Security Analyst IV - DLP Monitoring & Response
Role details
Job location
Tech stack
Job description
Your Role: We are seeking an experienced Security Analyst IV to support enterprise Data Loss Prevention (DLP) operations through event monitoring, investigation, triage, and risk assessment across cloud and on-premises environments. This role will be responsible for analyzing DLP alerts, identifying potential data exposure risks, coordinating incident response activities, and working with stakeholders across the organization to protect sensitive information. This role is critical to protecting the organization's sensitive data by ensuring timely detection, investigation, and response to potential data protection risks. The Security Analyst IV will help strengthen our data security posture, improve operational effectiveness, and support the continued evolution of DLP capabilities across the enterprise.
Your Work: The ideal candidate has strong experience in cybersecurity operations, DLP technologies, cloud security, and incident response, with the ability to collaborate effectively across technical and business teams.
Tools & Platforms
- Microsoft Purview DLP
- Microsoft Defender for Cloud Apps (MDCA)
- Netskope DLP/CASB
- AWS Macie
- Trellix DLP
- Akamai
- Wiz
- SIEM and security monitoring platforms, primarily Tines and Splunk, DLP Monitoring & Incident Triage
- Monitor, investigate, and triage DLP and data protection alerts across multiple security platforms.
- Analyze events to determine risk, business impact, and appropriate remediation actions.
- Escalate high-risk events in accordance with established incident response procedures.
- Document investigations, findings, and remediation recommendations.
Risk Assessment & Data Protection
- Identify potential data exposure, unauthorized sharing, and data exfiltration risks.
- Validate alerts and distinguish true positives from false positives.
- Support risk-based prioritization of security events and incidents.
- Ensure alignment with corporate security policies and regulatory requirements.
Collaboration & Stakeholder Engagement
- Partner with Cyber Defense, Security Engineering, IT, Cloud, Privacy, Legal, Compliance, and business teams.
- Work with data owners and stakeholders to validate business context and support remediation efforts.
- Communicate findings and recommendations to both technical and non-technical audiences.
Continuous Improvement
- Identify recurring trends, policy gaps, and tuning opportunities.
- Support DLP policy optimization, detection improvements, and automation initiatives.
- Contribute to operational playbooks, procedures, and knowledge-sharing efforts.
- Assist in developing metrics, dashboards, and reporting for leadership., * Actively shapes our company culture (e.g., participating in employee resource groups, volunteering, etc.)
- Lives into cultural norms (e.g., willing to have cameras when it matters: helping onboard new team members, building relationships, etc.)
- Travels as needed for role, including divisional / team meetings and other in-person meetings
- Fulfills business needs, which may include investing extra time, helping other teams, etc
- CISSP
- CISM
- Security+
- CEH
- Microsoft Security Certifications
- Netskope Certifications
- AWS Security Certifications
Please note we are hiring for this role remote anywhere in the United States with the following exceptions: Hawaii and Alaska., Sustainability: As climate change leads to more frequent and severe weather events, we are taking bold action to build more resilient communities and reduce our environmental impact. Submit your application to be considered. We communicate via email, so check your inbox and/or your spam folder to ensure you don't miss important updates from us., If you apply and are selected to continue in the recruiting process, we will schedule a preliminary call with you to discuss the role and will disclose during that call the available salary/hourly rate range based on your location. Factors used to determine the actual salary offered may include location, experience, or education.
Requirements
- Bachelor's degree in Cybersecurity, Information Systems, Computer Science, or a related field or equivalent practical experience (may be considered in place of a bachelor's degree).
- 7+ years of experience in cybersecurity, security operations, incident response, DLP, CASB, cloud security, or data protection.
- Hands-on experience investigating and responding to security or DLP alerts in an enterprise environment.
- Experience working with one or more DLP/CASB platforms such as Microsoft Purview, MDCA, Netskope, AWS Macie, or Trellix.
- Familiarity with cloud collaboration platforms and data sharing technologies.
Technical Skills
- Understanding of DLP concepts, data classification, and information protection controls.
- Knowledge of incident response processes and security event investigations.
- Experience with cloud security technologies and SaaS applications.
- Familiarity with SIEM tools, dashboards, and security reporting.
- Working knowledge of regulatory and compliance requirements such as PCI, GDPR, CCPA, HIPAA, or similar frameworks.Years' of experience
Benefits & conditions
Pulled from the full job description
- 401(k) matching, Recognition: We offer a total compensation package, annual bonus eligibility for most roles, 401(k) with a company match, and so much more! Read more about what we offer and what it is like to be a part of our dynamic team at https://careers.csaainsurance.aaa.com/us/en/benefits., The national average salary range for this position is $116,820.00-$129,800.00. However, we have a location-based compensation structure. Our salary ranges vary and are calculated based on work location. The starting pay range for this position across all the states we hire in is $116,820.00-$155,750.00. This role also includes an opportunity for a company-wide annual discretionary bonus, through our Annual Incentive Plan (AIP), of up to 10% of eligible pay.