Haystack
← Back to Jobs
Other
EG

Data Protection Analyst

Eliassen GroupBoston, MA🇺🇸United StatesPosted Sep 25, 2026

Quick Overview

Salary
$105.5k - $133k/yr
Seniority
Mid Senior
Work mode
On Site
Location
Boston, MA, United States
Posted
Yesterday
EncryptionComplianceContinuous ImprovementRESTRegulatory Compliance

Job Description

Description:
Hybrid 3 days onsite in Boston, MA
Our client seeks a Sr. Analyst, Data Protection to help define strategy, design policies, partner with stakeholders, analyze risks and metrics, and advance an enterprise Data Protection Program. You will operate within the Governance, Risk and Compliance team to execute the Data Protection Program, including Data Loss Prevention, Data Classification, Rights Management, and related controls. You will collaborate with Information Security Cyber Operations, IT, Legal/Privacy, and business stakeholders to design, implement, and manage effective protections for data in motion, at rest, and in use, with emphasis on Microsoft Purview DLP and Microsoft 365 security capabilities.
This is a full-time, permanent opportunity, offering a competitive salary and comprehensive benefits package. Qualified applicants must be willing and able to work on a w2 basis.
Salary: $105,500 - $133,000/ yr. w2
JN -34
Responsibilities:
  • Design, implement, and maintain DLP policies across endpoints, email, network or web, cloud applications, collaboration platforms, and data repositories.
  • Tune policies and optimize rules to reduce false positives and improve detection accuracy.
  • Lead testing, validation, and deployment of new DLP controls and policy updates.
  • Manage DLP incident workflows, escalations, and exception processes.
  • Identify emerging data protection risks and implement proactive monitoring controls.
  • Coordinate rollout of sensitivity labels and rights management or encryption controls across Microsoft 365 and integrated applications, including testing, documentation, communications, and end user training.
  • Monitor label adoption, effectiveness, and compliance with corporate data handling requirements.
  • Align and merge DLP policies with sensitivity label controls.
  • Collaborate with data owners and business units to identify, classify, and protect sensitive information assets.
  • Support program strategy, key metrics, and continuous improvement initiatives.
  • Support internal and external audits with evidence of controls, monitoring, and compliance reporting.
  • Maintain documentation for policies, exceptions, configurations, and operational procedures.
  • Serve as SME for DLP, data classification, and information protection technologies.
  • Provide guidance and training on data protection best practices.
  • Partner cross-functionally to gather requirements, translate needs into enforceable data protection policies, and mature the Data Protection Program.

Experience Requirements:
  • Bachelor's degree or equivalent work experience in a related field.
  • 6+ years of information security experience with focus on DLP, data classification, data protection, or information protection.
  • Hands-on experience with Microsoft Purview Information Protection, Microsoft Purview DLP, Endpoint DLP, Network or Web DLP, Cloud Access Security Broker, Defender for Cloud Apps, and Microsoft 365 security technologies.
  • Experience designing, testing, implementing, managing, and optimizing enterprise DLP, data classification, and sensitivity labeling policies and controls.
  • Experience analyzing DLP incidents and use cases and developing policies and mitigation strategies.
  • Experience working with engineering teams to implement and optimize controls.
  • Experience with enterprise-scale rollouts and change management in a global environment.
  • Strong understanding of data security, regulatory compliance, privacy requirements, and information governance.
  • Strong written and oral communication skills.
  • Ability to partner across functions and levels to achieve results.
  • Strong organizational skills with effective prioritization in a fast-paced environment.
  • Preferred certifications: CISSP, CISM, CIPP, Microsoft Security, or equivalent.

Education Requirements:
Bachelor's degree or equivalent work experience in Information Security, Cybersecurity, Computer Science, Information Technology, Information Systems, Business Administration, Legal or Privacy, or a related field.
Recruitment Transparency Notice

Eliassen Group values transparency in our recruitment practices. Please be advised that Eliassen Group utilizes artificial intelligence (AI) tools as part of its initial application screening and hiring process. You may receive email and SMS notifications from the Eliassen Virtual Recruiting Team (, ) inviting you to complete a brief voice screening as part of your application process. These tools assist our hiring teams in different ways, including but not limited to, assistance in reviewing application materials to help identify candidates whose qualifications most closely match the requirements of the position. All AI-assisted evaluations and responses are reviewed by human recruiters before any hiring decisions are made. The use of AI in our process is intended to support fairness, efficiency, and consistency, and Eliassen Group takes measures to prevent bias or discrimination in connection with its hiring practices. By proceeding, you acknowledge, agree, and consent to Eliassen Group's use of these tools, including AI tools, as part of the application and hiring process.
Skills, experience, and other compensable factors will be considered when determining pay rate. The pay range provided in this posting reflects a W2 hourly rate; other employment options may be available that may result in pay outside of the provided range.
W2 employees of Eliassen Group who are regularly scheduled to work 30 or more hours per week are eligible for the following benefits: medical (choice of 3 plans), dental, vision, pre-tax accounts, other voluntary benefits including life and disability insurance, 401(k) with match, and sick time if required by law in the worked-in state/locality.
If anyone reaches out to you about an open position connected with Eliassen Group, please ensure that you are working directly with us by confirming the following:

When you work with Eliassen Group, all email communication will come from an Eliassen.com address, never Gmail, Yahoo, etc.
Eliassen Group will never ask you for personal information (home address, bank account, or check routing number) until you have worked with someone clearly associated with Eliassen Group.
If you have any indication of fraudulent activity, please contact .
About Eliassen Group:
Eliassen Group is a strategic consulting firm that helps organizations reach further and achieve more through our technology, business advisory, and life sciences solutions. For nearly 40 years, we have combined exceptional people, deep domain expertise, and intelligent capabilities to expand our clients' capacity and accelerate meaningful outcomes. We are driven by a purpose to positively impact the lives of our employees, clients, consultants, and the communities we serve.
Eliassen is committed to building a diverse and inclusive team from a variety of backgrounds, perspectives, and skills. We are an Equal Opportunity and Affirmative Action Employer and all employment decisions are based on merit, performance, and business needs. Eliassen does not discriminate on the basis of race, color, gender identity or expression, sexual preference or orientation, sex (including pregnancy, childbirth, and related medical conditions), marital status, creed, religion, physical or mental disability, genetic information, military or veteran status, age, ancestry, national origin, citizenship status, prohibited criminal record inquiries of applicants and employees, or any other category protected by federal, state, or local laws.
Don't miss out on our referral program! If we hire a candidate that you refer us to then you can be eligible for a $1,000 referral check!

Similar jobs