Data Protection Analyst

Cyberhaven
Bangalore, Mexico
Hybrid

Who this role is best for

Strong fit for candidates with hands-on experience in data protection and insider threat analysis who can work collaboratively on global teams and adapt to evolving customer needs.

Best fit for

  • Candidates with 2–5 years in data protection and insider threat analysis, and a background in incident response.
    — “2–5 years with data protection or adjacent security tools (EDR, SIEM, SOAR) and 2+ years in Insider Threat/InfoSec.
  • Professionals who can manage technical analysis, policy refinement, and stakeholder communication effectively.
    — “Prepare and present summaries and reports to internal team members.
  • Individuals experienced in cross-platform environments (macOS, Linux, Windows) and cloud infrastructure.
    — “Comfortable across macOS, Linux, Windows and cloud platforms (AWS, GCP, Azure).

Things to consider

  • The role involves continuous improvement of policies and incident handling as customer strategies evolve.
    — “Refine datasets and policies and manage them as customers’ data risk strategy matures and business needs evolve.
  • Candidates should be ready to handle both technical and project management responsibilities.
    — “You will also perform analysis of events and incidents.

How to stand out

  • Highlight your ability to reduce false positives and improve detection accuracy in your resume and interviews.
    — “Eliminate noise and false-positive information from analytic results to enhance detection accuracy.
  • Emphasize your experience with SQL, dashboard building, and API scripting in your technical skills section.
    — “Data & automation: SQL for analysis; build/maintain dashboards; edit XML-based DLP rules; script and use APIs.
  • Showcase your track record in analyzing data security incidents and refining protection strategies.
    — “Perform technical analysis of data security incidents, finding and exposing risk in a customers environment.
Pace · Fast PacedCollaboration · MediumAutonomy · MediumDecision Impact · Team

Derived from job-description analysis by Serendipath's career intelligence engine.

What success looks like

  • providing insight into DLP analytics
  • improving policies and incidents/alerts
  • handling documentation and project management aspects of incident response
  • eliminating noise and false-positive information from analytic results
  • conducting forensic analysis on people, groups, and non-sanctioned egress destinations
Typical background
2-5 years with data protection or adjacent security toolsstrong grasp of endpoint protection best practicesexperience with DLP, Insider Threat, CASB and controls for handling sensitive data

Skills & requirements

Required

Data ProtectionIncident ResponseForensic AnalysisDLPInsider ThreatSIEMSOAREndpoint ProtectionIncident Mitigation WorkflowsSQLXMLApis

Preferred

Cloud PlatformsMacosLinuxWindowsAWSGCPAzure

Stack & domain

Data ProtectionSecurity Tools (edr, Siem, Soar)Insider ThreatCASBControls For Handling Sensitive DataMacosLinuxWindowsCloud Platforms (aws, GCP, Azure)SQLXml-based DLP RulesApisProblem-solvingCommunicationCollaborationCustomer-centricPassion For Cloud SecurityData SecurityEndpoint ProtectionIncident Mitigation Workflows

About the role

Original posting from Cyberhaven via Ashby

About the role

This is an ideal opportunity for a highly motivated individual to get in on the ground floor as we build out our Professional Services and Managed Services functions at Cyberhaven. The Data Protection Analyst holds a key position in providing continuous value for our customers and is responsible for advancing the mission of identifying potential insider threats and investigating endpoint forensic incidents. You will be responsible for performing technical analysis of data security incidents, finding and exposing risk in a customers environment as well as handling documentation and project management aspects of incident response. You will also perform analysis of events and incidents.

What you’ll do

  • Provide insight into DLP analytics and related issues.
  • Analyze Cyberhaven’s Data Detection and Response (DDR) platform event data to improve policies and incidents/alerts and bring focus to areas where data loss risk may exist.
  • Refine datasets and policies and manage them as customers’ data risk strategy matures and business needs evolve.
  • Prepare and present summaries and reports to internal team members.
  • Eliminate noise and false-positive information from analytic results to enhance detection accuracy.
  • Conduct forensic analysis on people, groups, and non sanctioned egress destinations as requested.

Who you are

  • 2–5 years with data protection or adjacent security tools (EDR, SIEM, SOAR) and 2+ years in Insider Threat/InfoSec.
  • Strong grasp of endpoint protection best practices and incident mitigation workflows.
  • Experience with DLP, Insider Threat, CASB and controls for handling sensitive data.
  • Comfortable across macOS, Linux, Windows and cloud platforms (AWS, GCP, Azure).
  • Data & automation: SQL for analysis; build/maintain dashboards; edit XML-based DLP rules; script and use APIs.
  • Excellent problem-solving and communication skills; collaborative on a global team; customer-centric with a passion for cloud security and emerging tech.

Joining Cyberhaven means joining the team building Data Security for the Agentic Enterprise. Traditional tools fall short. Cyberhaven traces the full lifecycle of your data, adapting protection to changing context, so protection moves with the way people actually work, not against it. AI Changed Work. We Protect It.

Backed by $250M from leading investors like Khosla and Redpoint, our team includes leaders who built industry-defining technologies at CrowdStrike, Palo Alto Networks, Meta, Google, and more. This role lets you shape the future of data security, working alongside people driven to protect workflows, not just data, for customers who cannot afford to slow down to stay safe.

AI Tools Disclosure: As part of Cyberhaven's hiring process, we use recruiting tools that include AI-powered features to help with tasks like scheduling, note-taking, workflow automation, and other recruiting activities ("AI Tools"). The AI Tools may process information you provide during the application and interview process. When AI-assisted interview note taking is used, candidates are notified in advance and have the option to opt out of the AI-assisted interview note taking.

Cyberhaven is committed to creating a diverse environment and is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status.

Source: Cyberhaven careers (Ashby)

Similar roles