高级数据保护与内部风险经理
Sr. Manager, Data Protection and Insider Risk
Dexcom 公司(纳斯达克股票代码:DXCM)是连续血糖监测(CGM)领域的先驱和全球领导者。Dexcom 最初是一家小公司,怀揣着一个宏大的梦想:彻底改变糖尿病的管理方式。解锁能带来更好健康结果的信息和洞见。25 年后的今天,我们已开创了一个行业。而我们才刚刚开始。我们正在将视野从糖尿病扩展到赋能人们掌控自己的健康。这意味着提供个性化、可操作的洞察,以解决重要的健康挑战。继续我们已开启的事业:改善人类健康。
我们由成千上万充满抱负、热情的全球员工驱动,他们愿意像战士一样奋斗,通过倾听、诚信服务、大胆思考和值得信赖来赢得客户的信任。我们已经改变了数百万人的生活,现在准备改变更多。我们的未来目标是成为领先的消费健康科技公司,同时继续开发针对严重健康状况的解决方案。我们将通过不断重塑独特的生物传感技术体验来实现这一目标。虽然我们已从初创时期走得很远,但我们的梦想比以往任何时候都更大。在全球范围内改善健康的机遇就在我们面前。
了解团队:
Dexcom 信息安全团队正在建立一个专门的数据保护与内部风险职能,以保护敏感信息,包括商业机密,防止未经授权的访问、转移、披露或滥用。该职能整合了数据防泄漏(DLP)、内部风险检测与响应、业务数据所有者协作、调查以及持续控制改进。
此职位将领导一个全球团队,推动数据保护控制和内部风险能力在终端、邮件、网页、云、SaaS 和协作环境中的成熟发展。团队将与信息安全同行职能、隐私、法律、人力资源、IT、全球安全和业务数据所有者紧密合作,以保护知识产权、受监管数据和其他高价值信息。
你将负责:
- 定义并执行与 Dexcom 业务风险、监管义务和信息安全优先事项一致的数据保护和内部风险战略、运营模式和路线图。
- 建立并领导一个高效的全球团队,涵盖员工、承包商和服务提供商,明确项目交付和调查的责任。
查看英文原文
The Company
Dexcom Corporation (NASDAQ DXCM) is a pioneer and global leader in continuous glucose monitoring (CGM). Dexcom began as a small company with a big dream: To forever change how diabetes is managed. To unlock information and insights that drive better health outcomes. Here we are 25 years later, having pioneered an industry. And we're just getting started. We are broadening our vision beyond diabetes to empower people to take control of health. That means personalized, actionable insights aimed at solving important health challenges. To continue what we've started: Improving human health.
We are driven by thousands of ambitious, passionate people worldwide who are willing to fight like warriors to earn the trust of our customers by listening, serving with integrity, thinking big, and being dependable. We've already changed millions of lives and we're ready to change millions more. Our future ambition is to become a leading consumer health technology company while continuing to develop solutions for serious health conditions. We'll get there by constantly reinventing unique biosensing-technology experiences. Though we've come a long way from our small company days, our dreams are bigger than ever. The opportunity to improve health on a global scale stands before us.
Meet The Team:
The Dexcom Information Security team is building a dedicated Data Protection and Insider Risk function to protect sensitive information, including trade secrets, from unauthorized access, movement, disclosure, or misuse. The function brings together Data Loss Prevention (DLP), insider risk detection and response, business data owner collaboration, investigations, and continuous control improvement.
This role will lead a global team maturing data protection controls and insider risk capabilities across endpoint, email, web, cloud, SaaS, and collaboration environments. The team will partner closely with peer Information Security functions, Privacy, Legal, HR, IT, Global Security, and business data owners to protect intellectual property, regulated data, and other high-value information.
Where You Come In:
- You will define and execute the Data Protection and Insider Risk strategy, operating model, and roadmap aligned to Dexcom’s business risk, regulatory obligations, and Information Security priorities.
- You will build and lead a high-performing global team across employees, contractors, and service providers, with clear accountability for program delivery, investigations, and control effectiveness.
- You will own the enterprise DLP control lifecycle, including rule design, testing, tuning, deployment, approved exceptions, enforcement, and retirement across endpoint, email, web, cloud, SaaS, and collaboration channels.
- You will establish and mature the Insider Risk Program, including governance, risk scenarios, indicators, detection use cases, triage and investigation workflows, escalation paths, and response playbooks.
- You partner with business data owners to identify high-value information, define protection requirements, validate control intent, implement approved exceptions, and drive remediation and control adoption.
- You lead sensitive insider risk and data protection investigations, including suspected data misuse, exfiltration, control violations, and high-risk departures.
- You oversee the integration and optimization of data protection and insider risk technologies, telemetry, and analytics, including DLP, user activity monitoring, behavioral analytics, and supporting security platforms.
- You will drive automation, analytics, and AI-assisted capabilities to improve alert quality, prioritization, investigation efficiency, control tuning, and response with appropriate human oversight.
- You define and report KPIs and KRIs for control coverage and effectiveness, violation and exception trends, investigation outcomes, alert quality, program maturity, and risk reduction.
- You maintain program governance, operating procedures, and defensible investigative practices that support proportionate monitoring, evidence handling, privacy requirements, and consistent decision-making.
What Makes You Successful:
- You have a BS/MS in Computer Science, Cybersecurity, Information Technology, Engineering, Risk Management, or a related field, or equivalent work experience.
- You have 10+ years of experience in cybersecurity, data security, risk, investigations, or related disciplines; 5+ years focused on data protection, DLP, or insider risk.
- You have proven success building, transforming, or scaling enterprise Data Protection, DLP, or Insider Risk programs in complex global environments.
- You have a strong understanding of enterprise DLP controls across endpoint, email, web, cloud, SaaS, and collaboration environments, including rule lifecycle management, tuning, approved exceptions, and control effectiveness.
- You have experience with enterprise DLP and insider risk platforms, including Netskope, Microsoft Purview, or similar technologies, and with user activity, behavioral, identity, endpoint, and other relevant telemetry.
- You have demonstrated experience leading sensitive investigations and partnering with HR, Legal, Privacy, GRC, Global Security, business leaders, and technical teams on risk-based response and remediation.
- You have strong knowledge of privacy, legal, regulatory, and ethical considerations for employee monitoring, sensitive data handling, and insider risk programs in global enterprises.
- You have experience using automation, analytics, or AI to improve data protection and insider risk operations and translate technical findings into business risk and executive-level insights.
- You may also bring preferred certifications such as CISSP, CISM, CIPP, GIAC, CERT Insider Threat credentials, or other relevant data protection, privacy, or insider risk certifications.
What You’ll Get:
- A front-row seat to groundbreaking technology that impacts lives around the world.
- A full and comprehensive benefits program, including medical, dental, and vision coverage, and wellness programs.
- Competitive compensation with performance incentives and opportunities for advancement within a growing, innovative company.
- Work-life balance support through flexible work arrangements and unlimited paid time off.
- Access to in-house training, development programs, career mentorship, and opportunities to attend security conferences to support your professional growth.
- The chance to work in an inclusive, diverse environment that values teamwork, collaboration, and continuous improvement.
- The opportunity to connect with the #dexcomwarriors community and contribute to a purpose-driven mission that makes a difference.
Travel Required:
· 5-15%
Experience and Education Requirements:
- Typically requires a Bachelor’s degree in a technical discipline with 13+ years of industry experience
- 5-8 years of previous people management experience
RemoteWorkplace:
· Your location will be a home office; youare not required tolive within commuting distance of your assigned Dexcom site (typically 75 miles/120km).If youresidewithin commuting distance of a Dexcom site (typically 75 miles/120km)a hybridworking environment may be available. Ask about our Flex workplaceoption.
Please note: The information contained herein is not intended to be an all-inclusive list of the duties and responsibilities of the job, nor are they intended to be an all-inclusive list of the skills and abilities required to do the job. Management may, at its discretion, assign or reassign duties and responsibilities to this job at any time. The duties and responsibilities in this job description may be subject to change at any time due to reasonable accommodation or other reasons. Reasonable accommodations may be made to enable individuals with disabilities to perform essential functions.
An Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, or protected veteran status and will not be discriminated against on the basis of disability. Dexcom’s AAP may be viewed upon request by contacting Talent Acquisition at .
If you are an individual with a disability and would like to request a reasonable accommodation as part of the employment selection process, please contact Dexcom Talent Acquisition at .
Meritain, an Aetna Company, creates and publishes the Machine-Readable Files on behalf of Dexcom. To link to the Machine-Readable Files, please click on the URL provided:
To all Staffing and Recruiting Agencies: Our Careers Site is only for individuals seeking a job at Dexcom. Only authorized staffing and recruiting agencies may use this site or to submit profiles, applications or resumes on specific requisitions. Dexcom does not accept unsolicited resumes or applications from agencies. Please do not forward resumes to the Talent Acquisition team, Dexcom employees or any other company location. Dexcom is not responsible for any fees related to unsolicited resumes/applications.
AI in Hiring Notice: We may use AI supported tools to help make our hiring process more efficient, consistent, and accessible for candidates around the world. All hiring decisions are made by people.
Salary:
$181,000.00 - $301,600.00
#DexcomUS
Originally posted on Himalayas