Director of Insider Threat & Data Protection
Huntington National Bank · Dallas, TX · 2 wk ago
Information TechnologyFull-time
Key Responsibilities
Leadership & Strategy
- Lead enterprise Insider Threat, Data Protection, and Digital Forensics functions.
- Develop and execute a strategic maturity roadmap focused on enhancing detection, investigative, forensic, and data protection capabilities.
- Establish long-term operational strategies aligned to cybersecurity, regulatory, and business objectives.
- Build scalable operating models, governance structures, and program metrics to measure effectiveness and maturity.
Insider Threat & Investigations
- Oversee insider threat monitoring, investigations, and response activities involving data misuse, fraud, intellectual property theft, policy violations, and high-risk user behavior.
- Partner with HR, Legal, Compliance, Privacy, and Corporate Security on sensitive investigations and escalation management.
- Develop behavioral analytics and risk-based monitoring capabilities to identify anomalous user activity.
Data Protection
- Lead enterprise data protection strategy including data classification and sensitive data monitoring initiatives.
- Oversee implementation and optimization of controls across endpoint, email, cloud, SaaS, and network environments.
- Partner with infrastructure, cloud, and engineering teams to improve protection of regulated and sensitive data.
Digital Forensics & Incident Response
- Lead digital forensic investigations supporting cyber incidents, insider threat cases, legal investigations, and regulatory matters.
- Establish forensic readiness standards, evidence handling procedures, and investigative protocols.
- Support enterprise incident response efforts through advanced forensic analysis and threat investigations.
Operational Maturity & Innovation
- Identify capability gaps and implement improvements across people, process, technology, automation, and analytics.
- Evaluate emerging technologies including AI-driven analytics, UEBA, DSPM, and advanced insider risk platforms.
- Drive integration between Cyber Fusion Operations, Threat Intelligence, SOC, and Data Protection teams.
Basic Qualifications
- 6+ years of experience in Information Security, preferably in the Operations domain
- 4+ years of experience with Network Defense solutions
- 4+ years of experience in a Leadership role
- Associate's Degree or 4+ additional years of equivalent experience.
Preferred Qualifications
- 10+ years of cybersecurity leadership experience with focus areas including Insider Threat, Data Protection, Digital Forensics, Incident Response, or Cyber Operations.
- Experience leading enterprise-scale cybersecurity or cyber investigations teams within highly regulated industries.
- Strong understanding of:
- Insider Threat Programs
- DLP/Data Protection technologies
- Digital Forensics & eDiscovery
- Threat Detection & Investigations
- Cloud and SaaS security
- Regulatory and compliance requirements
- Experience developing strategic cybersecurity roadmaps and operational maturity programs.
- Experience within financial services, healthcare, government, or other regulated industries.
- Experience operating within Cyber Fusion Center or SOC environments.
- Certifications such as CISSP, CISM, GCFA, GCFE, GNFA, EnCE, or CCSP.
- Experience with platforms such as: Microsoft Purview, Proofpoint, and/or Splunk.
- Strong executive communication and stakeholder management skills.