What are the responsibilities and job description for the Data Security Analyst position at Old Republic?
Reports To: Data Security Manager
Department: Information Technology
Location/Schedule: Tampa, FL /Hybrid
Classification: Full-Time / Exempt
Who We Are:
Old Republic is a leading specialty insurer that operates diverse property & casualty and title insurance companies. Founded in 1923 and a member of the Fortune 500, we are a leader in underwriting and risk management services for business partners across the United States and Canada. Our specialized operating companies are experts in their fields, enabling us to provide tailored solutions that set us apart.
Position Overview:
The Security Analyst is responsible for protecting the organization’s information assets and strengthening the enterprise data security posture. This role supports data protection strategies, monitors security controls, evaluates data-related risks, and helps ensure alignment with internal policies and applicable regulatory requirements. Working closely with Security Governance, Risk, and Compliance (GRC), Security Operations, technology teams, and business stakeholders, the Security Analyst provides technical and analytical expertise to identify risks, clearly communicate findings, and support measurable improvements across the data security program.
Essential Job Functions:
- Support the development, implementation, and continuous improvement of data security policies, standards, procedures, configuration management, and operational playbooks.
- Monitor sensitive data exposure, access, movement, and usage across enterprise systems, SaaS platforms, Microsoft 365, cloud environments, and other business applications or systems.
- Support data classification, sensitivity labeling, data loss prevention, insider risk, and data protection initiatives, including policy testing, tuning, exception handling, and rollout support.
- Analyze data security alerts and events to identify risks such as inappropriate access, excessive permissions, abnormal data movement, mass downloads, external sharing, and potential data exfiltration.
- Conduct or assist with data-focused risk assessments, control evaluations, compliance reviews, audits and remediation tracking.
- Partners with SOC, Microsoft 365, cloud, application, compliance, legal, and business teams to ensure data security requirements are consistently understood and executed.
- Prepare reports, dashboards, metrics, and summaries that communicate data security trends, control effectiveness, operational gaps, and program maturity.
- Document recurring issues, lessons learned, and standard response procedures to improve consistency, reduce single points of failure, and strengthen team operations.
- Contribute to training, awareness, and best practice guidance for business and technical teams handling sensitive or regulated data.
Qualifications:
- Minimum of 3 years of experience in one or more data security or related security functions, such as data loss prevention, data classification, insider risk, data access governance, SaaS security, sensitive data monitoring, security operations, risk management, or compliance.
- Minimum of 3 years of experience creating or maintaining security documentation, procedures, reports, metrics, dashboards, or recurring status updates.
- Strong analytical, problem-solving, and critical-thinking skills, with the ability to evaluate complex data-related risks and recommend effective data security solutions.
- Ability to manage multiple priorities, follow established processes, escalate issues appropriately, and work effectively both independently and as part of a team.
- Strong written and verbal communication skills, including the ability to translate technical findings into clear business risk statements and actionable recommendations.
- Familiarity with regulatory, audit, or control frameworks, such as SOX, NIST, CIS, ISO 27001, or similar standards.
ORI is an Equal Opportunity Employer. ORI provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.
This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.