- Company Name
- Toyota North America
- Job Title
- Data Protection Analyst, Senior
- Job Description
-
Job Title: Senior Data Protection Analyst
Role Summary: Spearhead the deployment, monitoring, and improvement of Data Loss Prevention (DLP) controls to protect corporate data integrity, ensure regulatory compliance, and respond to security incidents.
Expactations: 3‑5 years of data security monitoring and incident response, expertise in SIEM and DLP technologies (CrowdStrike, Symantec, Sumologic, Microsoft Purview/Defender, Trellix, Proofpoint, DSPM/CASB tools), experience configuring multi‑layer DLP policies, proficiency in threat intelligence integration, demonstrated automation and orchestration abilities, strong analytical and communication skills, and familiarity with regulated environments and compliance frameworks.
Key Responsibilities:
- Analyze and triage DLP alerts and incidents, executing timely containment and remediation actions.
- Collaborate with security and global stakeholders to develop and refine threat‑based mitigation policies.
- Ensure ongoing compliance with data protection laws and regulations (e.g., GDPR, PCI DSS, NIST CSF, ISO 27001).
- Support DLP engineering efforts by testing, evaluating, and scoring emerging technologies.
- Drive program maturity through automation, KPI definition, and process optimization.
- Participate in incident response activities and post‑incident reviews.
- Monitor cyber threat landscape and incorporate threat intelligence into controls.
- Author and maintain data protection response documentation, aligning with internal standards and industry best practices.
Required Skills:
- Proven experience (3‑5 yrs) in data security monitoring and response.
- Proficiency with SIEM alert management (CrowdStrike, Symantec, Sumologic).
- Ability to configure and manage DLP for Data in Motion, Data at Rest, Data in Use, and Internet Monitoring.
- Hands‑on experience with Microsoft Purview/Defender, CrowdStrike, Trellix, Proofpoint, or analogous DSPM/CASB solutions.
- Practical use of AI tools to augment security workflows.
- Strong analytical, problem‑solving, and rule‑authoring capabilities (automation, orchestration).
- Excellent written and verbal communication for technical and non‑technical audiences.
- Familiarity with audit, compliance, and governance processes in regulated settings.
- Bonus: Cybersecurity certifications (SSCP, Security+, CISSP, CCSP); knowledge of ISO 27001, NIST CSF 2.0, PCI DSS, GDPR; experience with CSPM/SSPM; cloud security; AI technology integration.
Required Education & Certifications:
- Bachelor’s degree in Cyber Security, Information Security, Computer Science, or related field.
- Relevant cybersecurity certifications (SSCP, Security+, CISSP, CCSP).
- Security framework knowledge (ISO 27001, NIST CSF, PCI DSS, GDPR).
- Preferred: Clearance (Top Secret/GS) or equivalent access in a regulated environment.