance functions to keep the frameworks aligned and effective
- Escalate blockers and emerging risks promptly with clear, decision-ready context
Requirements:
- 10+ years of experience in identity and access management, data loss prevention, IT governance, security, or a closely related field
- Hands-on experience with access governance processes — access certification, user access reviews, joiner/mover/leaver, privileged access management, and segregation of duties
- Hands-on experience implementing and managing DLP solutions, including policy creation, tuning, incident triage, and reporting
- Demonstrated experience with DLP tooling, specifically Microsoft Purview (Information Protection, DLP, Insider Risk Management) and Proofpoint (Email DLP, Content Compliance)
- Demonstrated experience developing IAM and/or DLP policies, guidelines, SOPs, or control documentation in a regulated environment
- Understanding of IAM concepts and tooling (RBAC/ABAC, SSO, MFA, SailPoint, Microsoft Entra ID, and PAM tools such as CyberArk or Delinea)
- Understanding of data classification frameworks, sensitive information types, and data handling requirements in financial services
- Familiarity with IAM- and DLP-relevant regulatory and control expectations across one or more APAC markets (MAS, HKIA, APRA, BNM, NFRA, IRDAI)
- Familiarity with control frameworks such as ISO 27001, NIST CSF, or SOC 2
- Experience supporting audits and regulatory inspections, and managing findings to closure
- Strong documentation and stakeholder management skills, including the ability to report clearly to senior stakeholders such as CISOs
- Highly organized, with the ability to manage multiple market workstreams in parallel
- Prior experience in insurance or broader financial services
- Relevant certifications (CISA, CRISC, CISM, SailPoint certifications, Microsoft Security certifications, or equivalent)
📌 IAM & DLP Lead, APAC (Mumbai)
🏢 liberty in asia pacific
📍 Mumbai