Data Protection Analyst

AcrisureAtlanta, GA
Onsite

About The Position

The Data Protection Analyst is responsible for monitoring, investigating, and responding to data protection, insider risk, and data exfiltration events across the organization. This role serves as a key member of the Cybersecurity team, leveraging Microsoft Purview, ServiceNow, Microsoft 365, and other security technologies to identify, investigate, and mitigate threats involving sensitive company, client, financial, and regulated data. The Analyst partners closely with Security Operations, Legal, Human Resources, Privacy, and IT teams to support insider risk investigations, eDiscovery requests, data subject access requests (DSARs), and data protection initiatives. This position plays a critical role in protecting Acrisure information assets while ensuring investigations are conducted in accordance with legal, regulatory, and privacy requirements. Success in this role means protecting Acrisure's sensitive data by quickly identifying, investigating, and mitigating insider risk and data protection incidents before they become business, legal, regulatory, or reputational events. You will deliver high-quality investigations, improve detection fidelity, and provide actionable insights that strengthen data protection controls, reduce risk, and support informed decisions across Security, Legal, HR, Privacy, and business leadership.

Requirements

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Criminal Justice, or a related field, or equivalent practical experience.
  • 2+ years of experience in Security Operations, Cybersecurity, Insider Risk, Digital Forensics, eDiscovery, Compliance, Privacy, or Incident Response.
  • Experience investigating security events and user activity involving sensitive information.
  • Working knowledge of Microsoft 365 security, collaboration, and data protection capabilities.
  • Experience using case management platforms such as ServiceNow or similar systems.
  • Strong analytical, investigative, documentation, and communication skills.
  • Ability to work with sensitive matters and partner appropriately with Legal, HR, Privacy, Compliance, IT, and business stakeholders.

Nice To Haves

  • Experience with Microsoft Purview Insider Risk Management.
  • Experience with Microsoft Purview DLP, eDiscovery, and Information Protection.
  • Experience supporting HR, Legal, Privacy, Compliance, or regulatory investigations.
  • Knowledge of data protection, privacy, employee monitoring, and regulated data handling concepts.
  • Security certifications such as SC-200, SC-400, GCFA, GCFE, GCIH, Security+, CySA+, or similar.

Responsibilities

  • Monitor and investigate insider risk alerts, suspicious user activity, data exfiltration attempts, and DLP incidents.
  • Conduct investigations related to mass downloads, large-scale sharing, data staging, privileged account misuse, and potential account compromise.
  • Triage and document insider risk cases using the enterprise case management process.
  • Collect, preserve, and analyze evidentiary data in support of investigations.
  • Coordinate with Legal, Human Resources, Privacy, Compliance, and management teams during investigations.
  • Monitor DLP alerts across Microsoft 365, endpoints, email, SharePoint, OneDrive, Teams, and cloud collaboration platforms.
  • Review policy violations and user justifications to identify repeat patterns, emerging risk, and areas requiring policy tuning.
  • Assist with tuning detection use cases to improve signal quality and reduce false positives.
  • Track and report key metrics including alert volume, true positive rate, time to triage, time to case closure, aged cases, and repeat patterns.
  • Support eDiscovery, litigation hold, DSAR, regulatory inquiry, departing employee review, HR investigation, and security investigation activities.
  • Use ServiceNow and Microsoft Purview capabilities to manage investigation workflows and evidence collection.
  • Maintain accurate case notes, evidence records, timelines, and reporting artifacts.
  • Escalate high-risk cases and policy exceptions to the appropriate Cybersecurity, Legal, HR, Privacy, or business stakeholders.
  • Identify insider risk trends and recommend improvements to detection, response, and escalation processes.
  • Participate in proactive threat hunting involving sensitive data movement and user behavior.
  • Contribute to insider risk playbooks, response procedures, dashboards, and operational standards.
  • Support data protection awareness efforts by identifying common user behaviors and recurring policy friction points.

Benefits

  • Comprehensive medical insurance
  • dental insurance
  • vision insurance
  • life and disability insurance
  • fertility benefits
  • wellness resources
  • paid sick time
  • Generous paid time off
  • holidays
  • Employee Assistance Program (EAP)
  • complimentary Calm app subscription
  • Immediate vesting in a 401(k) plan
  • Health Savings Account (HSA) and Flexible Spending Account (FSA) options
  • commuter benefits
  • employee discount programs
  • Paid maternity leave
  • paid paternity leave (including for adoptive parents)
  • legal plan options
  • pet insurance coverage
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service