Security Specialist (Senior to Staff) – Data Loss Prevention (DLP)
American Electric Power
- Location
- Columbus, OH
- Work model
- On-Site
- Level
- Staff
- H-1B history
- 16 approvals (FY2023)
- Posted
- Aug 24, 2026
Skills
About this role
Job Posting End Date 09-14-2026 Please note the job posting will close on the day before the posting end date.
Job Summary
Responsible for moderate-scale security assignments with limited direction from senior team members. Develops and maintains necessary documentation of security systems, projects, and/or processes to ensure unified understanding of system details. Performs and analyzes security controls assessments (internal and third party) through application security testing, penetration testing or other means to ensure controls effectiveness. Identifies and documents potential mitigations/remediations and creates reports of findings with identified risk response. Participates in the review, evaluation, and recommendation of emerging security technologies. More involved in advanced level implementation, support, and/or usage of technical solutions. Assists with problem solving, decision-making, and functional area knowledge.
Job Description
Play a key role in strengthening the Insider Threat Program Team as a Data Loss Prevention (DLP) Analyst. This role combines real-time security monitoring, investigative work, and proactive threat hunting to prevent data loss incidents.
What You'll Do
Essential Job Functions and Tasks Monitor and triage security alerts across multiple DLP platforms, determining which events require deeper investigation Review daily alerts for data loss of personally identifiable information (PII), business-critical data, and confidential information across various sources such as email, cloud, and endpoint systems Coordinate all DLP investigation activities, collaborating with internal stakeholders Document findings thoroughly and maintain detailed case records Design and tune data exfiltration detection use cases, improving alert accuracy and reducing false positives while ensuring effective protection of sensitive data. Drive continuous improvement initiatives for the DLP program and monitoring across the enterprise Stay current on threat actor tactics, techniques, and procedures (TTPs) Track program metrics and align improvements to strategic roadmap goals Participate in internal security improvement meetings and industry working groups Leverage team resources effectively and communicate workload priorities to leadership Required Qualifications and Skills Ability to obtain and maintain a U.S. government security clearance. Excellent written and verbal communication skills, with strong analytical and critical-thinking ability. Ability to investigate and handle sensitive and confidential information. Expertise and knowledge of enterprise DLP tools and data protection controls across email, endpoint, cloud, and web environments. Demonstrable ability to evaluate, implement, and improve DLP controls across diverse technology environments and business processes.
Preferred Qualifications
Bachelor's degree in cybersecurity, information security, computer science, or related field Experience in cybersecurity, insider threat, security operations, digital forensics, data loss prevention, investigations, fraud detection, or intelligence analysis Prior Investigations experience Experience monitoring and investigating anomalous user activity and policy violations Experience identifying data loss indicators through analytics and anomaly detection methodologies. Understanding of security monitoring tools, SIEM platforms, and endpoint detection solutions Ability to create and curate queries to detect and analyze data for potential data exfiltration activity Experience working in cross-functional environments involving HR, Legal, Compliance, Privacy, and Security teams Experience with case management and evidence handling Experience with data classification, information protection, data loss prevention (DLP), and sensitive data monitoring technologies. Familiarity with electric utility operations, industrial control systems (ICS/SCADA), or critical infrastructure protection frameworks (e.g., NERC CIP). Ability