Cyber Defense, Analyst – Data Loss Prevention
Invesco Ltd. Charlottetown, Prince Edward Island, Canada · CA$60K–CA$65K/yr
Financial Services · 5,001-10,000 employees
About the role
Lead day-to-day Microsoft DLP monitoring operations, including queue management, alert triage, and escalation oversight. Manage Palo Alto URL Filtering profile activities, including policy changes, governance, and representation in Change Advisory Board meetings.
What they look for
Requirements
Requires 5+ years of experience in cybersecurity operations, data protection, or proxy governance. Candidates should possess hands-on experience with Microsoft DLP and Palo Alto URL filtering tools, along with strong analytical and communication skills.
Benefits
Full description
As one of the world’s leading independent global investment firms, Invesco is dedicated to rethinking possibilities for our clients. By delivering the combined power of our distinctive investment management capabilities, we provide a wide range of investment strategies and vehicles to our clients around the world. If you're looking for challenging work, intelligent colleagues, and exposure across a global footprint, come explore your potential at Invesco.
Job Description
Who we are
With over $2.3 trillion of assets under management, Invesco is one of the world’s leading global investment management firms, headquartered in Atlanta, GA. Spreading across 20 countries and with over 8400 dedicated employees, we are driven by trust and care. As one of the world’s leading asset managers, we are solely dedicated to delivering an investment experience that helps people get more out of life. If you're looking for challenging work, thoughtful colleagues, and a global employer with social values, explore your potential at Invesco.
Your Team
The Cyber Defense team is responsible for threat detection and monitoring along with Microsoft DLP alert monitoring and Palo Alto URL Filtering profile management across the enterprise. The team reviews potential data loss events, supports policy-level analysis, manages URL filtering change requests, and troubleshoots access issues through defined change management controls. The team works closely with DLP Engineering, Insider Risk, Incident Response, Network Security, SASE/Proxy Engineering, CAB stakeholders, and business teams to ensure operational outcomes are consistent, risk-based, and well documented.
Your Role
- Lead day-to-day Microsoft DLP monitoring operations, including queue management, prioritization, SLA tracking, quality review, and escalation oversight.
- Guide Analysts during alert triage, evidence collection, case documentation, and true positive versus false positive validation across email, endpoint, Teams, SharePoint, OneDrive, and cloud activity where applicable.
- Own operational escalation for confirmed, high-risk, repeat, or sensitive data loss events and coordinate with Insider Risk, Incident Response, DLP Engineering, Legal/Compliance, and business stakeholders as needed.
- Identify recurring false positives, noisy DLP rules, URL filtering policy friction, data classification gaps, and process pain points; translate findings into tuning, policy, and automation recommendations.
- Lead Palo Alto URL Filtering profile management activities, including policy edits, URL category/profile changes, whitelisting/blacklisting governance, access troubleshooting, exception handling, and operational impact assessment.
- Manage the change lifecycle for URL Filtering and related proxy governance requests, including intake review, risk assessment, approval coordination, implementation validation, rollback planning, evidence capture, and closure documentation.
- Support approved change windows, including weekends and non-business days, as most Palo Alto URL Filtering profile changes are implemented outside normal business hours.
- Participate in weekend on-call support when required to ensure priority URL Filtering profile changes, troubleshooting, validations, and rollback activities are supported during planned maintenance windows.
- Represent Cyber Defense Operations in Change Advisory Board (CAB) meetings to review upcoming URL Filtering changes, provide operational impact input, support approvals, and ensure business requirements are understood.
- Develop and maintain SOPs, runbooks, quality checklists, knowledge articles, and operational playbooks for DLP monitoring and URL Filtering profile management.
- Coach Analysts, review investigation quality, support onboarding, and help maintain consistent operational standards across the team.
The Experience You Bring
- 5+ years of experience in cybersecurity operations, data protection, DLP operations, proxy governance, security operations, or incident handling; prior lead or senior analyst experience is preferred.
- Hands-on experience with Palo Alto URL Filtering profile management, including Panorama/NGFW or Prisma Access/SASE policy changes, URL categories, security profiles, whitelisting/blacklisting governance, troubleshooting, validation, and rollback support.
- Hands-on experience with Microsoft DLP operations, including alert triage, investigation, evidence collection, dispositioning, escalation, reporting, and operational tuning recommendations.
- Strong experience supporting security change management activities, including request intake, impact assessment, approvals, CAB representation, implementation validation, evidence capture, and closure documentation.
- Flexibility to support planned weekend and non-business day change windows and participate in weekend on-call coverage when required for Palo Alto URL Filtering profile changes and related troubleshooting.
- Strong understanding of Microsoft 365 security/compliance tools, sensitivity labels, data classification concepts, SIEM, ticketing systems, and case management workflows.
- Ability to analyze alert trends, policy friction, control gaps, and recurring operational issues, then convert findings into practical tuning, process, or automation recommendations.
- Strong written communication, stakeholder management, analytical thinking, attention to detail, and ability to produce clear, audit-ready investigation and change records.
Academic Requirements
- Bachelor’s degree in computer science, Information Technology, Cybersecurity, Information Security, or a related discipline is preferred; equivalent practical experience will be considered.
- Professional certifications such as Security+, Network +, CEH, CCNA , CISSP or equivalent are preferred.
The salary range for this position in PEI is 60,000-65,000 per year.
Full Time / Part Time
Full time
Worker Type
Employee
Job Exempt (Yes / No)
No
Workplace Model
Pursuant to Invesco’s Workplace Policy, employees are expected to comply with the firm’s most current workplace model, which as of October 1, 2025, includes spending at least four full days each week working in an Invesco office. This reflects our belief that spending time together in the office helps us build stronger relationships, collaborate more easily, and support each other’s growth and development.
What’s in it for you?
Our people are at the very core of our success and we strive to provide employees with a competitive total rewards package which includes:
- Hybrid working environment
- RRSP Contributions
- Health & Wellness Benefits
- Work flexibility Programs
- Parental Leave Benefits
- Study Support
The above information on this description has been designed to indicate the general nature and level of work performed by employees within this role. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities and qualifications required of employees assigned to this job. The job holder may be required to perform other duties as deemed appropriate by their manager from time to time.
Invesco is committed to fair and accessible employment practices. If selected for an interview, we will work with you to ensure that your interview is accessible and accommodation is provided. Please contact us at accessibility@invesco.ca or 1.800.874.6275 to let us know if you require accommodation for an interview due to a disability.