Lead Security Analyst (DLP/DSPM)

GartnerIrving, TX
Hybrid

About The Position

Gartner's Information Security Team is seeking a motivated Lead Security Analyst to join their Human Cyber Risk & Assessment Team. This role is crucial for safeguarding the organization from human-centric cyber threats by identifying, assessing, and mitigating risks associated with human behavior. The ideal candidate will have 5-7 years of experience in Information Security, with a passion for proactive security measures and building a strong security posture.

Requirements

  • Bachelor's degree in Computer Science, Information Security, or a related field (relevant experience may be considered in lieu of a degree).
  • 5-7 years of hands-on experience in Information Security, with a focus on human cyber risk, data loss prevention, and insider threat.
  • Strong understanding of information security best practices, frameworks (e.g., NIST, ISO 27001), and regulatory requirements.
  • In-depth knowledge of Data Loss Prevention (DLP) principles, technologies, and implementation strategies.
  • Proven experience with Insider Risk Management methodologies and tools.
  • Familiarity with current attack vectors tied to human actors, including phishing, social engineering, business email compromise (BEC), and malware delivery.
  • Technical & Data Security Capabilities: Hands-on experience with Data Loss Prevention (DLP) and Data Security Posture Management (DSPM) platforms to govern unstructured data and prevent exfiltration.
  • Experience with Email Security platforms and Endpoint Protection tools (device control, USB policy enforcement, local storage monitoring).
  • Proficiency in analyzing data security telemetry across cloud platforms (e.g., M365 Purview, Google Workspace, OneDrive/SharePoint).
  • Human Cyber Risk & Governance: Experience analyzing human risk indicators, insider threat telemetry, or security awareness campaign metrics (e.g., phishing performance, EDP training completions).
  • Understanding of Acceptable Use Policies (AUP) and experience managing risk-based exception workflows without causing business disruption.
  • Professional & Analytical Skills: Strong analytical skills with a proven track record of investigating data security alerts, performing root-cause analysis, and evaluating complex employee risk profiles.
  • Exceptional written and verbal communication skills, specifically the ability to conduct empathetic yet firm security remediations with employees and present risk insights to leadership (HR, Legal, IT).
  • Self-starter with the ability to manage independent investigations while collaborating seamlessly across a global security organization.

Nice To Haves

  • Relevant security certifications (e.g., CISSP, CISM, GSEC, Security+, SSAP).

Responsibilities

  • Conduct comprehensive assessments of human-centric cyber risks, identifying vulnerabilities and potential attack vectors tied to human actors like phishing, social engineering, and insider threats.
  • Design, implement, and manage Data Loss Prevention (DLP) strategies and controls to prevent unauthorized disclosure or exfiltration of sensitive information.
  • Monitor DLP alerts, investigate incidents, and recommend remediation steps.
  • Develop and implement programs to detect, analyze, and mitigate insider risks, including monitoring user behavior and collaborating with relevant stakeholders (e.g., HR, Legal) on incident response.
  • Stay ahead of current attack vectors, trends, and techniques used by threat actors targeting human vulnerabilities, proactively identifying emerging threats and recommending countermeasures.
  • Advocate for and ensure adherence to information security best practices across the organization, especially regarding human behavior and data handling.
  • Configure, monitor, and optimize security tools relevant to human cyber risk.
  • Support during security incidents related to human-centric threats, assisting with investigation, containment, eradication, and recovery efforts.
  • Contribute to the development and delivery of security awareness training programs to educate employees on human cyber risks and best practices.
  • Generate reports on human cyber risk posture, incident metrics, and the effectiveness of security controls, while maintaining accurate documentation of security processes.
  • Collaborate with cross-functional teams, including IT Operations, Legal, HR, and other security teams, to achieve security objectives.
  • Present Security Risk Findings to Leadership.
  • Assist with mentoring Junior Level Analysts.

Benefits

  • Competitive compensation.
  • Limitless growth and learning opportunities.
  • Ongoing mentorship and apprenticeship; Leadership courses, development programs, technical courses, certification opportunities and more!
  • A collaborative and positive culture.
  • A chance to make an impact.
  • Hybrid Work Environment.
  • 20+ PTO days plus holidays and floating holidays in your first year.
  • Extensive medical, dental insurance and vision plan.
  • 401K with corporate match, immediate vesting.
  • Health-and-wellness-related allowance programs.
  • Parental leave.
  • Tuition reimbursement.
  • Employee Stock Purchase Plan.
  • Employee Assistance Program.
  • Gartner Gives Charity Match.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service