Security Analyst

Tech Inc
West Columbia, SC, United States
4 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours

Tech stack

Artificial Intelligence ARM Architecture Microsoft Azure CompTIA Security+ Cyber Security Data Governance Information Leak Prevention Data Loss Data Security Identity and Access Management Information Security Management Python (Programming Language)
+11 more
Microsoft Security Essentials Windows PowerShell Information Technology Security Auditing Data Processing Scripting Data Classification Microsoft Power Automate Information Technology Patch Management Data Management Security Orchestration, Automation & Response

Job description

This position supports the agency’s cybersecurity and data protection program by protecting sensitive information, monitoring security risks, and strengthening controls related to Data Loss Prevention (DLP), Insider Risk Management, Microsoft Copilot and AI security, auditing, vendor security, and device patch management.

The Security Analyst is responsible for reviewing and triaging security alerts, investigating the access and movement of sensitive information, conducting system and vendor security assessments, documenting findings, supporting incident response activities, and collaborating with technical and business teams to strengthen the agency’s overall cybersecurity and data governance posture., Data Protection & Governance

  • Monitor, maintain, and administer Data Loss Prevention (DLP) policies and controls.
  • Investigate potential data loss, unauthorized disclosures, and sensitive data exposure incidents.
  • Support Data Security Posture Management (DSPM) initiatives for Microsoft Copilot and AI technologies.
  • Review the storage, movement, and sharing of sensitive information across enterprise systems.
  • Assist with implementing data classification and data handling standards.
  • Support enterprise data governance initiatives and collaborate with data owners and data stewards.

Security Monitoring & Incident Response

  • Monitor, review, and triage security alerts generated by DLP, Insider Risk Management, DSPM, and other security monitoring platforms.
  • Investigate suspicious activity involving sensitive or regulated information.
  • Document investigations, findings, and recommended actions.
  • Escalate security incidents in accordance with agency incident response procedures.
  • Assist with incident containment, recovery, and post-incident analysis.

Insider Risk Management

  • Monitor Insider Risk Management alerts and investigations.
  • Analyze user activity associated with potential policy violations.
  • Conduct investigations while maintaining confidentiality and proper chain of custody for evidence.
  • Recommend corrective actions and risk mitigation strategies.

Vendor Security Management

  • Participate in third-party and vendor security risk assessments.
  • Review vendor security documentation, audit reports, certifications, and security questionnaires.
  • Identify cybersecurity risks associated with third-party products and services.
  • Track remediation activities and document risk acceptance decisions.

Security Auditing & Compliance

  • Support internal and external cybersecurity audits.
  • Collect, review, and analyze evidence required for regulatory, contractual, and organizational compliance.
  • Participate in cybersecurity risk assessments and control validation activities.
  • Maintain documentation supporting audit readiness and compliance initiatives.

Collaboration & Reporting

  • Partner with technical and business stakeholders to address cybersecurity risks and security concerns.
  • Prepare reports, dashboards, metrics, and presentations on security trends, risks, and compliance activities.
  • Support cybersecurity awareness and training initiatives.
  • Recommend improvements to security policies, standards, procedures, and technical controls.

Requirements

The candidate must have:

  • At least three (3) years of experience supporting enterprise cybersecurity operations, including threat monitoring, incident response, and risk analysis.
  • At least three (3) years of hands-on experience working with data protection technologies, including:
  • Data Loss Prevention (DLP)
  • Insider Risk Management
  • Data Security Posture Management for AI (DSPM for AI)
  • At least three (3) years of experience reviewing and triaging data-related security alerts, analyzing access to and movement of sensitive information, documenting investigation findings, and escalating incidents in accordance with established procedures.
  • At least three (3) years of experience collaborating with both technical and non-technical stakeholders to resolve security issues and improve the organization’s data security posture., The ideal candidate will have experience with:
  • AI-driven security platforms, including Cortex and Data Security Posture Management (DSPM) solutions designed to protect AI systems.
  • Fine-tuning Data Loss Prevention (DLP) policies and Insider Risk Management rules.
  • Supporting enterprise data governance initiatives.
  • Microsoft Azure security services.
  • Identity and access management (IAM), including Conditional Access.
  • Security automation and scripting (PowerShell, Python, or similar).

Education & Certifications

Required

  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field. Equivalent professional experience may be considered.
  • One of the following certifications:
  • CompTIA Security+
  • GIAC Security Essentials (GSEC)

Preferred

  • Microsoft Certified: Cybersecurity Architect Expert (SC-100)
  • Microsoft Certified: Security Operations Analyst Associate (SC-200)
  • Certified Ethical Hacker (CEH)
  • Associate of (ISC)² (working toward CISSP)

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.disabledperson.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

41 sec

Massive client data loss and bio-digital storage

Chris Heilmann +1 · LIVE

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

4:04 min

Embedding data security and applied ethics into developer education

Daniel Tao +3 · WWC 2024

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

1:53 min

Evaluating traditional scripting languages for modern development tasks

Jens Knipper Jens Knipper · Europe 2026 Virtual

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

Videos

See all

Related articles

See all