
Data Protection Manager
- Saint Louis, MO
- Permanent
- Full-time
- Contributes to the ongoing development and maintenance of a Data Classification & Protection Policy, Data Labeling taxonomy and deployment strategy as well as produces Training materials to educate the contributing Data Users on their responsibilities
- Contributes to the development of processes to identify and mitigate privacy and Data exposure Risks associated with artificial intelligence, ensuring compliance with applicable regulations and supporting ethical use of AI in medical devices and cloud-based services.
- Contribute to the design and implementation of Data Loss Prevention (DLP) and Information Protection solutions across the scope of Clayco’s Data landscape
- Configure, tune, and optimize DLP policies and rules across multiple platforms with a bias towards optimizing signal-to-noise ratios and minimizing false positives while partnering with the Security Operations Center (SOC) team to operationalize monitoring, alerting and response actions to DLP events
- Analyzes process and control gaps relative to achieving regulation-driven or business-defined requirements and expectations
- Contributes to the development of road maps for material gap remediation to achieve and sustain Business-defined expectations
- Tracks, Monitors, and Reports on implementation of gap remediation efforts
- Identifies and communicates changes in Business context, Regulatory Climate, and/or Threat Landscape that may indicate a need for change in Business Processes, policies, procedures, internal controls, or training
- Builds and maintains relationships with and collaborates cross-functionally with other Information Technology teams and Business Stakeholders across the Organization as well as strategic 3rd Party Partners
- Contribute to ongoing Security Awareness Program to ensures all appropriate Employees have the knowledge and tools to comply with Clayco’s Data Privacy and protection standards
- Contributes to major organizational initiatives as necessary to ensure new solutions align with existing policies and compliance requirements
- Provides leadership with comprehensive reports of progress and challenges, as requested
- 6-8+ years of experience working in hands-on, functional Information Security roles
- 3-5+ years of experience working in Information Security roles directly involving Data Protection and Privacy Assurance
- Bachelor's degree in Information Security or related field, or equivalent experience
- Certified Information Systems Security Professional (CISSP), Certified Information Privacy Professional (CIPP) Certifications [actively certified, or obtained within 6 months of assuming role]
- Strong experience leveraging analysis principles and methodologies to evaluate policies, processes, systems, and Data structures to identify relationships, business risks, compliance with Regulations, Frameworks, & Standards, and any applicable control gaps
- Experience interpreting Data-related Laws and Regulations to identify Privacy, Protection, and Auditability requirements and an understanding of trends to ensure effectiveness and compliance with any relevant Regulations, Frameworks, and Standards such as NIST 800-171, NIST Cybersecurity Framework, CIS Critical Security Controls, HIPAA, PCI DSS, ITAR/EAR, and all applicable U.S. State-level Data Protection & Privacy Regulations ((CA, CO, CT, DE, FL, IN, IA, KY, MD, MN, MT, NE, NH, NJ, OR, RI, TN, TX, UT, VA, and any additional becoming active)
- Experience in leading Data Governance, Data Protection, or GRC Programs
- Functional knowledge of how to map business processes, map Data components to business processes, map Dataflows to identify exposure, engineer process improvements, design controls to reduce Sensitive Data exposure
- Functional knowledge and experience with utilizing Data Security Posture Management (DSPM) platforms to discover and classify Data, determine provisioned access, detect and alert on suspicious/ noncompliant access activity, and execute automated remediation when appropriate
- Functional knowledge and experience with both cloud-based and internally deployed Data Loss Prevention (DLP) and Information Protection solutions to enforce proper handling of classified Data and restrict transfer to only authorized repositories
- Functional knowledge of both Cloud and Client/Server infrastructures and their components related to Data storage, processing, transformation, transfer, exposure, etc. and the applicable controls necessary to ensure proper protection throughout its life-cycle
- Knowledge of statistics, reporting and analytical tools to analyze and solve complex problems
- Proficiency in necessary productivity tools (such as Microsoft Excel and PowerPoint) for analytics and presentations
- Operate with strong integrity with the ability to handle projects of a sensitive and confidential nature
- Strong project management abilities, with a track record of delivering complex Data Protection projects on time and within budget
- Excellent oral and written communication skills including the ability to document functional requirements, test and validation criteria, develop communication plans, report on performance and compliance, and other relevant Operational communications to both technical and non-technical stakeholders
- Ability to respond to Major Incidents 24/7 including holidays and weekends
- No other builder can offer the collaborative design-build approach that Clayco does.
- We work on creative, complex, award-winning, high-profile jobs.
- The pace is fast!
- 2024 Best Places to Work – Crain’s Chicago Business, St. Louis Business Journal, Los Angeles Business Journal, and Phoenix Business Journal.
- 2024 ENR Midwest – Midwest Contractor (#1).
- 2024 ENR Top 100 Design-Build Firms – Design-Build Contractor (Top 5).
- 2024 ENR Top 100 Green Contractors – Green Contractor (Top 5).
- Discretionary Annual Bonus: Subject to company and individual performance.
- Comprehensive Benefits Package Including: Medical, dental and vision plans, 401k, generous PTO and paid company holidays, employee assistance program, flexible spending accounts, life insurance, disability coverage, learning & development programs and more!
- The salary range for this position considers a wide range of factors in making compensation decisions including but not limited to: Education, qualifications, skills, training, experience, certifications, internal equity, and location. Compensation decisions are dependent on the facts and circumstances of each case.