Acrisure

Data Protection Analyst

Acrisure$80K — $95K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Cybersecurity, IT, Computer Science, Criminal Justice, or a related field, or equivalent experience.
  • 2+ years in Security Operations, Cybersecurity, Insider Risk, Digital Forensics, or Incident Response.
  • Experience investigating incidents involving sensitive information.
  • Working knowledge of Microsoft 365 security and data protection features.
  • Familiarity with case management tools like ServiceNow.
  • Strong analytical, investigative, and documentation skills.
  • Able to collaborate effectively across legal, HR, privacy, and IT teams.

Responsibilities

  • Monitor and investigate insider risk alerts and suspicious activities.
  • Conduct investigations on data misuse and potential account compromises.
  • Document and manage insider risk cases in the enterprise case management system.
  • Collect and analyze evidentiary data for investigations.
  • Coordinate with various teams during investigation processes.
  • Monitor DLP alerts across diverse platforms like Microsoft 365 and OneDrive.
  • Support eDiscovery and related investigation activities.

Benefits

  • Collaborative work environment fostering open communication.
  • Opportunities for professional development and growth.
  • Engagement in cross-functional partnerships.
  • Exposure to advanced security technologies and practices.
  • Role in enhancing data protection initiatives across the organization.
Full Job Description


Job Summary

The Data Protection Analyst is responsible for monitoring, investigating, and responding to data protection, insider risk, and data exfiltration events across the organization. This role serves as a key member of the Cybersecurity team, leveraging Microsoft Purview, ServiceNow, Microsoft 365, and other security technologies to identify, investigate, and mitigate threats involving sensitive company, client, financial, and regulated data.

The Analyst partners closely with Security Operations, Legal, Human Resources, Privacy, and IT teams to support insider risk investigations, eDiscovery requests, data subject access requests (DSARs), and data protection initiatives. This position plays a critical role in protecting Acrisure information assets while ensuring investigations are conducted in accordance with legal, regulatory, and privacy requirements.

Success in this role means protecting Acrisure's sensitive data by quickly identifying, investigating, and mitigating insider risk and data protection incidents before they become business, legal, regulatory, or reputational events. You will deliver high-quality investigations, improve detectionfidelity, and provide actionable insights that strengthen data protection controls, reduce risk, and support informed decisions across Security, Legal, HR, Privacy, and business leadership.

Responsibilities:

Insider Risk Operations 

  • Monitor and investigate insider risk alerts, suspicious user activity, data exfiltration attempts, and DLP incidents. 
  • Conduct investigations related to mass downloads, large-scale sharing, data staging, privileged account misuse, and potential account compromise. 
  • Triage and document insider risk cases using the enterprise case management process. 
  • Collect, preserve, and analyze evidentiary data in support of investigations. 
  • Coordinate with Legal, Human Resources, Privacy, Compliance, and management teams during investigations. 

Data Protection and DLP Monitoring

  • Monitor DLP alerts across Microsoft 365, endpoints, email, SharePoint, OneDrive, Teams, and cloud collaboration platforms.
  • Review policy violations and user justifications to identify repeat patterns, emerging risk, and areas requiring policy tuning.
  • Assist with tuning detection use cases to improve signal quality and reduce false positives.
  • Track and report key metrics including alert volume, true positive rate, time to triage, time to case closure, aged cases, and repeat patterns.

Investigations and Case Management

  • Support eDiscovery, litigation hold, DSAR, regulatory inquiry, departing employee review, HR investigation, and security investigation activities.
  • Use ServiceNow and Microsoft Purview capabilities to manage investigation workflows and evidence collection.
  • Maintain accurate case notes, evidence records, timelines, and reporting artifacts.
  • Escalate high-risk cases and policy exceptions to the appropriate Cybersecurity, Legal, HR, Privacy, or business stakeholders.

Threat Detection and Continuous Improvement

  • Identify insider risk trends and recommend improvements to detection, response, and escalation processes.
  • Participate in proactive threat hunting involving sensitive data movement and user behavior.
  • Contribute to insider risk playbooks, response procedures, dashboards, and operational standards.
  • Support data protection awareness efforts by identifying common user behaviors and recurring policy friction points.

Minimum Qualifications

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Criminal Justice, or a related field, or equivalent practical experience.
  • 2+ years of experience in Security Operations, Cybersecurity, Insider Risk, Digital Forensics, eDiscovery, Compliance, Privacy, or Incident Response.
  • Experience investigating security events and user activity involving sensitive information.
  • Working knowledge of Microsoft 365 security, collaboration, and data protection capabilities.
  • Experience using case management platforms such as ServiceNow or similar systems.
  • Strong analytical, investigative, documentation, and communication skills.
  • Ability to work with sensitive matters and partner appropriately with Legal, HR, Privacy, Compliance, IT, and business stakeholders.

Preferred Qualifications

  • Experience with Microsoft Purview Insider Risk Management.
  • Experience with Microsoft Purview DLP, eDiscovery, and Information Protection.
  • Experience supporting HR, Legal, Privacy, Compliance, or regulatory investigations.
  • Knowledge of data protection, privacy, employee monitoring, and regulated data handling concepts.
  • Security certifications such as SC-200, SC-400, GCFA, GCFE, GCIH, Security+, CySA+, or similar.

#LI-CH1

Candidates should be comfortable with an on-site presence to support collaboration, team leadership, and cross-functional partnership.

About Acrisure

Acrisure is an insurance brokerage firm that provides a range of insurance products and services to businesses and individuals. The company was founded in 2005 and is headquartered in Caledonia, Michigan. Acrisure offers a wide range of insurance products, including property and casualty, employee benefits, and personal lines insurance. The company has grown rapidly through a series of acquisitions, and now has over 500 offices in the United States and around the world. Acrisure has been recognized as one of the fastest-growing companies in the United States, and has won numerous awards for its innovative insurance products and services.
Learn more about Acrisure
Size
7,000 employees
Industry
Founded
2006

Similar Jobs

More Jobs at Acrisure

More Information Technology Jobs

Find similar Data Protection Analyst jobs: