Masco logo
MascoPosted 2 weeks ago

Cybersecurity Analyst - Data Protection, Privacy & Risk

$88,700–$139,260 year

On-siteIndianapolis, Indiana, United States

Full TimeBachelors DegreeEnterprise

Job Summary

Monitor and investigate alerts from data protection and security tools, including DLP, endpoint, and SaaS platforms. Analyze user and data activity to identify unusual behavior, potential policy violations, and elevated risk scenarios. Support internal reviews and investigations by gathering logs, evidence, and relevant contextual information. Drive continuous improvement of DLP policies and detection rules by identifying trends, reducing false positives, and enhancing monitoring effectiveness. Partner with Legal, HR, and other stakeholders on sensitive data protection matters while maintaining confidentiality and professionalism. Support Data Subject Access Requests (DSARs), including intake, tracking, documentation, and fulfillment activities. Maintain data inventories, data flow maps, and records of processing activities (RoPAs). Assist with privacy notices, consent management, and regulatory compliance activities. Support privacy reviews of vendor and third-party agreements to ensure appropriate data protection controls are in place. Support internal control assessments, audits, and remediation tracking activities. Help maintain security policies, standards, and procedures aligned with industry frameworks such as NIST CSF, ISO 27001, and SOC 2. Assist with third-party risk assessments, vendor reviews, and risk scoring activities. Participate in control testing and audit preparation efforts.

Required Qualifications

  • Bachelor's degree or equivalent experience
  • 3+ years of experience in cybersecurity, privacy, data protection, risk management, or a related field
  • Experience with security monitoring, DLP, endpoint security, investigations, or risk assessment activities
  • Familiarity with privacy regulations such as GDPR, CCPA, or HIPAA
  • Strong analytical, organizational, and problem-solving skills
  • Ability to communicate effectively with both technical and non-technical audiences
  • Demonstrated ability to manage sensitive information with professionalism and discretion
  • E-Verify eligibility

Desired Qualifications

  • Security+
  • CIPP/US
  • CIPP/E
  • CISSP
  • CRISC
  • or similar certifications
  • Microsoft Purview (DLP, Insider Risk, eDiscovery)
  • CrowdStrike or similar EDR platforms
  • Google SecOps or other SIEM solutions
  • Netskope, Zscaler, or other SaaS security platforms
  • Okta, SailPoint, or identity governance tools
  • ServiceNow or similar case management platforms

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce