
Senior Data Loss Prevention Analyst
Posted Aug 13

Posted Aug 13
This is a fully remote position, open to applicants in Illinois.
• Lead intricate and sensitive investigations into data loss, managing the process from initial alert to documentation and resolution, which may include insider-risk cases.
• Act as the primary escalation contact for the DLP team, offering guidance and conducting second-level case reviews.
• Design, develop, test, and optimize DLP policies and detection rules within Microsoft Purview.
• Create and sustain Splunk searches, correlation logic, dashboards, and reports to facilitate investigations, alert triage, and program metrics.
• Analyze alert queues to spot tuning opportunities, detection gaps, and emerging use cases.
• Integrate DLP telemetry with endpoint, email, cloud, identity, and network logs to probe potential data exfiltration incidents.
• Assist in the transition from the legacy DLP platform by mapping use cases, translating policies, validating tests, and ensuring detection parity.
• Collaborate with Legal, HR, Compliance, and Privacy teams on cross-functional investigations.
• Compile written reports for both technical and non-technical audiences.
• Mentor junior analysts while documenting investigative processes, playbooks, and runbooks.
• Bachelor’s Degree in Information Security, Computer Science, or a related discipline with 6 years of experience; or a Master’s Degree with 5 years of experience; or a PhD with no experience required.
• Proven experience in information security, particularly focused on data loss prevention or insider risk.
• Practical experience with Microsoft Purview DLP, encompassing policy creation, rule tuning, and alert investigation across endpoint, email, and cloud channels.
• Experience with Microsoft Purview Insider Risk Management is highly desirable.
• Familiarity with Splunk, including crafting SPL searches, developing dashboards and correlation logic, and assisting security investigations.
• Strong analytical and investigative abilities, capable of independently handling complex cases and drawing defensible conclusions from incomplete or ambiguous data.
• Knowledge of data classification, regulatory requirements such as HIPAA, GDPR, and PCI-DSS, and common data exfiltration techniques.
• Exceptional written communication skills for documenting findings intended for legal, HR, and executive audiences.
• Preferred: Over 5 years of experience in information security, with a minimum of 3 years specifically dedicated to data loss prevention or insider risk.
• Paid time off (vacation, holidays, sick leave).
• Medical, dental, and vision insurance coverage.
• 401(k) retirement plan.
• Eligibility to participate in short-term incentive programs.
Luxury Presence
Logitech
Get handpicked remote jobs straight to your inbox weekly.