Security Analyst DLP- W
Listed on 2026-07-24
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Security Management & Operations
Location: Columbia
W-2 ONLY
No subcontracting
No sponsorship
Security Analyst Security Analyst Position Summary/Job PurposeThe purpose of this position is to support the agency’s cybersecurity and data protection program by helping protect sensitive information, monitor security risks, and strengthen controls around AI, Copilot, DLP, Insider Risk, auditing, and vendor security.
Position DetailsThis position supports the agency’s cybersecurity and data protection operations, with a focus on DLP, Insider Risk Management, Copilot/AI data security, auditing, vendor security reviews, and device patching. The analyst will review and triage security alerts, investigate access and movement of sensitive information, perform system and vendor audits, document findings, assist with incident escalation, and work with technical and business teams to strengthen the agency’s overall security and data governance posture.
Key Responsibilities Data Protection & Data Governance- Monitor and administer Data Loss Prevention (DLP) policies and controls.
- Investigate potential data loss, data exposure, and unauthorized access incidents.
- Support Data Security Posture Management (DSPM) initiatives related to AI and Copilot.
- Review the movement, storage, and sharing of sensitive information.
- Assist in implementation of data classification and data handling requirements.
- Participate in data governance initiatives and support data owners and stewards.
- Review and triage security alerts from DLP, Insider Risk Management, DSPM, and other security platforms.
- Investigate suspicious activity involving sensitive information.
- Document findings and maintain investigation records.
- Escalate incidents according to agency incident response procedures.
- Assist with containment, recovery, and post-incident activities.
- Monitor Insider Risk Management alerts and cases.
- Analyze user activity associated with potential policy violations.
- Conduct investigations while maintaining confidentiality and proper chain of evidence.
- Recommend corrective actions and risk mitigation strategies.
- Participate in third-party and vendor security assessments.
- Review vendor security documentation, audit reports, and questionnaires.
- Identify cybersecurity risks associated with third-party services.
- Assist in tracking remediation efforts and risk acceptance decisions.
- Support cybersecurity audits and compliance reviews.
- Collect and analyze evidence for regulatory and policy requirements.
- Assist with risk assessments and control validation activities.
- Maintain documentation supporting compliance efforts.
- Work with technical and non-technical staff to address security concerns.
- Prepare reports, metrics, and presentations regarding security risks and trends.
- Participate in cybersecurity awareness and training initiatives.
- Recommend improvements to security policies, procedures, and controls.
Work Location:
Hybrid (3 days in office, 2 days remote).
Candidate MUST be an SC resident. No relocation allowed.
Must Have / Required Skills- The candidate must have 3‑5+ years experience supporting enterprise cybersecurity operations, including threat monitoring, incident response, and risk analysis.
- The candidate must have 3 years hands‑on experience working with data protection technologies such as data loss prevention (DLP), insider risk management tools, and data security posture management for AI (DSPM for AI).
- The candidate must have 3 years experience reviewing and triaging data‑related security alerts, analyzing access and movement of sensitive information, documenting findings, and escalating incidents according to established procedures.
- The candidate must have 3 years collaborating with technical and non‑technical teams to resolve security issues and supporting continuous improvement in the agency’s data security posture.
- A bachelor’s degree in cybersecurity, information technology, computer science, or a related field is required; equivalent experience may be considered.
- A foundational security certification such as CompTIA Security+ or GIAC Security Essentials (GSEC) is required.
- Experience working with AI‑driven security tools, Cortex, particularly DSPM platforms designed to manage sensitive data used by AI systems.
- Experience fine tuning DLP policies, refining insider risk alerts, or supporting data governance programs.
- Familiarity with Azure security, identity‑based access controls, conditional access, and security automation or scripting.
- Microsoft SC100, SC200, CEH, or an Associate level CISSP Certifications.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).