Jobs · Engineering · Minnesota

Sr Data Protection & Governance Analyst

Starkey Hearing · Eden Prairie, MN · 4 wk ago
On-siteEngineering$86k–$117k/yrFull-time

Job Responsibilities/Results

  • Own the day-to-day operation, governance, and adoption of our data protection program across the Microsoft 365 (E5) environment.
  • Consolidate a fast-growing body of work — Data Loss Prevention (DLP), sensitivity labeling, and the administration of enterprise-wide security settings — that is currently distributed across existing team members alongside their primary security-operations duties.
  • Lead the employee training and organizational change management required for those controls to be adopted and sustained.
  • Administer and govern the sensitivity-label taxonomy, auto-labeling policies, and label-based protection, including the dynamic group / scoping logic that ensures full population coverage.
  • Investigate DLP alerts and policy matches, triage incidents, and partner with the SOC/MDR provider and Security Engineering on escalations.
  • Administer the security, compliance, and data-governance settings of large enterprise SaaS solutions, with Microsoft 365 / Purview as the primary platform.
  • Maintain configuration baselines, document control settings, and support periodic posture assessments and audit/risk-assessment requests.
  • Cook up data-protection requirements for new integrations and data flows (e.g., analytics pipelines, mirrored/replicated data stores, and SaaS-to-SaaS connections).
  • Develop and deliver end-user training and enablement on sensitivity labels, DLP behavior, and secure data-handling expectations.
  • Partner with business units (e.g., Business Intelligence / Enterprise Analytics and application teams) to translate their data-handling needs into appropriate, workable protection policies.
  • Design, build, and maintain an internal AI assistant/agent that lets employees self-serve answers to security-program questions.
  • Curate and maintain the knowledge base behind the agent (policies, FAQs, control documentation) so responses stay accurate as the program evolves.
  • Identify other practical applications of AI to the data-protection program (e.g., assisting with classification, drafting policy language, or triaging DLP alerts) and pilot them where they add measurable value.
  • Produce a recurring IT/security newsletter and related employee communications that build awareness and reinforce good data-handling habits.
  • Develop and deliver general end-user enablement on core productivity tools (e.g., Microsoft Outlook, Excel, Teams), including quick-reference guides, tips, and informal training.
  • Serve as point of contact for employee “how do I…” questions on IT and productivity tools, and feed recurring questions back into training material and the AI assistant.

Job Requirements

  • Bachelor's degree in cybersecurity, information security, computer science, information technology, or a related field — or equivalent hands-on experience.
  • 5+ years in information security or IT.
  • 3+ years of hands on Microsoft Purview/DLP experience.
  • Hands-on Microsoft Purview experience: DLP policies, sensitivity labels, Sensitive Information Types, trainable classifiers, and the M365 compliance/security portals.
  • Working knowledge of Microsoft 365 / Entra ID administration: dynamic groups, scoping, role-based access, and tenant security/compliance settings.
  • Practical regex skills and an understanding of data classification methodology.
  • Familiarity with the broader Microsoft security stack (Defender, Sentinel) and how DLP/labeling data flows into monitoring.
  • Ability to build and maintain an AI assistant/agent for internal users, using a retrieval-augmented (knowledge-grounded) approach so answers are sourced from our own policies and documentation rather than generic model knowledge.
  • Familiarity with enterprise AI tooling available in our environment — Microsoft Copilot Studio and Security Copilot (both available under E5) are the most direct fit — and/or general experience with LLM platforms, prompt design, and connecting a model to a curated knowledge base.
  • Judgment around responsible/secure AI use: data privacy of prompts and responses, access control, guardrails, and knowing which questions an automated assistant should escalate to a human rather than answer.
  • Experience iterating on the agent based on real employee questions, and measuring whether it actually deflects routine queries and improves security awareness.
  • Experience in a regulated / sensitive-data environment (healthcare, medical device, PHI/PII, or IP-heavy manufacturing).
  • ServiceNow or similar ITSM ticketing workflow experience.
  • Relevant certifications: Microsoft SC-400 (Information Protection & Compliance Administrator), SC-401, SC-200, or equivalent.

Compensation

The target pay rate for this position is between $86,000 - $117,000 annually. Factors which may affect starting pay within this range may include: geography/market, skills, education, experience and other qualifications of the successful candidate. This position is eligible for a bonus based upon performance results. There is no guarantee of payout.

Benefits

  • Medical, dental and vision insurance.
  • 401(k) retirement plan with company match.
  • Company-paid life and short-term disability insurance.
  • Long-term disability insurance.
  • Employee assistance plan.
  • Hearing aid benefits.
  • Paid Time Off.
  • paid holidays.
  • paid floating holidays.
  • paid volunteer service day.
  • paid paternity and maternity leave.
  • Tuition reimbursement.

Similar jobs

Sr. Analyst, Data Governance

Navitus Health SolutionsUnited States· 1 mo ago
RemoteInformation Technology$85k/yrapply on careers-navitus.icims.com