Sr. Insider & Data Risk Analyst in Madrid, Madrid, Comunidad de at Jobgether
Explore Related Opportunities
Job Description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Sr. Insider & Data Risk Analyst based in Spain.
This is a senior individual contributor role focused on protecting sensitive information, systems, and people from insider and data-loss risks. You will own complex investigations from initial triage through resolution while helping mature insider risk management and Data Loss Prevention capabilities. The role sits at the intersection of cybersecurity, data protection, privacy, and regulated financial services. You will work closely with People/HR, Legal, Compliance, Engineering, IT, and Security teams on highly sensitive cases requiring discretion and sound judgment. The position also offers an opportunity to strengthen risk processes, automate investigations, and apply AI to emerging security challenges. Success requires a highly organized professional who can translate complex findings into clear recommendations for both technical teams and leadership.
- Own insider risk investigations from initial triage through closure, including establishing case timelines, coordinating containment and escalation, documenting determinations, and capturing lessons learned.
- Mature the Insider Risk Management Program by developing scalable case-management processes, risk-tiering methodologies, investigation standards, and repeatable workflows.
- Operate, monitor, and tune Data Loss Prevention capabilities across SaaS applications, endpoints, and other environments, improving detection quality while reducing false positives.
- Investigate potential data exfiltration, misuse, policy violations, and inappropriate access involving source code, cloud platforms, collaboration tools, third-party applications, and critical business or trading systems.
- Strengthen data classification and governance practices while aligning DLP controls with information sensitivity and business risk.
- Assess risks associated with unauthorized AI and agentic tooling, including potential exposure of sensitive or proprietary information through approved and unsanctioned AI applications.
- Use workflow automation, AI, and security orchestration capabilities to improve alert triage, investigation efficiency, and the overall maturity of insider risk processes.
- Lead insider risk and data protection assessments, maintain risk registers, and track remediation activities and emerging threats.
- Partner with People/HR, Legal, Compliance, Engineering, IT, and Security on sensitive personnel cases, departures, policy violations, and data-handling concerns with a high level of discretion and care.
- Support internal and external audits, regulatory requirements, and security assurance activities related to insider risk, data protection, privacy, and information security.
- Contribute insider risk and secure data-handling content to security awareness and employee training programs.
- Serve as a senior escalation point for insider risk cases and mentor colleagues on investigation methodologies, case management, and effective risk analysis.
- Monitor developments in insider risk, data protection, privacy, cybersecurity, and financial services regulation to identify opportunities for continuous improvement.
- 4+ years of professional experience in insider risk, Data Loss Prevention, digital forensics, security investigations, or a closely related discipline.
- Demonstrated hands-on experience leading sensitive investigations and managing cases involving personnel matters, data misuse, policy violations, or potential exfiltration.
- Practical experience operating and tuning DLP solutions across SaaS and endpoint environments, with an understanding of detection quality and false-positive reduction.
- Experience with workflow automation, AI, or SOAR platforms for alert triage, investigation support, and case orchestration.
- Strong understanding of data classification, data governance, data protection, and information security principles.
- Working knowledge of SIEM platforms and log analysis, such as Elastic/ELK or Splunk, to support investigations and establish evidence-based conclusions.
- Familiarity with security and compliance frameworks including NIST CSF, ISO 27001, SOC 2, and privacy regulations such as GDPR and APPI.
- Strong written and verbal communication skills, with the ability to produce clear investigation reports, case documentation, risk assessments, and executive summaries.
- Exceptional integrity, discretion, and judgment when handling confidential personnel, customer, business, and security information.
- Strong organizational skills and attention to detail, with the ability to manage multiple sensitive investigations in a fast-paced, distributed environment.
- Ability to collaborate effectively with People/HR, Legal, Compliance, Engineering, IT, and Security stakeholders.
- Experience with digital forensics, eDiscovery, UEBA, insider risk platforms, security operations, or incident response is an advantage.
- Scripting or automation experience using technologies such as Python or SQL is a plus.
- Experience with major cloud platforms and familiarity with supporting SOC 2, ISO 27001, or regulatory audits is beneficial.
- Exposure to fintech, financial services, trading platforms, or regulated environments is strongly valued.
- Relevant certifications such as GCFA, GCFE, CISSP, CISM, CIPP, CFE, or equivalent are considered a plus.
- Familiarity with financial services regulatory expectations and multi-jurisdiction privacy requirements is advantageous.
- A genuine interest in AI-related data risk and using emerging AI capabilities to improve security operations and investigation workflows.
- Competitive salary and stock options.
- Health benefits.
- One-time USD $500 new-hire home-office setup allowance.
- USD $150 monthly stipend through a Brex Card.
- Opportunity to work within a globally distributed team spanning multiple countries and time zones.
- Exposure to cutting-edge cybersecurity, financial technology, cloud infrastructure, AI, and data protection challenges.
- An inclusive environment committed to diversity and equal opportunity.