> Markdown version of [/jobs/ext/2593779-lead-security-analyst-dlp-dspm](https://www.wearedevelopers.com/jobs/ext/2593779-lead-security-analyst-dlp-dspm). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Security Analyst (DLP/DSPM) - **Company:** Gartner, Inc. - **Location:** Irving, TX, United States (Remote available) - **Experience:** Expert - **Salary:** $94,000.0 - $134,000.0 - **Contract:** Permanent contract - **Skills:** Data Analysis, CompTIA Security+, Cyber Security, Information Leak Prevention, Data Security, Information Security Management, Information Technology Operations, Phishing, Microsoft SharePoint, Unstructured Data, Data Processing, Information Technology, Cybercrime, Gsuite - **Published:** August 11, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=da6ed6a6538bbd52 ## About the Role * Bachelor's degree in Computer Science , Information Security, or a related field (relevant experience may be considered in lieu of a degree). * 5-7 years of hands-on experience in Information Security, with a focus on human cyber risk, data loss prevention, and insider threat. * Strong understanding of information security best practices, frameworks (e.g., NIST, ISO 27001), and regulatory requirements. * In-depth knowledge of Data Loss Prevention (DLP) principles, technologies, and implementation strategies. * Proven experience with Insider Risk Management methodologies and tools. * Familiarity with current attack vectors tied to human actors, including phishing, social engineering, business email compromise (BEC), and malware delivery . Must have: Technical & Data Security Capabilities * Hands-on experience with Data Loss Prevention (DLP) and Data Security Posture Management (DSPM) platforms to govern unstructured data and prevent exfiltration. * Experience with Email Security platforms and Endpoint Protection tools (device control, USB policy enforcement, local storage monitoring). * Proficiency in analyzing data security telemetry across cloud platforms (e.g., M365 Purview, Google Workspace, OneDrive/SharePoint). Human Cyber Risk & Governance * Experience analyzing human risk indicators, insider threat telemetry, or security awareness campaign metrics (e.g., phishing performance, EDP training completions). * Understanding of Acceptable Use Policies (AUP) and experience managing risk-based exception workflows without causing business disruption. Professional & Analytical Skills * Strong analytical skills with a proven track record of investigating data security alerts, performing root-cause analysis, and evaluating complex employee risk profiles. * Exceptional written and verbal communication skills, specifically the ability to conduct empathetic yet firm security remediations with employees and present risk insights to leadership (HR, Legal, IT). * Self-starter with the ability to manage independent investigations while collaborating seamlessly across a global security organization. Nice to have: * Relevant security certifications (e.g., CISSP, CISM, GSEC, Security+ , SSAP ). Who you are : * A lifelong learner with a desire for continuous personal and professional development. * Someone with proven communication, collaboration, and critical thinking skills. * Able to build trusting, meaningful relationships with peers, stakeholders, partners, and suppliers. * Capable of defining and communicating risk in a business-relevant language to both non-technical and technical audiences including Leadership teams . * Someone who can apply expert knowledge to solve complex business/technical issues. ## Description We're looking for a well-rounded and motivated Lead Security Analyst to join our Human Cyber Risk & Assessment Team. In this critical role, you'll be instrumental in safeguarding our organization from human-centric cyber threats. You'll leverage your expertise in information security best practices to identify , assess, and mitigate risks associated with human behavior, ensuring the protection of our sensitive data and systems. This is an excellent opportunity for a professional with 5-7 years of experience in Information Security who is passionate about proactive security measures and building a strong security posture. What you will do: * Conduct comprehensive assessments of human-centric cyber risks, identifying vulnerabilities and potential attack vectors tied to human actors like phishing, social engineering, and insider threats. * Design, implement, and manage Data Loss Prevention (DLP) strategies and controls to prevent unauthorized disclosure or exfiltration of sensitive information. You'll also monitor DLP alerts, investigate incidents, and recommend remediation steps. * Develop and implement programs to detect, analyze, and mitigate insider risks, including monitoring user behavior and collaborating with relevant stakeholders (e.g., HR, Legal) on incident response. * Stay ahead of current attack vectors, trends, and techniques used by threat actors targeting human vulnerabilities, proactively identifying emerging threats and recommending countermeasures. * Advocate for and ensure adherence to information security best practices across the organization, especially regarding human behavior and data handling. * Configure, monitor , and optimize security tools relevant to human cyber risk. * Support during security incidents related to human-centric threats, assisting with investigation, containment, eradication, and recovery efforts. * Contribute to the development and delivery of security awareness training programs to educate employees on human cyber risks and best practices. * Generate reports on human cyber risk posture, incident metrics, and the effectiveness of security controls, while maintaining accurate documentation of security processes. * Collaborate with cross-functional teams, including IT Operations, Legal, HR, and other security teams, to achieve security objectives . * Present Security Risk Findings to Leadership * Assist with mentoring Junior Level Analyst ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Skynet wants your Passwords! The Role of AI in Automating Social Engineering](https://www.wearedevelopers.com/videos/770-skynet-wants-your-passwords-the-role-of-ai-in-automating-social-engineering) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)