Security Analyst

Tech Inc
West Columbia, United States of America
3 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Intermediate

Job location

West Columbia, United States of America

Tech stack

Artificial Intelligence
ARM
Azure
CompTIA Security+
Computer Security
Data Governance
Information Leak Prevention
Data Loss
Data Security
Identity and Access Management
Information Security Management
Python
Microsoft Security Essentials
Powershell
Information Technology Security Auditing
Data Processing
Scripting (Bash/Python/Go/Ruby)
Data Classification
Microsoft Power Automate
Information Technology
Patch Management
Data Management
Security Orchestration, Automation & Response

Job description

This position supports the agency's cybersecurity and data protection program by protecting sensitive information, monitoring security risks, and strengthening controls related to Data Loss Prevention (DLP), Insider Risk Management, Microsoft Copilot and AI security, auditing, vendor security, and device patch management.

The Security Analyst is responsible for reviewing and triaging security alerts, investigating the access and movement of sensitive information, conducting system and vendor security assessments, documenting findings, supporting incident response activities, and collaborating with technical and business teams to strengthen the agency's overall cybersecurity and data governance posture., Data Protection & Governance

  • Monitor, maintain, and administer Data Loss Prevention (DLP) policies and controls.
  • Investigate potential data loss, unauthorized disclosures, and sensitive data exposure incidents.
  • Support Data Security Posture Management (DSPM) initiatives for Microsoft Copilot and AI technologies.
  • Review the storage, movement, and sharing of sensitive information across enterprise systems.
  • Assist with implementing data classification and data handling standards.
  • Support enterprise data governance initiatives and collaborate with data owners and data stewards.

Security Monitoring & Incident Response

  • Monitor, review, and triage security alerts generated by DLP, Insider Risk Management, DSPM, and other security monitoring platforms.
  • Investigate suspicious activity involving sensitive or regulated information.
  • Document investigations, findings, and recommended actions.
  • Escalate security incidents in accordance with agency incident response procedures.
  • Assist with incident containment, recovery, and post-incident analysis.

Insider Risk Management

  • Monitor Insider Risk Management alerts and investigations.
  • Analyze user activity associated with potential policy violations.
  • Conduct investigations while maintaining confidentiality and proper chain of custody for evidence.
  • Recommend corrective actions and risk mitigation strategies.

Vendor Security Management

  • Participate in third-party and vendor security risk assessments.
  • Review vendor security documentation, audit reports, certifications, and security questionnaires.
  • Identify cybersecurity risks associated with third-party products and services.
  • Track remediation activities and document risk acceptance decisions.

Security Auditing & Compliance

  • Support internal and external cybersecurity audits.
  • Collect, review, and analyze evidence required for regulatory, contractual, and organizational compliance.
  • Participate in cybersecurity risk assessments and control validation activities.
  • Maintain documentation supporting audit readiness and compliance initiatives.

Collaboration & Reporting

  • Partner with technical and business stakeholders to address cybersecurity risks and security concerns.
  • Prepare reports, dashboards, metrics, and presentations on security trends, risks, and compliance activities.
  • Support cybersecurity awareness and training initiatives.
  • Recommend improvements to security policies, standards, procedures, and technical controls.

Requirements

The candidate must have:

  • At least three (3) years of experience supporting enterprise cybersecurity operations, including threat monitoring, incident response, and risk analysis.
  • At least three (3) years of hands-on experience working with data protection technologies, including:
  • Data Loss Prevention (DLP)
  • Insider Risk Management
  • Data Security Posture Management for AI (DSPM for AI)
  • At least three (3) years of experience reviewing and triaging data-related security alerts, analyzing access to and movement of sensitive information, documenting investigation findings, and escalating incidents in accordance with established procedures.
  • At least three (3) years of experience collaborating with both technical and non-technical stakeholders to resolve security issues and improve the organization's data security posture., The ideal candidate will have experience with:
  • AI-driven security platforms, including Cortex and Data Security Posture Management (DSPM) solutions designed to protect AI systems.
  • Fine-tuning Data Loss Prevention (DLP) policies and Insider Risk Management rules.
  • Supporting enterprise data governance initiatives.
  • Microsoft Azure security services.
  • Identity and access management (IAM), including Conditional Access.
  • Security automation and scripting (PowerShell, Python, or similar).

Education & Certifications

Required

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field. Equivalent professional experience may be considered.
  • One of the following certifications:
  • CompTIA Security+
  • GIAC Security Essentials (GSEC)

Preferred

  • Microsoft Certified: Cybersecurity Architect Expert (SC-100)
  • Microsoft Certified: Security Operations Analyst Associate (SC-200)
  • Certified Ethical Hacker (CEH)
  • Associate of (ISC)² (working toward CISSP)

Apply for this position