Sr Data Protection & Governance Analyst
Starkey Hearing · Eden Prairie, MN · 4 wk ago
On-siteEngineering$86k–$117k/yrFull-time
Job Responsibilities/Results
- Own the day-to-day operation, governance, and adoption of our data protection program across the Microsoft 365 (E5) environment.
- Consolidate a fast-growing body of work — Data Loss Prevention (DLP), sensitivity labeling, and the administration of enterprise-wide security settings — that is currently distributed across existing team members alongside their primary security-operations duties.
- Lead the employee training and organizational change management required for those controls to be adopted and sustained.
- Administer and govern the sensitivity-label taxonomy, auto-labeling policies, and label-based protection, including the dynamic group / scoping logic that ensures full population coverage.
- Investigate DLP alerts and policy matches, triage incidents, and partner with the SOC/MDR provider and Security Engineering on escalations.
- Administer the security, compliance, and data-governance settings of large enterprise SaaS solutions, with Microsoft 365 / Purview as the primary platform.
- Maintain configuration baselines, document control settings, and support periodic posture assessments and audit/risk-assessment requests.
- Cook up data-protection requirements for new integrations and data flows (e.g., analytics pipelines, mirrored/replicated data stores, and SaaS-to-SaaS connections).
- Develop and deliver end-user training and enablement on sensitivity labels, DLP behavior, and secure data-handling expectations.
- Partner with business units (e.g., Business Intelligence / Enterprise Analytics and application teams) to translate their data-handling needs into appropriate, workable protection policies.
- Design, build, and maintain an internal AI assistant/agent that lets employees self-serve answers to security-program questions.
- Curate and maintain the knowledge base behind the agent (policies, FAQs, control documentation) so responses stay accurate as the program evolves.
- Identify other practical applications of AI to the data-protection program (e.g., assisting with classification, drafting policy language, or triaging DLP alerts) and pilot them where they add measurable value.
- Produce a recurring IT/security newsletter and related employee communications that build awareness and reinforce good data-handling habits.
- Develop and deliver general end-user enablement on core productivity tools (e.g., Microsoft Outlook, Excel, Teams), including quick-reference guides, tips, and informal training.
- Serve as point of contact for employee “how do I…” questions on IT and productivity tools, and feed recurring questions back into training material and the AI assistant.
Job Requirements
- Bachelor's degree in cybersecurity, information security, computer science, information technology, or a related field — or equivalent hands-on experience.
- 5+ years in information security or IT.
- 3+ years of hands on Microsoft Purview/DLP experience.
- Hands-on Microsoft Purview experience: DLP policies, sensitivity labels, Sensitive Information Types, trainable classifiers, and the M365 compliance/security portals.
- Working knowledge of Microsoft 365 / Entra ID administration: dynamic groups, scoping, role-based access, and tenant security/compliance settings.
- Practical regex skills and an understanding of data classification methodology.
- Familiarity with the broader Microsoft security stack (Defender, Sentinel) and how DLP/labeling data flows into monitoring.
- Ability to build and maintain an AI assistant/agent for internal users, using a retrieval-augmented (knowledge-grounded) approach so answers are sourced from our own policies and documentation rather than generic model knowledge.
- Familiarity with enterprise AI tooling available in our environment — Microsoft Copilot Studio and Security Copilot (both available under E5) are the most direct fit — and/or general experience with LLM platforms, prompt design, and connecting a model to a curated knowledge base.
- Judgment around responsible/secure AI use: data privacy of prompts and responses, access control, guardrails, and knowing which questions an automated assistant should escalate to a human rather than answer.
- Experience iterating on the agent based on real employee questions, and measuring whether it actually deflects routine queries and improves security awareness.
- Experience in a regulated / sensitive-data environment (healthcare, medical device, PHI/PII, or IP-heavy manufacturing).
- ServiceNow or similar ITSM ticketing workflow experience.
- Relevant certifications: Microsoft SC-400 (Information Protection & Compliance Administrator), SC-401, SC-200, or equivalent.
Compensation
The target pay rate for this position is between $86,000 - $117,000 annually. Factors which may affect starting pay within this range may include: geography/market, skills, education, experience and other qualifications of the successful candidate. This position is eligible for a bonus based upon performance results. There is no guarantee of payout.
Benefits
- Medical, dental and vision insurance.
- 401(k) retirement plan with company match.
- Company-paid life and short-term disability insurance.
- Long-term disability insurance.
- Employee assistance plan.
- Hearing aid benefits.
- Paid Time Off.
- paid holidays.
- paid floating holidays.
- paid volunteer service day.
- paid paternity and maternity leave.
- Tuition reimbursement.