Security Analyst IV – DLP Monitoring & Response

Cybersecurity Jobs

Phoenix (AZ)

Remote

USD 117,000 - 156,000

Full time

11 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Total compensation package
Annual bonus eligibility
401(k) with company match
Annual discretionary bonus up to 10%

Job summary

CSAA is seeking an experienced cybersecurity professional to support Data Loss Prevention (DLP) monitoring and response across cloud and on-premises environments. The role involves investigating alerts, assessing risk, and coordinating remediation with multiple teams to protect data assets.

Responsibilities include triaging DLP alerts, analyzing risk and business impact, and documenting investigations with remediation recommendations.

Qualifications

  • 7+ years in cybersecurity, security operations, incident response, DLP, CASB or data protection.
  • Hands-on experience with enterprise DLP alerts and remediation.
  • Experience with DLP/CASB platforms (Purview, MDCA, Netskope, AWS Macie, Trellix).
  • Familiar with cloud apps, data sharing tech, and information protection controls.
  • Knowledge of incident response processes and security event investigations.
  • Familiarity with PCI, GDPR, CCPA, HIPAA or similar frameworks.

Responsibilities

  • Monitor, triage, and investigate DLP alerts across multiple platforms.
  • Analyze events to assess risk, business impact, and remediation actions.
  • Escalate high-risk events per incident response procedures.
  • Document investigations and remediation recommendations.
  • Identify data exposure, unauthorized sharing, and exfiltration risks.
  • Validate alerts and distinguish true vs false positives.
  • Support risk-based prioritization of security events and incidents.
  • Ensure activities align with security policies and regulatory requirements.
  • Collaborate with Cyber Defense, IT, Cloud, Privacy, Legal, and business teams.
  • Communicate findings to technical and non-technical audiences.
  • Develop metrics, dashboards, and reporting for leadership.

Skills

DLP monitoring
Incident response
Risk assessment
Security operations
Data protection
Cloud security
Regulatory awareness
Communication to technical and non-IT

Education

Bachelor’s degree in Cybersecurity or related field

Tools

Microsoft Purview DLP
MDCA
Netskope
AWS Macie
Trellix DLP
SIEM (Splunk, Tines)

Job description

Support enterprise Data Loss Prevention (DLP) monitoring and response by investigating alerts, assessing risk, and coordinating remediation across cloud and on-premises environments.

Responsibilities
  • Monitor, investigate, and triage DLP and data protection alerts across multiple security platforms.
  • Analyze security events to determine risk, business impact, and appropriate remediation actions.
  • Escalate high-risk events according to established incident response procedures.
  • Document investigations, findings, and remediation recommendations.
  • Identify potential data exposure, unauthorized sharing, and data exfiltration risks.
  • Validate alerts and distinguish true positives from false positives.
  • Support risk-based prioritization of security events and incidents.
  • Ensure activities align with corporate security policies and regulatory requirements.
  • Partner with Cyber Defense, Security Engineering, IT, Cloud, Privacy, Legal, Compliance, and business teams.
  • Work with data owners and stakeholders to validate business context and support remediation efforts.
  • Communicate findings and recommendations to both technical and non-technical audiences.
  • Identify recurring trends, policy gaps, and tuning opportunities.
  • Support DLP policy optimization, detection improvements, and automation initiatives.
  • Contribute to operational playbooks, procedures, and knowledge-sharing efforts.
  • Assist in developing metrics, dashboards, and reporting for leadership.
Requirements
  • Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, or a related field (or equivalent practical experience may be considered).
  • 7+ years of experience in cybersecurity, security operations, incident response, DLP, CASB, cloud security, or data protection.
  • Hands-on experience investigating and responding to security or DLP alerts in an enterprise environment.
  • Experience with one or more DLP/CASB platforms, including Microsoft Purview, MDCA, Netskope, AWS Macie, or Trellix.
  • Familiarity with cloud collaboration platforms and data sharing technologies.
  • Understanding of DLP concepts, data classification, and information protection controls.
  • Knowledge of incident response processes and security event investigations.
  • Experience with cloud security technologies and SaaS applications.
  • Familiarity with SIEM tools, dashboards, and security reporting.
  • Working knowledge of regulatory/compliance requirements such as PCI, GDPR, CCPA, HIPAA, or similar frameworks.
Technologies
  • Microsoft Purview DLP
  • Microsoft Defender for Cloud Apps (MDCA)
  • Netskope DLP/CASB
  • AWS Macie
  • Trellix DLP
  • Akamai
  • Wiz
  • SIEM and security monitoring platforms (primarily Tines and Splunk)
Benefits
  • Total compensation package
  • Annual bonus eligibility for most roles
  • 401(k) with a company match
  • Opportunity for a company-wide annual discretionary bonus via the Annual Incentive Plan (AIP), up to 10% of eligible pay
Additional Certifications That May Stand Out
  • CISSP
  • CISM
  • Security+
  • CEH
  • Microsoft Security Certifications
  • Netskope Certifications
  • AWS Security Certifications
Remote Work
  • Remote anywhere in the United States
  • Exclusions: Hawaii and Alaska
Salary
  • Annual range: USD 116,820 - 155,750 (yearly)
  • National average salary range: USD 116,820 - 129,800
  • Colorado specific range: USD 116,820 - 142,800
  • Annual Incentive Plan (AIP): opportunity for discretionary bonus up to 10% of eligible pay
Visa Sponsorship
  • CSAA does not provide visa sponsorship for this role
  • Applicants must have authorization to work indefinitely in the US
Reasonable Accommodations
  • CSAA is committed to providing reasonable accommodations to qualified applicants and employees with disabilities or other limitations
  • To request an accommodation for the application or interview process, contact TalentAcquistion@csaa.com

Location: Phoenix, AZ (remote).

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Data Loss Prevention Analyst
Data Loss Prevention Analyst

Bayview Fund Management, LLC • Coral Gables (FL), Northern (KY)

On-site
USD 70,000 - 130,000
Annual bonus
Medical coverage from day one
401(k) company match
Remote Senior DLP & Data Protection Security Analyst
Remote Senior DLP & Data Protection Security Analyst

Cybersecurity Jobs • Phoenix (AZ)

Remote
USD 117,000 - 156,000
Total compensation package
Annual bonus eligibility
401(k) with company match
+1
DLP/Data Security Engineer (Job ID 3022226)
DLP/Data Security Engineer (Job ID 3022226)

ADT Security Services • Boca Raton (FL), Northern (KY)

Hybrid
USD 140,000 - 190,000
Cloud Engineer - Enterprise Data Security (Remote - US)
Cloud Engineer - Enterprise Data Security (Remote - US)

Jobgether • United States

On-site
USD 120,000 - 170,000
Competitive compensation and bonus eligibility
Core benefits including medical, dental, vision, and 401(k) with company match
Flexible work environment: fully remote, hybrid, or in-office options
+3
Security Engineer
Security Engineer

Sargent & Lundy • Chicago (IL)

On-site
USD 64,915 - 95,019
Health Plans: Medical, Dental, Vision
401(k)
Paid Annual Personal/Sick Time
+1
Cybersecurity Incident Response & Threat Detection Analyst
Cybersecurity Incident Response & Threat Detection Analyst

Cybersecurity Jobs • Columbus (OH)

On-site
USD 100,000 - 160,000
Health insurance
Dental
Vision
+6
Data Loss Prevention Analyst
Data Loss Prevention Analyst

Lakeview Loan Servicing, LLC. • Flower Mound (TX)

On-site
USD 70,000 - 130,000
Medical coverage starting day one
Company-matched 401(k)
Security & Compliance Engineer II, AWS Security Assurance Services, LLC
Security & Compliance Engineer II, AWS Security Assurance Services, LLC

Amazon Web Services (AWS) • Austin (TX)

On-site
USD 159,000 - 202,000
Security & Compliance Engineer II, AWS Security Assurance Services, LLC
Security & Compliance Engineer II, AWS Security Assurance Services, LLC

Amazon Web Services (AWS) • Nashville (TN)

On-site
USD 138,000 - 184,000
Health insurance
401(k) matching
Parental leave
Security & Compliance Engineer II, AWS Security Assurance Services, LLC
Security & Compliance Engineer II, AWS Security Assurance Services, LLC

Amazon Web Services (AWS) • Seattle (WA)

On-site
USD 150,000 - 190,000
Health insurance
401(k) matching
Paid time off