Senior Data Security Analyst
The Senior Data Security Analyst is responsible for protecting the organization's data by implementing, monitoring, and improving data security controls. This role partners with Cybersecurity, IT, Legal, Privacy, Risk, Audit, and business teams to reduce risk, prevent data loss, support compliance requirements, and strengthen the company's overall security posture. The position will have a strong focus on Data Security Posture Management (DSPM) technology and emerging AI Security controls for enterprise-wide implementation. This role reports to the Cybersecurity Data Security Manager and will work closely with the Data Security Architect.
This is a remote position.
This position is not eligible for sponsorship for work authorization now or in the future, including conversion to H1-B visa. Must be legally authorized to work in the country of employment without needing sponsorship for employment work visa status now or in the future.
Job duties include contact with other employees and access confidential and proprietary information and/or other items of value, and such access may be supervised or unsupervised. The Company therefore has determined that a review of criminal history is necessary to protect the business and its operations and reputation and is necessary to protect the safety of the Company’s staff, employees, and business relationships.
AI Data Security
- Lead the design and implementation of AI runtime security controls for internal and external monitoring.
- Design and integrate AI gateway controls for model oversight and policy enforcement.
- Configure, administer, and optimize enterprise AI security platforms.
- Assess and implement AI connectors, APIs, and integrations required for AI visibility and monitoring.
- Operationalize AI governance workflows, security guardrails, and compliance controls.
Data Security & Risk Management
- Lead data classification and data discovery initiatives.
- Perform risk assessments to identify and reduce data security risks.
- Design, implement, and maintain data protection controls.
- Evaluate applications and systems for security gaps and recommend improvements.
- Lead remediation activities for identified security risks and vulnerabilities.
- Monitor and improve the effectiveness of data security controls.
Security Strategy & Compliance
- Develop and maintain data security standards, procedures, and best practices.
- Support compliance efforts related to GDPR, HIPAA, SOX, CCPA, PCI-DSS, and other regulatory requirements.
- Participate in the development of security policies, standards, and guidelines.
- Stay current on emerging threats, technologies, and industry best practices.
Security Operations
- Monitor security tools and technologies to ensure effective operation.
- Review security alerts, logs, and reports to identify potential threats.
- Support investigations of security incidents and suspicious activity.
- Maintain security configurations and security control baselines.
- Recommend and implement enhancements to existing security solutions.
Reporting & Leadership
- Develop security metrics, dashboards, and executive-level reporting.
- Present risk findings, recommendations, and project updates to leadership.
- Lead or support enterprise-wide security projects and initiatives.
- Mentor junior analysts and provide technical guidance.
Collaboration & Stakeholder Engagement
- Partner with Cybersecurity, IT, Legal, Privacy, Data Governance, Internal Audit, and business teams.
- Build strong relationships across the organization to support security objectives.
- Communicate security requirements, risks, and best practices to stakeholders.
- Support compliance with applicable laws, regulations, and company policies.
Education & Experience
Required:
- Bachelor’s degree (or foreign equivalent) in a Computer Science, Computer Engineering, or Information Technology field of study (e.g., Information Technology, Electronics and Instrumentation Engineering, Computer Systems Management, Mathematics) or equivalent experience.
-
5+ years of Cybersecurity, IT, or business-related experience.
-
3+ years of experience with data protection, data engineering/infrastructure, data governance, or data loss prevention.
-
Fundamental knowledge of NIST CSF Framework and associated Data Protection concepts.
-
Demonstrated skill in leading cross functional projects with business and IT stakeholders.
- Must be eighteen years or older
- Must be legally authorized to work in the United States without company sponsorship
Preferred
- 1+ years of designing or supporting AI platforms, projects, or initiatives.
- Experience working with IT Audit, Compliance, or Information Security.
- Experience working with DSPM and other security technologies (Ex: DLP, EDR, Cloud, SIEM, etc.)
- Working knowledge of information security concepts related to Data Protection methodologies.
- Experience evaluating cyber risks or threats.