数据保护分析师
Data Protection Analyst
**关于职位**
这是为一位积极进取的个人提供的绝佳机会,随着Cyberhaven在专业服务和托管服务职能方面的扩展,你将有机会从早期阶段参与其中。数据保护分析师在为客户提供持续价值方面发挥关键作用,并负责推进识别潜在内部威胁和调查端点取证事件的任务。你将负责对数据安全事件进行技术分析,发现并揭示客户环境中的风险,以及处理事件响应的文档和项目管理方面的工作。你还将进行事件和事件的分析。
**你将负责**
- 提供对DLP分析和相关问题的见解。
- 分析Cyberhaven的数据检测与响应(DDR)平台事件数据,以改进策略和事件/警报,并关注可能存在数据丢失风险的区域。
- 优化数据集和策略,并根据客户的数据风险策略成熟度和业务需求的变化进行管理。
- 准备并向内部团队成员汇报总结和报告。
- 从分析结果中消除噪音和误报信息,以提高检测准确性。
- 根据要求对人员、组和非授权出口目的地进行取证分析。
**你具备**
- 2–5年数据保护或相关安全工具(EDR、SIEM、SOAR)经验,以及2年以上内部威胁/信息安全经验。
- 熟悉端点保护最佳实践和事件缓解工作流程。
- 具有DLP、内部威胁、CASB以及处理敏感数据的控制经验。
- 熟练使用macOS、Linux、Windows和云平台(AWS、GCP、Azure)。
- 数据与自动化:使用SQL进行分析;构建和维护仪表板;编辑基于XML的DLP规则;编写脚本和使用API。
- 优秀的解决问题和沟通能力;能够在全球团队中协作;以客户为中心,对云安全和新兴技术充满热情。
加入Cyberhaven意味着加入一支正在为智能企业打造数据安全的团队。传统工具无法满足需求。Cyberhaven追踪数据的完整生命周期,根据变化的上下文调整保护措施,使保护措施随着人们实际的工作方式而移动,而不是与其对抗。AI改变了工作方式。我们保护它。
由Khosla和Redpoint等领先投资者注资2.5亿美元,我们的团队包括曾在CrowdStrike、Palo Alto等公司打造行业定义技术的领导者。
查看英文原文
**About the role**
This is an ideal opportunity for a highly motivated individual to get in on the ground floor as we build out our Professional Services and Managed Services functions at Cyberhaven. The Data Protection Analyst holds a key position in providing continuous value for our customers and is responsible for advancing the mission of identifying potential insider threats and investigating endpoint forensic incidents. You will be responsible for performing technical analysis of data security incidents, finding and exposing risk in a customers environment as well as handling documentation and project management aspects of incident response. You will also perform analysis of events and incidents.
**What you’ll do**
- Provide insight into DLP analytics and related issues.
- Analyze Cyberhaven’s Data Detection and Response (DDR) platform event data to improve policies and incidents/alerts and bring focus to areas where data loss risk may exist.
- Refine datasets and policies and manage them as customers’ data risk strategy matures and business needs evolve.
- Prepare and present summaries and reports to internal team members.
- Eliminate noise and false-positive information from analytic results to enhance detection accuracy.
- Conduct forensic analysis on people, groups, and non sanctioned egress destinations as requested.
**Who you are**
- 2–5 years with data protection or adjacent security tools (EDR, SIEM, SOAR) and 2+ years in Insider Threat/InfoSec.
- Strong grasp of endpoint protection best practices and incident mitigation workflows.
- Experience with DLP, Insider Threat, CASB and controls for handling sensitive data.
- Comfortable across macOS, Linux, Windows and cloud platforms (AWS, GCP, Azure).
- Data & automation: SQL for analysis; build/maintain dashboards; edit XML-based DLP rules; script and use APIs.
- Excellent problem-solving and communication skills; collaborative on a global team; customer-centric with a passion for cloud security and emerging tech.
Joining Cyberhaven means joining the team building Data Security for the Agentic Enterprise. Traditional tools fall short. Cyberhaven traces the full lifecycle of your data, adapting protection to changing context, so protection moves with the way people actually work, not against it. AI Changed Work. We Protect It.
Backed by $250M from leading investors like Khosla and Redpoint, our team includes leaders who built industry-defining technologies at CrowdStrike, Palo Alto Networks, Meta, Google, and more. This role lets you shape the future of data security, working alongside people driven to protect workflows, not just data, for customers who cannot afford to slow down to stay safe.
**AI Tools Disclosure:** As part of Cyberhaven's hiring process, we use recruiting tools that include AI-powered features to help with tasks like scheduling, note-taking, workflow automation, and other recruiting activities ("AI Tools"). The AI Tools may process information you provide during the application and interview process. When AI-assisted interview note taking is used, candidates are notified in advance and have the option to opt out of the AI-assisted interview note taking.
_Cyberhaven is committed to creating a diverse environment and is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status._