Posted today · be early
Information Security Spec II
Bio-Rad Laboratories
WorldwideremotePosted 1 day ago
Skill Required
Information-Security-SpecialistCybersecurity-AnalystDLP-SpecialistCloud-Security-EngineerSecurity-Operations-AnalystIT-Security-SpecialistSenior-Information-Security-SpecialistInformation-Security-AnalystsecuritySOCCloud SecurityEngineeringSystem AdministrationISO 27001automationObservabilityCryptographyFirewallbuildingTestNGAzuredesignCloudAWSGitandFulltime
Key highlights
- Required experience: 8+ years in information security
- Must cover non-US hours for global incident escalation
- Owns the enterprise DLP program (Microsoft Purview preferred)
- Strong Azure cloud security required (Defender for Cloud, Entra ID, Azure Policy)
- Professional certification preferred (CISSP, CCSP, AZ-500, SC-400, GCIH or equivalent)
- Open to equivalent work experience in lieu of a bachelor's degree
Role overview
This position protects Bio-Rad's data and cloud estate and leads high-severity security incident response outside US hours. The role owns the enterprise Data Loss Prevention (DLP) program, manages cloud security across AWS and Azure, and serves as the senior escalation point for security alerts in the non-US time zone. The ideal candidate will have a bachelor's degree in Computer Science, Information Security or a closely related subject, and will collaborate effectively with IT infrastructure, application teams, business users, and managed security service providers.
Responsibilities
- Own and manage the enterprise Data Loss Prevention (DLP) program end to end – policy design and changes, exception handling, new functionality and rollout – in partnership with Legal and data owners.
- Define and enforce protection for high-risk company assets by implementing enterprise DLP controls aligned to Legal and regulatory requirements, and maintain a quarterly-reviewed inventory of protected assets with Legal.
- Reduce Azure/AWS security risk by performing cloud security assessments and remediating all identified findings.
- Support Azure cloud security engineering work, including Microsoft Graph API automation, secure configuration, and identity and workload hardening.
- Serve as the security alert lead contact for the non-US time zone for all High and Critical cases, owning end-to-end handling of complex and high-risk incidents through documented closure within SLA.
- Increase L2 support team's effectiveness through standardized SOPs, expert guidance, structured escalation support and automation playbooks that shift work left to L2 and reduce escalation volume.
- Act as integration owner and backup contact for the 3rd party managed detection and response service.
- Ensure Information Security operations remain compliant with ISO 27001, data privacy regulations and other applicable requirements; support internal audit, FedRAMP and Legal requests.
- Support Information Security special projects and act as designated backup across key security and GIT domains, building T-shaped skills across the function.
- Prepare reports, technical presentations and KPI/metrics reporting for management decision-making.
- Review and monitor security logs for networks and cloud infrastructure to identify and investigate any potential security threats or vulnerabilities.
- DLP program – review what the system blocked, tune policies, and work through exception requests from the business.
- Communicate specific security needs and recommend appropriate security measures.
- Review configuration of security tools such as firewalls, intrusion detection systems, and encryption technologies to protect networks and data.
- Keep up-to-date on the latest security threats and technologies.
- Assess and test networks and cloud infrastructure for vulnerabilities and suggest remediation steps.
- Review and audit Azure and AWS Security Groups to ensure they are configured in a secure and compliant manner.
- Respond to security incidents and resolve them; report in multiple report formats.
- Collaborate with other security experts and stakeholders to improve overall security posture.
- Own Bio-Rad's DLP program and reach full coverage of data labeled Confidential and Restricted, cutting repeat policy violations by improving policies based on what the system actually blocks.
- Measurably reduce Azure cloud risk by assessing the estate and closing every Critical and High finding within 90 days of identification.
- Be the escalation point the business relies on outside US hours, leading High and Critical incidents from detection to documented closure within SLA.
- Make the L2 team materially stronger through SOPs, coaching and automation playbooks that shift work left and reduce escalations.
- Keep Information Security operations audit-ready against ISO 27001, data privacy regulations and customer commitments.
Requirements
- Eight (8) or more years of relevant information security experience, including hands-on ownership of an enterprise security program.
- Bachelor's degree in Information Security, Computer Science or a related field; or equivalent work experience required.
- Demonstrated experience owning an enterprise DLP program – Microsoft Purview DLP and Information Protection preferred – including policy authoring, tuning, exception management and sensitivity labeling of Confidential and Restricted data.
- Proven experience designing, assessing and remediating Azure cloud security controls (Defender for Cloud, Entra ID, Azure Policy, network and workload security) against compliance and industry best practice.
- Hands-on incident response experience at L2/L3, including ownership of High and Critical cases through closure alongside an MSSP or 24x7 SOC partner, and authorship of SOPs, runbooks and automation/SOAR playbooks. Incident report writing skills.
- Working knowledge of Microsoft Graph API and scripting automation (PowerShell, Python) applied to security operations.
- Knowledge of information security and data privacy laws and frameworks – ISO 27001, GDPR and similar – and experience supporting internal and external audits.
- Available to cover non-US-hours escalation for global incidents.
- Strong written and verbal communication; able to work with Legal, business stakeholders and global IT teams, and available to cover High and Critical escalations in the non-US time zone.
Nice to have
- Advanced degree preferred.
- AWS exposure is an advantage.
- Professional certification preferred: CISSP, CCSP, AZ-500, SC-400, GCIH or equivalent.
- Deep, hands-on data protection experience – enterprise DLP policy design, tuning and exception management, plus data classification and labeling, ideally with Microsoft Purview.
- Strong Azure cloud security skills – assessment, secure configuration, identity and workload protection, remediation at scale, and automation via Graph API and scripting.
- Proven incident response leadership at L2 support team with an MSSP or 24x7 SOC, owning High and Critical cases end to end.
- Excellent judgment and communication – able to explain risk and trade-offs to Legal, business stakeholders and executives, and to write SOPs that others can follow.
Benefits
- Competitive insurance plans for you and your immediate family.
- Annual health checkup.
- Marriage Leave.
- Paternity Leave.
- Employee Assistance Programme.
- Extensive learning and development opportunities.
Additional details
- This position is responsible for protecting Bio-Rad's data and cloud estate and for leading high-severity security incident response outside US hours.
- The role owns the enterprise Data Loss Prevention (DLP) program, responsible for cloud security (AWS and Azure), and acts as the senior escalation point for security alerts in the non-US time zone.
- The ideal candidate will have a bachelor's degree in Computer Science, Information Security or a closely related subject; an advanced degree is preferred.
- The position requires strong collaboration skills and the ability to work effectively with IT infrastructure, application teams, business users and managed security service providers.
- The role must cover non-US-hours escalation for global incidents.
- Bio-Rad: For 70 years, Bio-Rad has focused on advancing the discovery process and transforming the fields of science and healthcare. As one of the top five life science companies, they are a global leader in developing, manufacturing, and marketing a broad range of high-quality research and clinical diagnostic products. They help people everywhere live longer, healthier lives. Recently voted a Best Place to Work, Bio-Rad offers a unique employee experience with collaborative teams that span the globe. Here, you are supported by leadership to build your career and are empowered to drive change that makes an impact you can see.
- Bio-Rad's biggest asset is its people, and the reason why their Total Rewards deliver programs that provide value, quality, and inclusivity while satisfying the diverse needs of their evolving workforce. Their robust offerings serve to enrich the overall health, wealth, and wellbeing of employees through the various stages of an employee's work and life cycle.
- EEO Statement: Bio-Rad is an Equal Employment Opportunity/Affirmative Action employer, and welcomes candidates of all backgrounds. Veterans, people with disabilities, and people of all races, ethnicities, genders, ages, and orientations are encouraged to apply.
- Agency Non-Solicitation: Bio-Rad does not accept agency resumes unless the agency has been authorized by a Bio-Rad Recruiting Representative. Please do not submit resumes unless authorized to do so. Bio-Rad will not pay for any fees related to unsolicited resume.
- Originally posted on Himalayas.