Sr Data Protection & Governance Analyst

Starkey Hearing Technologies

Eden Prairie (MN)

On-site

USD 86,000 - 117,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Bonus eligible
Comprehensive benefits
Paid time off

Job summary

Starkey Hearing Technologies seeks a Data Protection & Governance Analyst to own DLP and information-protection controls in Microsoft Purview, and to lead enterprise governance across the Microsoft 365 environment. The role includes training, change management, and building an internal AI assistant wired to Starkey policies.

You will coordinate with SOC/MDR, Security Engineering, and IT teams to enable secure data handling while scaling protections across the organization.

Qualifications

  • Bachelor's degree in cybersecurity, information security, computer science, information technology, or a related field - or equivalent hands-on experience.
  • 5+ years in information security or IT
  • 3+ years of hands on Microsoft Purview/DLP experience

Responsibilities

  • Own the day-to-day operation, governance, and adoption of the data protection program across Microsoft 365 (E5).
  • Administer DLP policies, SITs, and labeling in Microsoft Purview to protect email, SharePoint, OneDrive, Teams, and endpoints.
  • Govern sensitivity-label taxonomy, auto-labeling policies, and protection with group scoping.
  • Investigate DLP alerts, triage incidents, and coordinate with SOC/MDR and Security Engineering on escalations.
  • Develop and deliver end-user training on labels, DLP, and secure data handling; drive change management for new controls.
  • Design and maintain an AI assistant for security questions, ensuring guardrails and privacy controls.

Skills

Data protection
DLP policies
Microsoft Purview
Regex
AI assistant design
Change management
Training & enablement
Stakeholder management
SOC/MDR coordination
ITSM (ServiceNow)

Education

Bachelor's degree in cybersecurity / information security / IT

Tools

Microsoft Purview
Microsoft 365 Admin
Entra ID
Defender/Sentinel
ServiceNow

Job description

Help build a security-first culture where technology enables the business instead of slowing it down. As our Data Protection & Governance Analyst, you'll lead Microsoft 365 data protection, AI-powered employee enablement, and enterprise governance initiatives that safeguard critical information while making security simple, practical, and scalable across the organization.

Starkey is a world leader in the manufacturing and distribution of advanced hearing technologies. We are in the business of connecting people and changing lives. Our teams come to work each day focused on ensuring people everywhere have the products and services they need to hear better and live better.

Founded in 1967 by Bill Austin, Starkey is known for our cutting-edge hearing health innovations, industry-leading research and development, and not being afraid to push the edge of what's possible.

We are headquartered in Eden Prairie, Minnesota, have over 5,000 employees in 29 facilities across the globe, and do business in more than 100 markets worldwide.

Watch this video to see more of what sets Starkey apart: https://youtu.be/9cUYwTlCepg?si=wkovx8_R_iINfrc6

JOB RESPONSIBILITIES/RESULTS
JOB SUMMARY DESCRIPTION / PRIMARY PURPOSE OF JOB

The Data Protection & Governance Analyst owns the day-to-day operation, governance, and adoption of our data protection program across the Microsoft 365 (E5) environment. This role consolidates a fast-growing body of work - Data Loss Prevention (DLP), sensitivity labeling, and the administration of enterprise-wide security settings - that is currently distributed across existing team members alongside their primary security-operations duties.

The Data Protection & Governance Analyst will be the single accountable owner for DLP and information-protection controls in Microsoft Purview, will administer security and compliance settings across our largest enterprise SaaS platforms (starting with Microsoft 365), and will lead the employee training and organizational change management required for those controls to be adopted and sustained rather than worked

  • Data Loss Prevention and Information Protection
    • Own the design, configuration, tuning, and validation of DLP policies in Microsoft Purview across email, SharePoint, OneDrive, Teams, and endpoints.
    • Build and maintain Sensitive Information Types (SITs), including regex-based detection and trainable classifiers, and validate detection accuracy to reduce false positives and coverage gaps.
    • Administer and govern the sensitivity-label taxonomy, auto-labeling policies, and label-based protection, including the dynamic group / scoping logic that ensures full population coverage.
    • Investigate DLP alerts and policy matches, triage incidents, and partner with the SOC/MDR provider and Security Engineering on escalations.
  • Enterprise SaaS Security Administration
    • Administer the security, compliance, and data-governance settings of large enterprise SaaS solutions, with Microsoft 365 / Purview as the primary platform.
    • Maintain configuration baselines, document control settings, and support periodic posture assessments and audit/risk-assessment requests.
    • Coordinate data-protection requirements for new integrations and data flows (e.g., analytics pipelines, mirrored/replicated data stores, and SaaS-to-SaaS connections).
    • Investigate DLP alerts and policy matches, triage incidents, and partner with the SOC/MDR provider and Security Engineering on escalations.
  • Training and Change Management
    • Develop and deliver end-user training and enablement on sensitivity labels, DLP behavior, and secure data-handling expectations.
    • Lead the change management for new and updated controls - communications, rollout sequencing, stakeholder readiness, and feedback loops - so controls are adopted with minimal business disruption.
    • Partner with business units (e.g., Business Intelligence / Enterprise Analytics and application teams) to translate their data-handling needs into appropriate, workable protection policies.
  • AI Enablement
  • Design, build, and maintain an internal AI assistant/agent that lets employees self-serve answers to security-program questions - e.g., "How do I label this document?", "Can I share this externally?", "What's our policy on personal cloud storage?" - grounded in our own policies, standards, and DLP/labeling guidance.
  • Curate and maintain the knowledge base behind the agent (policies, FAQs, control documentation) so responses stay accurate as the program evolves, and establish guardrails so the agent declines or escalates questions it shouldn't answer.
  • Apply secure-by-design practices to the agent itself: appropriate data handling for prompts/responses, access scoping, and avoidance of sensitive-data exposure through the tool.
  • Identify other practical applications of AI to the data-protection program (e.g., assisting with classification, drafting policy language, or triaging DLP alerts) and pilot them where they add measurable value.
  • Employee Enablement and Communications
    • Produce a recurring IT/security newsletter and related employee communications that build awareness and reinforce good data-handling habits.
    • Develop and deliver general end-user enablement on core productivity tools (e.g., Microsoft Outlook, Excel, Teams), including quick-reference guides, tips, and informal training.
    • Serve as point of contact for employee "how do I..." questions on IT and productivity tools, and feed recurring questions back into training material and the AI assistant.
JOB REQUIREMENTS
Education
  • Bachelor's degree in cybersecurity, information security, computer science, information technology, or a related field - or equivalent hands-on experience.
Experience
  • 5+ years in information security or IT
  • 3+ years of hands on Microsoft Purview/DLP experience
Knowledge / Technical Requirements
  • Hands-on Microsoft Purview experience: DLP policies, sensitivity labels, Sensitive Information Types, trainable classifiers, and the M365 compliance/security portals.
  • Working knowledge of Microsoft 365 / Entra ID administration: dynamic groups, scoping, role-based access, and tenant security/compliance settings.
  • Practical regex skills and an understanding of data classification methodology.
  • Familiarity with the broader Microsoft security stack (Defender, Sentinel) and how DLP/labeling data flows into monitoring
  • Ability to build and maintain an AI assistant/agent for internal users, using a retrieval-augmented (knowledge-grounded) approach so answers are sourced from our own policies and documentation rather than generic model knowledge.
  • Familiarity with enterprise AI tooling available in our environment - Microsoft Copilot Studio and Security Copilot (both available under E5) and/or general experience with LLM platforms, prompt design, and connecting a model to a curated knowledge base.
  • Judgment around responsible/secure AI use: data privacy of prompts and responses, access control, guardrails, and knowing which questions an automated assistant should elevate to a human rather than answer.
  • Experience iterating on the agent based on real employee questions, and measuring whether it actually deflects routine queries and improves security awareness.
  • Experience in a regulated / sensitive-data environment (healthcare, medical device, PHI/PII, or IP-heavy manufacturing).
  • ServiceNow or similar ITSM ticketing workflow experience.
  • Relevant certifications: Microsoft SC-400 (Information Protection & Compliance Administrator), SC-401, SC-200, or equivalent.
Competencies, Skills & Abilities
  • Demonstrated ability to drive change management and user adoption for security controls - not just configure them.
  • Strong written and verbal communication; able to create training material and brief both technical and non-technical audiences.
  • Stakeholder management across business and IT teams, with the patience to negotiate workable controls.
  • Ability to create employee-facing communications (e.g., a newsletter) and coaching non-technical staff on everyday productivity tools (Outlook, Excel, Teams); approachable, patient, and able to explain technology in easy to understand terms

The target pay rate for this position is between $86000 - $117,000 annually. Factors which may affect starting pay within this range may include: geography/market, skills, education, experience and other qualifications of the successful candidate.

This position is eligible for a bonus based upon performance results. There is no guarantee of payout.

The following benefits for this position, subject to applicable eligibility requirements, include medical, dental and vision insurance, 401(k) retirement plan with company match, company-paid life and short-term disability insurance, long-term disability insurance, employee assistance plan, hearing aid benefits, Paid Time Off, paid holidays, paid floating holidays, paid volunteer service day, paid paternity and maternity leave and tuition reimbursement.

#LI-MP1

Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities

This employer is required to notify all applicants of their rights pursuant to federal employment laws.

For further information, please review the Know Your Rights notice from the Department of Labor.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr Data Protection & Governance Analyst
Sr Data Protection & Governance Analyst

Starkey Laboratories • Eden Prairie (MN)

On-site
USD 86,000 - 117,000
Medical Insurance
Dental & Vision Insurance
401(k) Matching
+4
Sr Data Protection & Governance Analyst
Sr Data Protection & Governance Analyst

Starkey Hearing • Eden Prairie (MN)

On-site
USD 86,000 - 117,000
Medical insurance
Dental and vision insurance
401(k) with company match
+2
Senior Information Security Engineer - Data Protection & Insider Risk
Senior Information Security Engineer - Data Protection & Insider Risk

Cravath, Swaine & Moore LLP • New York (NY)

Hybrid
USD 160,000 - 200,000
Medical, dental, vision insurance
401(k) plan with company match
Paid time off and health club benefits
+1
Microsoft Purview and Data Protection Engineer
Microsoft Purview and Data Protection Engineer

The Carlyle Group • Washington

On-site
USD 160,000 - 180,000
Health insurance
Retirement benefits
Paid time off
Microsoft Purview and Data Protection Engineer
Microsoft Purview and Data Protection Engineer

1P284 THE CARLYLE GROUP EMPLOYEE CO., LLC • Washington

Hybrid
USD 160,000 - 180,000
Data Security Analyst
Data Security Analyst

clarivate • Kansas City (MO)

Hybrid
USD 105,000 - 145,000
Data Protection & Governance Lead — AI-Driven Security (M365)
Data Protection & Governance Lead — AI-Driven Security (M365)

Starkey Hearing • Eden Prairie (MN)

On-site
USD 86,000 - 117,000
Medical insurance
Dental and vision insurance
401(k) with company match
+2
Data Security Specialist
Data Security Specialist

Milbank LLP • New York (NY)

On-site
USD 140,000 - 160,000
Data Security Analyst
Data Security Analyst

Clarivate • Philadelphia

Hybrid
USD 90,000 - 120,000
Cyber Security Engineer
Cyber Security Engineer

Milwaukee Succeeds • Milwaukee (WI)

On-site
USD 80,000 - 100,000
401(k) with employer match
Medical, dental, and vision insurance
Paid time off (PTO) and holidays
+2