Solo Network logo
Solo Network

Soluções que valorizam e impulsionam seu negócio

Data and Information Security Analyst (Mid-level)

Security AnalystSecurity AnalystFull TimeRemoteSeniorTeam 201-500Since 2002H1B No SponsorCompany SiteLinkedIn

Location

Brazil

Posted

3 days ago

Salary

0

Seniority

Senior

Bachelor DegreePortuguese

Job Description

Data and Information Security Analyst (Mid-level)

Solo Network

• Work to protect corporate data and information, being responsible for the implementation, administration and evolution of Data Loss Prevention (DLP) and Data Governance solutions in the Microsoft ecosystem. • Implement, administer and maintain Data Loss Prevention (DLP) policies in Microsoft 365 environments and corporate devices. • Configure, review and optimize data protection policies using Microsoft Purview. • Continuously monitor events and alerts related to data protection, conducting incident analysis and investigations. • Identify and mitigate risks related to the leakage of confidential information. • Implement and administer sensitivity labels, classification and document protection policies. • Manage retention policies and information lifecycle (Data Lifecycle Management) and support Records Management initiatives. • Support eDiscovery, Communication Compliance and security audits when required. • Manage email protection capabilities using Microsoft Defender for Office 365.

Job Requirements

  • Bachelor’s degree in Information Security, Computer Science, Information Systems, Computer Networks or related fields.
  • Experience with Microsoft Purview solutions focused on Data Governance and Data Protection.
  • Experience implementing and administering Data Loss Prevention (DLP) policies.
  • Knowledge of:
  • Microsoft Information Protection;
  • Sensitivity Labels;
  • Classification and labeling policies;
  • Data Lifecycle Management;
  • Retention policies;
  • Records Management;
  • eDiscovery;
  • Communication Compliance.
  • Hands-on experience with Microsoft Defender for Office 365, including:
  • Exchange Online Protection (EOP);
  • Anti-Spam;
  • Anti-Phishing;
  • Anti-Malware;
  • Safe Links;
  • Safe Attachments;
  • Threat Explorer;
  • Quarantine management.
  • Knowledge of email authentication using SPF, DKIM and DMARC.
  • Knowledge of compliance with LGPD, GDPR and data governance best practices.
  • Basic to intermediate experience with PowerShell (Exchange Online and Microsoft Purview).

Related Job Pages

More Security Analyst Jobs

Solo Network logo

Data and Information Security Analyst – Junior

Solo Network

Soluções que valorizam e impulsionam seu negócio

Full TimeRemoteTeam 201-500Since 2002H1B No Sponsor

• Act as a Data and Information Security Analyst with a technical and consultative focus on protecting sensitive data and information. • Responsible for implementing and maintaining classification, labeling and protection policies, as well as Data Loss Prevention (DLP) technologies and regulatory compliance, ensuring the secure lifecycle of information. • Work with Microsoft Information Protection, Microsoft Purview and Data Loss Prevention (DLP) to identify, classify and protect sensitive data across data infrastructures, endpoints, e-mail, SharePoint, Teams, OneDrive, etc. • Configure DLP policies based on financial, contractual and regulatory information (LGPD, SOX, PCI-DSS). • Continuously improve DLP policies based on events, false positives and exception cases. • Monitor DLP alerts, perform analysis and collaborate with incident response teams. • Support investigations conducted by other teams by providing technical input and context on DLP policies, classification rules and potential leakage vectors. • Work together with Data Stewards. • Conduct mapping, categorization and classification of critical/sensitive data. • Define and maintain OKRs and maturity indicators related to technical data governance and leakage prevention activities. • Demonstrate results through dashboards, executive reports and technical evidence. • Ensure compliance with standards and legislation such as LGPD, GDPR, SOX, HIPAA, PCI-DSS, ISO 27001:2022 and NIST. • Support internal/external audits with compliance evidence related to DLP, classification and governance. • Conduct trainings, workshops and awareness campaigns on secure use and classification of information.

Brazil
Solo Network logo

Junior Data and Information Security Analyst

Solo Network

Soluções que valorizam e impulsionam seu negócio

Full TimeRemoteTeam 201-500Since 2002H1B No Sponsor

• Work with Microsoft Information Protection, Microsoft Purview and Data Loss Prevention (DLP) to identify, classify, and protect sensitive data across data infrastructures, devices, email, SharePoint, Teams and OneDrive. • Continuously improve DLP policies based on events, false positives and exception cases. • Monitor DLP alerts, perform analyses and collaborate with incident response teams. • Support investigations conducted by other teams by providing technical inputs and contextual information about DLP policies. • Work together with Data Stewards who act as focal points to ensure data quality, appropriate use, security and correct data classification. • Conduct mapping, categorization and classification of critical/sensitive data, aligning with the owners of each data domain (e.g., finance, legal, HR). • Define and maintain OKRs and maturity indicators related to technical data governance and data leakage prevention activities. • Ensure compliance with regulations and legislation such as LGPD, GDPR, SOX, HIPAA and PCI-DSS.

Brazil
Synack, Inc. logo

Security Analyst, Part-Time

Synack, Inc.

The Premier Security Testing Platform.

Part TimeRemoteTeam 201-500H1B No Sponsor

• Assist the Vulnerability Operations team with the review and acceptance of Missions, Patch Verifications, and vulnerability reports • Bypass customer patch attempts, create suspected vulnerability reports, and exploit real world vulnerabilities • Work remotely with seasoned Computer Security Analysts • Learn what it's like to review complex vulnerability reports

United States
$25 / hour

Role Description The Senior Security Analyst (Healthcare) is responsible for protecting the organization’s information systems, data, and technology assets with a primary focus on safeguarding Protected Health Information (PHI) and ensuring compliance with healthcare regulatory requirements. This role plays a critical part in designing, implementing, monitoring, and improving the organization’s cybersecurity posture in alignment with HIPAA, HITECH, and other applicable standards. This position serves as a senior technical and operational resource within the security function, leading security monitoring, incident response, risk assessments, vulnerability management, and compliance initiatives. The Senior Security Analyst works closely with IT, infrastructure, application teams, compliance, and external partners to identify risks, respond to threats, and maintain a strong security posture across a multi-site healthcare environment. Everything we do connects back to real people navigating complex healthcare journeys - and this role helps make that journey brighter. What You’ll Do - Security Operations and Monitoring - Monitor and analyze security events and alerts across networks, endpoints, cloud platforms, and applications. - Investigate suspicious activity and lead incident response efforts, including triage, containment, eradication, and recovery. - Serve as an escalation point for complex security incidents and coordinate cross-functional response efforts. - Maintain and tune SIEM, EDR, and other security tools to improve detection and reduce false positives. - Conduct root cause analysis and document incidents, actions taken, and lessons learned. - Healthcare Security and Compliance - Ensure compliance with HIPAA, HITECH, and other healthcare regulatory and privacy requirements. - Participate in security risk assessments, gap analyses, and audits (internal and external), including support for third-party assessments. - Develop and maintain security policies, standards, and procedures aligned with regulatory expectations. - Monitor controls related to PHI protection, data access, and breach prevention. - Support audit readiness and remediation activities for compliance findings. - Vulnerability and Risk Management - Conduct regular vulnerability scans and coordinate remediation efforts across infrastructure and application teams. - Prioritize risks based on business impact, exploitability, and regulatory exposure. - Track and report on vulnerability remediation status and risk reduction efforts. - Perform risk assessments on new systems, vendors, and technology implementations. - Contribute to third-party risk management and vendor security reviews. - Security Engineering and Architecture Support - Collaborate with infrastructure and application teams to implement secure configurations and controls. - Evaluate and recommend security solutions, tools, and technologies to enhance protection capabilities. - Support secure design reviews for new applications, systems, and integrations. - Validate implementation of security controls across networks, endpoints, and cloud environments. - Identity and Access Management (IAM) - Review and monitor user access to systems containing PHI and sensitive data. - Support access governance processes, including provisioning, deprovisioning, and periodic access reviews. - Investigate access anomalies and enforce least-privilege principles. - Training, Awareness, and Continuous Improvement - Support security awareness and training initiatives with a focus on healthcare threats (e.g., phishing, ransomware). - Provide guidance to IT and business teams on security best practices and risk mitigation. - Identify opportunities to improve security processes, tooling, and response capabilities. - Mentor junior analysts and contribute to the development of the security team. Qualifications - Bachelor’s degree in Cybersecurity, Information Technology, or a related field preferred; equivalent experience considered. - 5+ years of experience in cybersecurity, information security, or related roles. - 2+ years of experience in healthcare IT, security, or regulated environments required. - Demonstrated experience with incident response, threat detection, and vulnerability management. - Experience supporting audits and compliance frameworks in regulated industries. Requirements - Strong understanding of: - Security operations (SIEM, EDR, log analysis) - Network security (firewalls, IDS/IPS, segmentation) - Endpoint security and device hardening - Cloud security principles (Azure, AWS, or similar) - Vulnerability scanning and remediation tools - Familiarity with: - HIPAA Security Rule and Privacy Rule - NIST Cybersecurity Framework (CSF) and/or NIST 800-53 - HITRUST CSF (preferred in healthcare environments) - Knowledge of identity and access management practices. - Understanding of secure system and application design principles. Benefits - Purpose-driven work with real impact - A patient-first, clinician-led culture - Supportive, collaborative teammates - The opportunity to grow with a company building something meaningful Pay Range/Rate $110,000 — $120,000 USD

United States
$110K - $120K / year