Data Security Analyst, Team Lead
Listed on 2026-06-10
-
IT/Tech
Cybersecurity, Information Security, Data Security, Security Manager
Southern Company Cybersecurity
Job Description:
Title:
Data Security Analyst, Team Lead
Schedule: M-F (4 days onsite, 1 day remote)
Grade Level: 6 or 7
Location: Atlanta or Birmingham
Position Summary:
Southern Company is seeking a highly capable and operationally focused Lead Data Security Analyst (Team Lead) to support and help scale the enterprise Data Security Program. This role serves as both a hands‑on senior analyst and frontline team lead, responsible for executing advanced data security operations while providing day‑to‑day guidance and oversight for a small team of analysts.
This individual will perform all core Data Security Analyst responsibilities, including DLP/DSPM policy deployment, alert triage, tuning, and encryption validation, while also driving operational consistency, prioritization, quality control, and continuous improvement across the team.
The Lead Data Security Analyst will coordinate closely with Cybersecurity leadership, Incident Response, Legal, Privacy, Compliance, and business stakeholders to ensure effective risk reduction outcomes. Success in this role requires strong technical depth, operational discipline, and the ability to lead through influence, driving high‑quality execution while balancing security risk with business productivity.
Job Responsibilities:
Deploy, configure, and maintain DLP and DSPM policies across in‑scope channels (e.g., email, endpoints, SaaS/cloud repositories, etc.) in alignment with program standards and priorities.
Provide day‑to‑day guidance and task prioritization for a team of analysts to ensure consistent operational coverage.
Review analyst work (alert handling, investigations, tuning changes, documentation) to ensure quality and adherence to standards.
Act as the primary escalation point for analysts and remove blockers to maintain workflow efficiency.
Drive consistent use of runbooks, playbooks, and standard operating procedures.
Coach and mentor other analysts to build technical capability and investigative maturity.
Monitor, review, and triage data security alerts; determine severity and next steps, perform initial investigation, and document findings and actions.
Execute defined response actions (e.g., alert, notify, quarantine, block, restrict sharing, require encryption) and follow established workflows for incident handling and escalation.
Tune and improve DLP rules, detection logic, and policies to reduce false positives, improve signal quality, and minimize business disruption.
Support deployment and ongoing execution of data encryption controls for sensitive data at rest and in transit, in alignment with enterprise encryption standards and data handling requirements.
Coordinate encryption enablement activities with platform teams, data owners, and application teams, including validation, testing, and documentation of implemented controls.
Support data classification and labeling efforts by validating detections, refining patterns/classifiers, and assisting with coverage expansion and quality improvements.
Conduct basic investigations by correlating alert details with relevant logs/telemetry and partnering with the SOC/IR teams when additional investigative depth is needed.
Identify when to engage key stakeholders (e.g., Legal, Privacy, Compliance, HR, business owners) and coordinate escalation pathways based on defined criteria.
Create and maintain operational documentation, including runbooks, response playbooks, encryption validation steps, and standard operating procedures.
Track and report operational metrics such as alert volumes, false positives, time‑to‑resolution, and recurring themes requiring control or policy changes.
Participate in continuous improvement activities, including encryption coverage expansion, policy reviews, rule enhancements, and operational process improvements.
Work effectively within an analyst team by sharing workload, coordinating priorities, maintaining coverage, and supporting a customer‑focused service mindset.
Promote a culture of accountability, collaboration, and operational excellence while supporting the broader Data Security Program’s goals.
Requirements and qualifications:
Minimum
3+ year(s) of…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).