Business Development Bank of Canada

TECHNICAL LEAD, IT SECURITY (INFOSEC) OPERATIONS - DLP & DSPM

Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 10+ years of IT experience, including 5+ years in security/network roles
  • Experience with leading DLP tools like O365 - PureView
  • Relevant certifications (GSEC, GPPA, etc.) are an asset
  • Strong understanding of cyber frameworks (ATT&CK, Cyber Kill Chain)
  • Ability to communicate complex situations clearly and effectively

Responsibilities

  • Centralize DLP development activities across operations and implementations
  • Draft processes and procedures for information protection
  • Analyze system logs to identify and address suspicious activity
  • Create dashboards and KPIs for senior management using PowerBI
  • Develop training strategies for information security awareness
  • Act as a liaison between technical teams and business units

Benefits

  • Flexible and competitive benefits package
  • Hybrid work model promoting work-life balance
  • Generous time-off policy including personal and sick days
  • Opportunities for continuous learning and development
  • Employee Savings and Investment Plan with matching contributions
Full Job Description
POSITION OVERVIEW

The Technical Lead is responsible for day-to-day security and data protection operations to ensure that BDC's technology environment is well protected. The selected candidate coordinates activities, manages incident response, designs processes, drafts procedures, and provides recommendations for the secure adoption of artificial intelligence and the transition to a data-centric security model.

The Technical Lead will work within the Agile SCRUM collaboration framework and support the Product Owner in defining the roadmap for DLP and DSPM services. The Technical Lead will serve as a subject matter expert within their squad and with other stakeholders.

CHALLENGES TO BE MET
  • Develop and document processes and procedures related to information protection operations.
  • Regularly monitor and analyze all systems and application logs to identify suspicious activity and recommend solutions to eliminate or mitigate risks.
  • Monitor the effectiveness of DLP controls to prevent data exfiltration, while reducing false positives and the impact on operations.
  • Generate dashboards, metrics, and statistics based on application logs and propose data models to support KPIs.
  • Identify and propose solutions to mitigate data exposure risks in alignment with security requirements.
  • Develop and implement policies, procedures, and detection rules by monitoring trends, international news, current threats, and internal observations of behaviors requiring improvement.
  • Assess protection gaps and recommend compensatory and additional controls to continuously improve the security posture.
  • Work with the vendor to ensure that data loss prevention (DLP) rules are appropriate and functioning as intended.
  • Monitor and mitigate internal threat alerts and document investigations while maintaining a high level of confidentiality.
  • Secure the adoption of artificial intelligence, including monitoring the data used by AI agents and assistants.
  • Respond to emergency situations as needed to identify, assess, and mitigate critical data protection issues.
  • Provide technical leadership and operational governance by serving as a point of reference for DSPM practices.
  • Serve as a technical point of reference for the PO to prioritize risks and plan/guide strategic initiatives


WHAT WE ARE LOOKING FOR

Technical Skills and Required Qualifications
  • Expertise in data leak prevention strategies, processes, and technologies, as well as in optimizing detective and preventive controls.
  • Ability to analyze risks, conduct gap analyses, and recommend mitigation measures proportional to threats and requirements.
  • Expertise in risks related to AI agents, generative models, and data consumed or exposed by enterprise AI platforms.
  • Ability to serve as a subject matter expert and influence decisions
  • Knowledge of regulatory requirements, security controls, and information governance principles applicable to the financial and defense sectors.
  • Ability to explain technical concepts in an accessible, educational manner and to translate operational findings into a roadmap for business value creation.
  • Ability to communicate effectively in both official languages
  • Leadership, autonomy, vigilance, teamwork, ability to see the big picture, discretion, and a sense of confidentiality.
  • Sense of priorities, understanding of issues, criticality, and impact
  • Attention to detail in drafting documentation and processes related to the practice


Experience
  • 5 or more years of experience in cybersecurity, including a significant portion in the field of data protection.
  • 5 or more years of hands-on experience with enterprise DLP solutions, including the implementation, operation, and optimization of DLP and DSPM controls.
  • At least 3 years of experience with one of the following tools: O365 - PureView, Symantec WSS CASB, CrowdStrike, or other similar tools/services.
  • Experience in executing DLP transformation or migration programs, including gap analyses, compensating controls, and transition risk management.
  • Experience with data protection in cloud, SaaS, and hybrid environments, including sensitive data discovery, governance, and modern security models.


Assets
  • One of the following certifications: GSEC, GPPA, GCIA, GCWN, GMON, GCDA, OSCP
  • Familiarity with cybersecurity frameworks such as ATT&CK, Cyber Kill Chain, and the Diamond Model
  • Knowledge of the SCRUM collaboration model; proficiency in Azure DevOps
  • Expertise in DSPM and the application of Zero Trust principles.
  • Knowledge of open source
  • Experience in the banking sector and/or at BDC (significant asset)

About Business Development Bank of Canada

The Business Development Bank of Canada (BDC) is a federal Crown corporation that provides financing, advisory services, and capital to Canadian businesses. The bank was founded in 1944 and is headquartered in Montreal, Quebec. BDC offers a range of financial services, including loans, venture capital, and consulting services. The bank focuses on small and medium-sized businesses, and has a particular emphasis on supporting entrepreneurs and startups. BDC has offices across Canada and works with businesses in a variety of industries, including manufacturing, technology, and services.
Learn more about Business Development Bank of Canada
Size
2,000 employees
Industry

Similar Jobs

More Jobs at Business Development Bank of Canada

More Information Technology Jobs

Find similar TECHNICAL LEAD, IT SECURITY (INFOSEC) OPERATIONS - DLP & DSPM jobs: