Data Protection Analyst
Listed on 2026-08-20
-
IT/Tech
Information Security & Data Protection, Cybersecurity
About Acrisure
A global fintech leader, Acrisure empowers millions of ambitious businesses and individuals with the right solutions to grow boldly forward. By bringing cutting-edge technology and top-tier human support together, we connect clients with customized solutions across insurance, reinsurance, payroll, benefits, cybersecurity, mortgage services — and more.
In the last twelve years, Acrisure has grown in revenue from $38 million to nearly $5 billion, with over 19,000 colleagues in more than 20 countries. Acrisure was built on entrepreneurial spirit. Prioritizing leadership, accountability, and collaboration, we equip our teams to work at the highest levels possible.
Job SummaryThe Data Protection Analyst is responsible for monitoring, investigating, and responding to data protection, insider risk, and data exfiltration events across the organization. This role serves as a key member of the Cybersecurity team, leveraging Microsoft Purview, Service Now, Microsoft 365, and other security technologies to identify, investigate, and mitigate threats involving sensitive company, client, financial, and regulated data.
The Analyst partners closely with Security Operations, Legal, Human Resources, Privacy, and IT teams to support insider risk investigations, eDiscovery requests, data subject access requests (DSARs), and data protection initiatives. This position plays a critical role in protecting Acrisure information assets while ensuring investigations are conducted in accordance with legal, regulatory, and privacy requirements.
Success in this role means protecting Acrisure's sensitive data by quickly identifying, investigating, and mitigating insider risk and data protection incidents before they become business, legal, regulatory, or reputational events. You will deliver high-quality investigations, improve detection fidelity, and provide actionable insights that strengthen data protection controls, reduce risk, and support informed decisions across Security, Legal, HR, privacy, and business leadership.
ResponsibilitiesInsider Risk Operations
- Monitor and investigate insider risk alerts, suspicious user activity, data exfiltration attempts, and DLP incidents.
- Conduct investigations related to mass downloads, large-scale sharing, data staging, privileged account misuse, and potential account compromise.
- Triage and document insider risk cases using the enterprise case management process.
- Collect, preserve, and analyze evidentiary data in support of investigations.
- Coordinate with Legal, Human Resources, Privacy, Compliance, and management teams during investigations.
- Monitor DLP alerts across Microsoft 365, endpoints, email, SharePoint, One Drive, Teams, and cloud collaboration platforms.
- Review policy violations and user justifications to identify repeat patterns, emerging risk, and areas requiring policy tuning.
- Assist with tuning detection use cases to improve signal quality and reduce false positives.
- Track and report key metrics including alert volume, true positive rate, time to triage, time to case closure, aged cases, and repeat patterns.
- Support eDiscovery, litigation hold, DSAR, regulatory inquiry, departing employee review, HR investigation, and security investigation activities.
- Use Service Now and Microsoft Purview capabilities to manage investigation workflows and evidence collection.
- Maintain accurate case notes, evidence records, timelines, and reporting artifacts.
- Escalate high-risk cases and policy exceptions to the appropriate Cybersecurity, Legal, HR, privacy, or business stakeholders.
- Identify insider risk trends and recommend improvements to detection, response, and escalation processes.
- Participate in proactive threat hunting involving sensitive data movement and user behavior.
- Contribute to insider risk playbooks, response procedures, dashboards, and operational standards.
- Support data protection awareness efforts by identifying common user behaviors and recurring policy friction points.
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Criminal Justice, or a related field, or equivalent practical experience.
- 2+ years of experience in Security Operations, Cybersecurity, Insider Risk, Digital Forensics, eDiscovery, Compliance, Privacy, or Incident Response.
- Experience investigating security events and user activity involving sensitive information.
- Working knowledge of Microsoft 365 security, collaboration, and data protection capabilities.
- Experience using case management platforms such as Service Now or similar systems.
- Strong analytical, investigative, documentation, and communication skills.
- Ability to work with sensitive matters and partner appropriately with Legal, HR, privacy, Compliance, IT, and business stakeholders.
- Experience with Microsoft Purview Insider Risk Management.
- Experience with Microsoft Purview DLP,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).