Summary
Community Loan Servicing, LLC is seeking a Data Loss Prevention Analyst to protect sensitive company and customer information. The role monitors and investigates potential data leakage incidents, develops and fine-tunes DLP controls, conducts risk assessments, and collaborates with technical and business teams to support compliance and secure business practices.
Responsibilities
- Continuously monitor and analyze DLP alerts to identify potential data loss incidents, policy violations and risky business practices
- Investigate, escalate and respond to DLP incidents in accordance with security policies and incident response procedures
- Conduct root cause analysis and recommend corrective actions to mitigate data loss risks
- Profile and analyze patterns of data movement to enhance data protection controls and reduce insider risks
- Profile and analyze data discovery and data classification reports to validate true positives and work cross-functionally to mitigate risk exposure
- Develop, implement, and fine-tune DLP policies and rules to prevent unauthorized data access or transmission, and minimize false positives
- Conduct periodic audits and assessments to evaluate the effectiveness of DLP controls
- Assist in the classification and protection of sensitive data, ensuring compliance with organizational policies
- Generate reports on DLP incidents, trends, and security risks, providing recommendations for improvement
- Collaborate with IT, security and business teams to integrate data protection controls into workflows and business processes
- Educate employees on best practices for data security and compliance
- Collaborate with vendors and engineers to optimize technical solutions and address system enhancements
- Troubleshoot issues with end users related to sensitivity labels and DLP controls
- Develop and maintain documentation related to operating procedures, policy configuration, etc
- Develop and update data classification labels and label policies
Skills
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field (or equivalent experience)
- 4+ years of experience in data protection, forensic investigations, incident response, or law enforcement roles
- Strong, hands-on experience with Microsoft Purview (including but not limited to Data Loss Prevention, Information Protection, eDiscovery, and Audit), Microsoft Defender, Netskope, or Zscaler
- Familiarity with Varonis, Splunk, or Microsoft Sentinel, and insider-threat tools is a plus
- Experience with custom regex-based pattern matching, exact data matching, and document indexing
- Experience preparing incident investigation reports and documenting activities
- Understanding of data protection laws, compliance frameworks, and industry best practices
- Knowledge of encryption, network security, endpoint security, and cloud security principles
- Scripting (e.g., Python and PowerShell) experience is a plus
- Experience configuring and managing API-based integrations with business applications to support DLP and CASB monitoring, visibility, and policy enforcement
- Strong analytical, problem-solving, and incident response skills with attention to detail
- Ability to work independently and collaboratively in a fast-paced environment
- Excellent communication skills to interact with technical and non-technical stakeholders
- CISSP, CISA, CEH, CCSP, or Microsoft Certified preferred
Qualifications
Must Haves
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field (or equivalent experience)
- 4+ years of experience in data protection, forensic investigations, incident response, or law enforcement roles
- Strong, hands-on experience with Microsoft Purview (including but not limited to Data Loss Prevention, Information Protection, eDiscovery, and Audit), Microsoft Defender, Netskope, or Zscaler
- Familiarity with Varonis, Splunk, or Microsoft Sentinel, and insider-threat tools is a plus
- Experience with custom regex-based pattern matching, exact data matching, and document indexing
- Experience preparing incident investigation reports and documenting activities
- Understanding of data protection laws, compliance frameworks, and industry best practices
- Knowledge of encryption, network security, endpoint security, and cloud security principles
- Scripting (e.g., Python and PowerShell) experience is a plus
- Experience configuring and managing API-based integrations with business applications to support DLP and CASB monitoring, visibility, and policy enforcement
- Strong analytical, problem-solving, and incident response skills with attention to detail
- Ability to work independently and collaboratively in a fast-paced environment
- Excellent communication skills to interact with technical and non-technical stakeholders
Nice to Haves
- CISSP, CISA, CEH, CCSP, or Microsoft Certified preferred
Benefits
- This is a fully remote position with the option of working a hybrid schedule out of our Coral Gables, FL office.
- Annual bonus
- Medical coverage starting on day one
- A company-matched 401(k)