AbbVie logo

Senior Data Loss Prevention Analyst

AbbVie
August 13, 2026
Remote
United States
$96,500 - $183,500 USD yearly
IT
This position can be virtual anywhere in the U.S.

Responsibilities:
- Lead complex and sensitive data loss investigations from initial alert through documentation and closure, including cases involving potential insider risk.
- Serve as the senior escalation point for the DLP team, providing guidance and second level review on cases requiring advanced analytical judgment.
- Design, build, test, and tune DLP policies and detection rules in Microsoft Purview, balancing detection coverage against false positive volume.
- Develop and maintain Splunk searches, correlation logic, dashboards, and reports to support DLP investigations, alert triage, and program metrics.
- Continuously review the alert queue to identify tuning opportunities, detection gaps, and candidates for new use cases.
- Correlate DLP telemetry with other data sources, endpoint, email, cloud, identity, and network logs to build complete pictures of potential data exfiltration.
- Support migration from the legacy DLP platform (use-case mapping, policy translation, validation testing, detection parity verification).
- Partner with Legal, HR, Compliance, and Privacy on investigations and prepare clear written findings for technical and non-technical audiences.
- Mentor junior analysts; document investigative procedures; contribute to playbooks/runbooks.

Qualifications:
- Bachelorโ€™s degree (Info Security/CS or related) + 6 years; or Masterโ€™s + 5 years; or PhD + 0 years.
- Demonstrated information security experience focused on data loss prevention or insider risk.
- Hands-on Microsoft Purview DLP (policy creation, rule tuning, alert investigation across endpoint, email, cloud); Purview Insider Risk Management is a plus.
- Demonstrated Splunk experience (SPL searches, dashboards/correlation logic, supporting security investigations).
- Strong analytical/investigative skills with independent, defensible conclusions from incomplete/ambiguous data.
- Solid understanding of data classification, regulatory drivers (HIPAA, GDPR, PCI-DSS or similar), and common data exfiltration methods.
- Excellent written communication for legal/HR/executive audiences.

Preferred:
- 5+ years in information security, with at least 3 years focused on data loss prevention or insider risk.