Security Analyst IV – DLP Monitoring & Response
Job Description
Support enterprise Data Loss Prevention (DLP) monitoring and response by investigating alerts, assessing risk, and coordinating remediation across cloud and on-premises environments.
Responsibilities
- Monitor, investigate, and triage DLP and data protection alerts across multiple security platforms.
- Analyze security events to determine risk, business impact, and appropriate remediation actions.
- Escalate high-risk events according to established incident response procedures.
- Document investigations, findings, and remediation recommendations.
- Identify potential data exposure, unauthorized sharing, and data exfiltration risks.
- Validate alerts and distinguish true positives from false positives.
- Support risk-based prioritization of security events and incidents.
- Ensure activities align with corporate security policies and regulatory requirements.
- Partner with Cyber Defense, Security Engineering, IT, Cloud, Privacy, Legal, Compliance, and business teams.
- Work with data owners and stakeholders to validate business context and support remediation efforts.
- Communicate findings and recommendations to both technical and non-technical audiences.
- Identify recurring trends, policy gaps, and tuning opportunities.
- Support DLP policy optimization, detection improvements, and automation initiatives.
- Contribute to operational playbooks, procedures, and knowledge-sharing efforts.
- Assist in developing metrics, dashboards, and reporting for leadership.
Requirements
- Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, or a related field (or equivalent practical experience may be considered).
- 7+ years of experience in cybersecurity, security operations, incident response, DLP, CASB, cloud security, or data protection.
- Hands-on experience investigating and responding to security or DLP alerts in an enterprise environment.
- Experience with one or more DLP/CASB platforms, including Microsoft Purview, MDCA, Netskope, AWS Macie, or Trellix.
- Familiarity with cloud collaboration platforms and data sharing technologies.
- Understanding of DLP concepts, data classification, and information protection controls.
- Knowledge of incident response processes and security event investigations.
- Experience with cloud security technologies and SaaS applications.
- Familiarity with SIEM tools, dashboards, and security reporting.
- Working knowledge of regulatory/compliance requirements such as PCI, GDPR, CCPA, HIPAA, or similar frameworks.
Technologies
- Microsoft Purview DLP
- Microsoft Defender for Cloud Apps (MDCA)
- Netskope DLP/CASB
- AWS Macie
- Trellix DLP
- Akamai
- Wiz
- SIEM and security monitoring platforms (primarily Tines and Splunk)
Benefits
- Total compensation package
- Annual bonus eligibility for most roles
- 401(k) with a company match
- Opportunity for a company-wide annual discretionary bonus via the Annual Incentive Plan (AIP), up to 10% of eligible pay
Additional Certifications That May Stand Out
- CISSP
- CISM
- Security+
- CEH
- Microsoft Security Certifications
- Netskope Certifications
- AWS Security Certifications
Remote Work
- Remote anywhere in the United States
- Exclusions: Hawaii and Alaska
Salary
- Annual range: USD 116,820 - 155,750 (yearly)
- National average salary range: USD 116,820 - 129,800
- Colorado specific range: USD 116,820 - 142,800
- Annual Incentive Plan (AIP): opportunity for discretionary bonus up to 10% of eligible pay
Visa Sponsorship
- CSAA does not provide visa sponsorship for this role
- Applicants must have authorization to work indefinitely in the US
Reasonable Accommodations
- CSAA is committed to providing reasonable accommodations to qualified applicants and employees with disabilities or other limitations
- To request an accommodation for the application or interview process, contact [email protected]
Location: Phoenix, AZ (remote). Posting unposted on Fri, 2 Oct 2026.