Data Protection Analyst
Acrisure Atlanta, Georgia, United States
Financial Services · 10,001+ employees
About the role
The Data Protection Analyst monitors, investigates, and responds to insider risk and data exfiltration events using tools like Microsoft Purview and ServiceNow. They collaborate with Legal, HR, and Privacy teams to conduct investigations and improve data protection controls.
What they look for
Requirements
Candidates must have a bachelor's degree in a relevant field and at least 2 years of experience in cybersecurity, forensics, or compliance. Proficiency in Microsoft 365 security tools and case management systems is required.
Benefits
Full description
About Acrisure
A global fintech leader, Acrisure empowers millions of ambitious businesses and individuals with the right solutions to grow boldly forward. By bringing cutting-edge technology and top-tier human support together, we connect clients with customized solutions across insurance, reinsurance, payroll, benefits, cybersecurity, mortgage services — and more.
In the last twelve years, Acrisure has grown in revenue from $38 million to nearly $5 billion, with over 19,000 colleagues in more than 20 countries. Acrisure was built on entrepreneurial spirit. Prioritizing leadership, accountability, and collaboration, we equip our teams to work at the highest levels possible.
Job Summary
The Data Protection Analyst is responsible for monitoring, investigating, and responding to data protection, insider risk, and data exfiltration events across the organization. This role serves as a key member of the Cybersecurity team, leveraging Microsoft Purview, ServiceNow, Microsoft 365, and other security technologies to identify, investigate, and mitigate threats involving sensitive company, client, financial, and regulated data.
The Analyst partners closely with Security Operations, Legal, Human Resources, Privacy, and IT teams to support insider risk investigations, eDiscovery requests, data subject access requests (DSARs), and data protection initiatives. This position plays a critical role in protecting Acrisure information assets while ensuring investigations are conducted in accordance with legal, regulatory, and privacy requirements.
Success in this role means protecting Acrisure's sensitive data by quickly identifying, investigating, and mitigating insider risk and data protection incidents before they become business, legal, regulatory, or reputational events. You will deliver high-quality investigations, improve detection fidelity, and provide actionable insights that strengthen data protection controls, reduce risk, and support informed decisions across Security, Legal, HR, Privacy, and business leadership.
Responsibilities:
Insider Risk Operations
- Monitor and investigate insider risk alerts, suspicious user activity, data exfiltration attempts, and DLP incidents.
- Conduct investigations related to mass downloads, large-scale sharing, data staging, privileged account misuse, and potential account compromise.
- Triage and document insider risk cases using the enterprise case management process.
- Collect, preserve, and analyze evidentiary data in support of investigations.
- Coordinate with Legal, Human Resources, Privacy, Compliance, and management teams during investigations.
Data Protection and DLP Monitoring
- Monitor DLP alerts across Microsoft 365, endpoints, email, SharePoint, OneDrive, Teams, and cloud collaboration platforms.
- Review policy violations and user justifications to identify repeat patterns, emerging risk, and areas requiring policy tuning.
- Assist with tuning detection use cases to improve signal quality and reduce false positives.
- Track and report key metrics including alert volume, true positive rate, time to triage, time to case closure, aged cases, and repeat patterns.
Investigations and Case Management
- Support eDiscovery, litigation hold, DSAR, regulatory inquiry, departing employee review, HR investigation, and security investigation activities.
- Use ServiceNow and Microsoft Purview capabilities to manage investigation workflows and evidence collection.
- Maintain accurate case notes, evidence records, timelines, and reporting artifacts.
- Escalate high-risk cases and policy exceptions to the appropriate Cybersecurity, Legal, HR, Privacy, or business stakeholders.
Threat Detection and Continuous Improvement
- Identify insider risk trends and recommend improvements to detection, response, and escalation processes.
- Participate in proactive threat hunting involving sensitive data movement and user behavior.
- Contribute to insider risk playbooks, response procedures, dashboards, and operational standards.
- Support data protection awareness efforts by identifying common user behaviors and recurring policy friction points.
Minimum Qualifications
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Criminal Justice, or a related field, or equivalent practical experience.
- 2+ years of experience in Security Operations, Cybersecurity, Insider Risk, Digital Forensics, eDiscovery, Compliance, Privacy, or Incident Response.
- Experience investigating security events and user activity involving sensitive information.
- Working knowledge of Microsoft 365 security, collaboration, and data protection capabilities.
- Experience using case management platforms such as ServiceNow or similar systems.
- Strong analytical, investigative, documentation, and communication skills.
- Ability to work with sensitive matters and partner appropriately with Legal, HR, Privacy, Compliance, IT, and business stakeholders.
Preferred Qualifications
- Experience with Microsoft Purview Insider Risk Management.
- Experience with Microsoft Purview DLP, eDiscovery, and Information Protection.
- Experience supporting HR, Legal, Privacy, Compliance, or regulatory investigations.
- Knowledge of data protection, privacy, employee monitoring, and regulated data handling concepts.
- Security certifications such as SC-200, SC-400, GCFA, GCFE, GCIH, Security+, CySA+, or similar.
#LI-CH1
Candidates should be comfortable with an on-site presence to support collaboration, team leadership, and cross-functional partnership.
Why Join Us:
At Acrisure, we’re building more than a business, we’re building a community where people can grow, thrive, and make an impact. Our benefits are designed to support every dimension of your life, from your health and finances to your family and future.
Making a lasting impact on the communities it serves, Acrisure has pledged more than $22 million through its partnerships with Corewell Health Helen DeVos Children's Hospital in Grand Rapids, Michigan, UPMC Children's Hospital in Pittsburgh, Pennsylvania and Blythedale Children's Hospital in Valhalla, New York.
Employee Benefits
We also offer our employees a comprehensive suite of benefits and perks, including:
- Physical Wellness: Comprehensive medical insurance, dental insurance, and vision insurance; life and disability insurance; fertility benefits; wellness resources; and paid sick time.
- Mental Wellness: Generous paid time off and holidays; Employee Assistance Program (EAP); and a complimentary Calm app subscription.
- Financial Wellness: Immediate vesting in a 401(k) plan; Health Savings Account (HSA) and Flexible Spending Account (FSA) options; commuter benefits; and employee discount programs.
- Family Care: Paid maternity leave and paid paternity leave (including for adoptive parents); legal plan options; and pet insurance coverage.
- … and so much more!
This list is not exhaustive of all available benefits. Eligibility and waiting periods may apply to certain offerings. Benefits may vary based on subsidiary entity and geographic location.
Acrisure is an Equal Opportunity Employer. We consider qualified applicants without regard to race, color, religion, sex, national origin, disability, or protected veteran status. Applicants may request reasonable accommodation by contacting leaves@acrisure.com.
Final candidates will be required to complete post-offer verification processes related to the role and in accordance with applicable laws.
California Residents: Learn more about our privacy practices for applicants by visiting the Acrisure California Applicant Privacy Policy.
Recruitment Fraud: Please visit here to learn more about our Recruitment Fraud Notice.
Welcome, your new opportunity awaits you.