Cybersecurity Business Analyst — Data Risk – Offices; Hybrid
Listed on 2026-09-22
-
IT/Tech
Information Security & Data Protection, Cybersecurity, IT Business Analyst
The Cybersecurity Business Analyst - Data Risk, is responsible for identifying, analyzing, and helping remediate risks to the firm’s sensitive and regulated data throughout its lifecycle. The role bridges security, privacy, compliance, and business teams—translating data protection requirements into actionable controls, clear reporting, and prioritized risk decisions that reduce exposure while enabling the business.
This is a hybrid position and can be resident in Phoenix, AZ;
Atlanta, GA;
Minneapolis, MN;
Seattle, WA;
Charlotte, NC;
Miami or Orlando, FL; or Dallas, TX, with an onsite expectation of once per month.
Pursuant to Washington and Minneapolis regulations, the salary range is $137,800 to $151,600 annually and includes eligibility for performance-based bonuses. Factors which may affect starting pay within this range may include geography/market, skills, education, experience and other qualifications of the successful candidate. We offer generous compensation and benefits packages. For more information visit:
Responsibilities Data risk analysis and assessment- Maintain an inventory of sensitive and regulated data, data flows, systems, and third-party sharing.
- Conduct data risk assessments covering confidentiality, integrity, availability, and regulatory exposure.
- Analyze data classification, access, retention, and handling to identify gaps and control weaknesses.
- Quantify and prioritize data risks, and track remediation activities through to closure.
- Support data classification, DLP, and data protection policies and standards.
- Translate privacy and regulatory requirements (e.g., GDPR, CCPA, HIPAA where applicable) into data control requirements.
- Partner with control owners to define, document, and validate data safeguards.
- Monitor control effectiveness and produce metrics on the firm’s data risk posture.
- Gather and document business and security requirements for data protection initiatives.
- Build dashboards and reports on data risk, exposure, and remediation progress for leadership.
- Perform root-cause and trend analysis on data incidents, DLP alerts, and access anomalies.
- Support audits and client assessments with data risk evidence and documentation.
- Serve as a liaison between Security, Privacy, Risk, IT, and business stakeholders.
- Translate technical data risks into clear business language and actionable recommendations.
- Provide guidance that helps teams handle data safely and meet compliance obligations.
- Support response to data-related incidents, findings, and control failures.
- Experience in a legal, professional services, or other highly regulated environment.
- Familiarity with data governance and risk platforms (e.g., One Trust, Microsoft Purview, Service Now).
- Comfort with data analysis and visualization tools (e.g., Excel / Power BI) and basic querying (e.g., SQL).
- Core security / risk: CISM, CRISC, or CISSP.
- Data / privacy: CIPP, CIPM, or CDPSE.
- Governance / analysis: ISO/IEC 27001 lead implementer/auditor or a recognized business analysis certification (e.g., CBAP).
Littler is the largest global employment and labor law practice in the world exclusively devoted to representing management. With more than 1,900 attorneys in over 100 offices worldwide, Littler serves as the single source solution provider to the global employer community. Consistently recognized in the industry as a leading and innovative law practice, Littler has been litigating, mediating and negotiating some of the most influential employment law cases and labor contracts on record for over 75 years.
Littler’s unparalleled commitment to labor and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).