ForgeApply
Try it free

ForgeApply · Job listing

Lead Security Analyst (DLP/DSPM)

Gartner

Irving, TX | Stamford, USonsite

Tailor your resume to this posting in about a minute.

ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for Gartner's site. Free trial, no card required.

About this role

About Gartner IT:  

Join a world-class team of skilled engineers who build creative digital solutions to support our colleagues and clients.  We make a broad organizational impact by delivering   cutting-edge   technology solutions that power Gartner.  Gartner IT values its culture of nonstop innovation, an outcome-driven approach to success, and the notion that great ideas can come from anyone on the team.   

About the role   

Gartner ’s   I nformation   S ecurity   T eam   is   a group of passionate information security   professionals dedicated to Protecting, Detecting, and Responding to threats. Our team is filled with lifelong learners who are consistently researching ways to better defend and stay ahead of the threats of tomorrow. We are a collaborative group, where   good ideas   come together whether they come from the most experienced or the newest members of the team.   

We're   looking for a well-rounded and motivated   Lead Security Analyst   to join our Human Cyber Risk & Assessment Team. In this critical role,   you'll   be instrumental in safeguarding our organization from human-centric cyber threats.   You'll   leverage   your   expertise   in information security best practices to   identify , assess, and mitigate risks associated with human behavior, ensuring the protection of our sensitive data and systems. This is an excellent opportunity for a professional with   5-7   years of experience in Information Security who is passionate about proactive security measures and building a strong security   posture.  

What   you will   do:  

• Conduct comprehensive assessments of human-centric cyber risks,   identifying   vulnerabilities and potential attack vectors tied to human actors like phishing, social engineering, and insider threats.  

• Design, implement, and manage Data Loss Prevention (DLP) strategies and controls to prevent unauthorized disclosure or exfiltration of sensitive information.   You'll   also monitor DLP alerts, investigate incidents, and recommend remediation steps.  

• Develop and implement programs to detect, analyze, and mitigate insider risks, including monitoring user behavior and collaborating with relevant stakeholders (e.g., HR, Legal) on incident response.  

• Stay ahead of current attack vectors, trends, and techniques used by threat actors targeting human vulnerabilities, proactively   identifying   emerging   threats   and recommending countermeasures.  

• Advocate for and ensure adherence to information security best practices across the organization, especially   regarding   human behavior and data handling.  

• Configure,   monitor , and   optimize   security tools relevant to human cyber risk.  

• Support during security incidents related to human-centric threats,   assisting   with investigation, containment, eradication, and recovery efforts.  

• Contribute to the development and delivery of security awareness training programs to educate employees on human cyber risks and best practices.  

• Generate reports on human cyber risk posture, incident metrics, and the effectiveness of security controls, while   maintaining   accurate   documentation of security processes.  

• Collaborate with cross-functional teams, including IT Operations, Legal, HR, and other security teams, to achieve security   objectives .  

• Present   Security Risk Findings to Leadership  

• Assist   with mentoring   Junior Level Analyst  

What you will need:  

• Bachelor's degree in Computer Science , Information Security, or a related field (relevant experience may be considered in lieu of a degree).  

• 5-7   years of hands-on experience in Information Security, with a focus on human cyber risk, data loss prevention, and insider threat.  

• Strong understanding of information security best practices, frameworks (e.g., NIST, ISO 27001), and regulatory requirements.  

• In-depth knowledge of Data Loss Prevention (DLP) principles, technologies, and implementation strategies.  

• Proven experience with Insider Risk Management methodologies and tools.  

• Familiarity with current attack vectors tied to human actors, including phishing, social engineering, business email compromise (BEC), and malware delivery .  

Must   have:  

Technical & Data Security Capabilities  

• Hands-on experience with Data Loss Prevention (DLP) and Data Security Posture Management (DSPM) platforms to govern unstructured data and prevent exfiltration.  

• Experience with Email Security platforms and Endpoint Protection tools (device control, USB policy enforcement, local storage monitoring).  

• Proficiency   in analyzing data security telemetry across cloud platforms (e.g., M365 Purview, Google Workspace, OneDrive/SharePoint).  

Human Cyber Risk & Governance  

• Experience analyzing human risk indicators, insider threat telemetry, or security awareness campaign metrics (e.g., phishing performance, EDP training completions).  

• Understanding of   Acceptable Use Policies (AUP) and experience managing risk-based exception workflows without causing business disruption.  

Professional & Analytical Skills  

• Strong analytical skills with a proven   track record   of investigating data security alerts, performing root-cause analysis, and evaluating complex employee risk profiles.  

• Exceptional written and verbal communication skills, specifically the ability to conduct empathetic yet firm security remediations with employees and present risk insights   to   leadership (HR, Legal, IT).  

• Self-starter with the ability to manage independent investigations while collaborating seamlessly across a global security organization.  

  Nice to have:  

• Relevant security certifications (e.g., CISSP, CISM, GSEC, Security+ , SSAP ).  

Who   you are :  

• A lifelong learner with a desire for continuous personal and professional development.  

• Someone with proven communication, collaboration, and critical thinking skills.  

• Able to build trusting, meaningful relati

Ready to apply to Gartner?

Tailor my resume for this role

Similar jobs

More like this: Security & Cybersecurity Jobs · More jobs at Gartner · Browse all jobs