Logo
Okta, Inc.

Principal Data Security Analyst - Data Classification & Governance

Okta, Inc., Chicago

Save Job

Senior Data Security Analyst - Data Classification & Governance

Chicago, IL

Get to know Okta
Okta is The Worlds Identity Company. We free everyone to safely use any technology, anywhere, on any device or app. Our flexible and neutral products, Okta Platform and Auth0 Platform, provide secure access, authentication, and automation, placing identity at the core of business security and growth.
At Okta, we celebrate a variety of perspectives and experiences. We are not looking for someone who checks every single box - were looking for lifelong learners and people who can make us better with their unique experiences.
Join our team! Were building a world where Identity belongs to you.

Role Summary: We seek an experienced and detail-oriented Staff Data Security Analyst to contribute to our strategic Data Classification and Governance Program. In this role, you will be instrumental in the operational execution of our data governance strategy. You will work hands-on with data discovery and classification tools, apply data protection policies, and collaborate extensively with cross-functional teams, including Business Technology (BT), Legal, Data & Insights (D&I), and other Security teams. Your focus will be on implementing and maintaining the data classification framework, supporting the rollout of technical controls, and ensuring that our data handling practices align with our security and compliance objectives.

Key Responsibilities:

  • Data Classification & Labeling:
  • Actively participate in data discovery initiatives to identify and inventory sensitive data (PII, SPI, financial, IP, AI training data) across key enterprise systems (e.g., Google Workspace, Salesforce, Workday, NetSuite, Snowflake).
  • Assist in executing pilot programs for data classification on high-priority systems and contribute to refining classification processes.
  • Assist data Stewards and system owners in implementing the data classification policy and data handling standards to support their operationalization.
  • Collaborate with BT and Security engineering teams to test and validate the implementation of technical controls (e.g., DLP rules, CASB configurations) based on data classification.
  • Help define and test controls related to sensitive data input into enabled AI tools.
  • Tooling & Process Support:
  • Become proficient in using selected data discovery, classification, and governance tools (potential tools include Varonis, native Google/Snowflake capabilities).
  • Assist with the configuration, including helping to set up scans and reviewing results.
  • Contribute to developing and maintaining documentation for classification procedures and tool usage.
  • Collaboration & Stakeholder Engagement:
  • Work closely with Data Stewards (from D&I and business units) to understand data context, validate classification results, and ensure alignment with business needs.
  • Partner with BT application owners to facilitate classification efforts and implement necessary data handling changes.
  • Support Security GRC by providing data and insights for risk assessments and compliance reporting related to data classification.
  • Assist in establishing and tracking key metrics for data classification coverage, accuracy, and the effectiveness of associated controls.
  • Contribute to developing dashboards and reports for program stakeholders and the Data Governance Council.

Required Qualifications & Skills:

  • Bachelor's degree in Information Security, Computer Science, Information Systems, or a related field, or equivalent practical experience.
  • 7+ years of experience in data security, governance, IT risk management, or a similar analytical role focusing on data protection.
  • Strong, demonstrable understanding of data classification principles, methodologies, data lifecycle management, and data handling best practices.
  • Hands-on experience with data discovery and/or data classification tools and technologies.
  • Solid understanding of data protection concepts and technologies (e.g., DLP, data masking, tokenization, encryption, IAM).
  • Knowledge of key data privacy regulations (e.g., CCPA, GDPR) and their impact on data handling.
  • Excellent analytical, problem-solving, and critical-thinking skills with meticulous attention to detail.
  • Proven ability to work effectively in a cross-functional team environment and manage multiple tasks.
  • Strong written and verbal communication skills, with the ability to articulate technical concepts to varied audiences.

Preferred Qualifications:

  • Experience with specific data governance or classification platforms (e.g., Varonis, OneTrust, Google Cloud DLP, Snowflake Data Classification).
  • Experience implementing or operating data security controls in SaaS environments (e.g., Salesforce, Workday, Google Workspace, M365) and cloud platforms (AWS, Azure, GCP).
  • Familiarity with security considerations for AI/ML systems and data inputs, including knowledge of AI-native solutions for data labeling and classification.
  • Hands-on experience with AI governance principles and frameworks, including implementing controls for responsible AI use.
  • Experience in developing and delivering training or awareness materials.
  • Relevant industry certifications (e.g., CISM, CISSP, CIPP, CDMP, or tool-specific certifications).

#LI-BF1

#LI-Hybrid

The annual base salary range for this position for candidates located in the San Francisco Bay area is between:

Get to know Okta
Okta is The Worlds Identity Company. We free everyone to safely use any technology, anywhere, on any device or app. Our flexible and neutral products, Okta Platform and Auth0 Platform, provide secure access, authentication, and automation, placing identity at the core of business security and growth.
At Okta, we celebrate a variety of perspectives and experiences. We are not looking for someone who checks every single box - were looking for lifelong learners and people who can make us better with their unique experiences.
Join our team! Were building a world where Identity belongs to you.

Role Summary: We seek an experienced and detail-oriented Staff Data Security Analyst to contribute to our strategic Data Classification and Governance Program. In this role, you will be instrumental in the operational execution of our data governance strategy. You will work hands-on with data discovery and classification tools, apply data protection policies, and collaborate extensively with cross-functional teams, including Business Technology (BT), Legal, Data & Insights (D&I), and other Security teams. Your focus will be on implementing and maintaining the data classification framework, supporting the rollout of technical controls, and ensuring that our data handling practices align with our security and compliance objectives.

Key Responsibilities:

  • Data Classification & Labeling:
    • Actively participate in data discovery initiatives to identify and inventory sensitive data (PII, SPI, financial, IP, AI training data) across key enterprise systems (e.g., Google Workspace, Salesforce, Workday, NetSuite, Snowflake).
    • Assist in executing pilot programs for data classification on high-priority systems and contribute to refining classification processes.
  • Policy Operationalization & Control Support:
    • Assist data Stewards and system owners in implementing the data classification policy and data handling standards to support their operationalization.
    • Collaborate with BT and Security engineering teams to test and validate the implementation of technical controls (e.g., DLP rules, CASB configurations) based on data classification.
    • Help define and test controls related to sensitive data input into enabled AI tools.
  • Tooling & Process Support:
    • Become proficient in using selected data discovery, classification, and governance tools (potential tools include Varonis, native Google/Snowflake capabilities).
    • Assist with the configuration, including helping to set up scans and reviewing results.
    • Contribute to developing and maintaining documentation for classification procedures and tool usage.
  • Collaboration & Stakeholder Engagement:
    • Work closely with Data Stewards (from D&I and business units) to understand data context, validate classification results, and ensure alignment with business needs.
    • Partner with BT application owners to facilitate classification efforts and implement necessary data handling changes.
    • Support Security GRC by providing data and insights for risk assessments and compliance reporting related to data classification.
  • Monitoring, Reporting & Continuous Improvement:
    • Assist in establishing and tracking key metrics for data classification coverage, accuracy, and the effectiveness of associated controls.
    • Contribute to developing dashboards and reports for program stakeholders and the Data Governance Council.

Required Qualifications & Skills:

  • Bachelor's degree in Information Security, Computer Science, Information Systems, or a related field, or equivalent practical experience.
  • 7+ years of experience in data security, governance, IT risk management, or a similar analytical role focusing on data protection.
  • Strong, demonstrable understanding of data classification principles, methodologies, data lifecycle management, and data handling best practices.
  • Hands-on experience with data discovery and/or data classification tools and technologies.
  • Solid understanding of data protection concepts and technologies (e.g., DLP, data masking, tokenization, encryption, IAM).
  • Knowledge of key data privacy regulations (e.g., CCPA, GDPR) and their impact on data handling.
  • Excellent analytical, problem-solving, and critical-thinking skills with meticulous attention to detail.
  • Proven ability to work effectively in a cross-functional team environment and manage multiple tasks.
  • Strong written and verbal communication skills, with the ability to articulate technical concepts to varied audiences.

Preferred Qualifications:

  • Experience with specific data governance or classification platforms (e.g., Varonis, OneTrust, Google Cloud DLP, Snowflake Data Classification).
  • Experience implementing or operating data security controls in SaaS environments (e.g., Salesforce, Workday, Google Workspace, M365) and cloud platforms (AWS, Azure, GCP).
  • Familiarity with security considerations for AI/ML systems and data inputs, including knowledge of AI-native solutions for data labeling and classification.
  • Hands-on experience with AI governance principles and frameworks, including implementing controls for responsible AI use.
  • Experience in developing and delivering training or awareness materials.
  • Relevant industry certifications (e.g., CISM, CISSP, CIPP, CDMP, or tool-specific certifications).

#LI-BF1

#LI-Hybrid

The annual base salary range for this position for candidates located in the San Francisco Bay area is between: $128,000 $192,000 USD

Below is the annual base salary range for candidates located in California, Colorado, New York and Washington. Your actual base salary will depend on factors such as your skills, qualifications, experience, and work location. In addition, Okta offers equity (where applicable), bonus, and benefits, including health, dental and vision insurance, 401(k), flexible spending account, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies. To learn more about our Total Rewards program please visit: .

The annual base salary range for this position for candidates located in California (excluding San Francisco Bay Area), Colorado, New York, and Washington is between: $114,000 $172,000 USD

What you can look forward to as a Full-Time Okta employee!

  • Amazing Benefits
  • Making Social Impact
  • Developing Talent and Fostering Connection + Community at Okta

Okta cultivates a dynamic work environment, providing the best tools, technology and benefits to empower our employees to work productively in a setting that best and uniquely suits their needs. Each organization is unique in the degree of flexibility and mobility in which they work so that all employees are enabled to be their most creative and successful versions of themselves, regardless of where they live. Find your place at Okta today! .
Some roles may require travel to one of our office locations for in-person onboarding.

Okta is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, ancestry, marital status, age, physical or mental disability, or status as a protected veteran. We also consider for employment qualified applicants with arrest and convictions records, consistent with applicable laws.
If reasonable accommodation is needed to complete any part of the job application, interview process, or onboarding please use this Form to request an accommodation.

Okta is committed to complying with applicable data privacy and security laws and regulations. For more information, please see our Privacy Policy at .

U.S. Equal Opportunity Employment Information
Read more

Individuals seeking employment at this company are considered without regards to race, color, religion,national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, genderidentity, or sexual orientation. When submitting your application above, you are being given theopportunity to provide information about your race/ethnicity, gender, and veteran status.

Completion of the form is entirely voluntary . Whatever your decision, it will not beconsidered in the hiring process or thereafter. Any information that you do provide will be recorded andmaintained in a confidential file.

If you believe you belong to any of the categories of protected veterans listed below, please indicate bymaking the appropriate selection. As a government contractor subject to Vietnam Era Veterans ReadjustmentAssistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreachand positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categoriesis as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air servicewho is entitled to compensation (or who but for the receipt of military retired pay would be entitled tocompensation) under laws administered by the Secretary of Veterans Affairs; or a person who was dischargedor released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date ofsuch veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S.military, ground, naval or air service during a war, or in a campaign or expedition for which a campaignbadge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S.military, ground, naval or air service, participated in a United States military operation for which anArmed Forces service medal was awarded pursuant to Executive Order 12985.

Individuals seeking employment at this company are considered without regards to race, color, religion,national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, genderidentity, or sexual orientation. When submitting your application above, you are being given theopportunity to provide information about your race/ethnicity, gender, and veteran status.

Completion of the form is entirely voluntary . Whatever your decision, it will not beconsidered in the hiring process or thereafter. Any information that you do provide will be recorded andmaintained in a confidential file.

If you believe you belong to any of the categories of protected veterans listed below, please indicate bymaking the appropriate selection. As a government contractor subject to Vietnam Era Veterans ReadjustmentAssistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreachand positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categoriesis as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air servicewho is entitled to compensation (or who but for the receipt of military retired pay would be entitled tocompensation) under laws administered by the Secretary of Veterans Affairs; or a person who was dischargedor released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date ofsuch veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S.military, ground, naval or air service during a war, or in a campaign or expedition for which a campaignbadge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S.military, ground, naval or air service, participated in a United States military operation for which anArmed Forces service medal was awarded pursuant to Executive Order 12985.

Pay Transparency

Okta complies with all applicable federal, state, and local pay transparency rules. For additionalinformation about the federal requirements, click here .

Voluntary Self-Identification of Disability
Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years. Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor's Office of Federal Contract Compliance Programs (OFCCP) website at

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labors Office of Federal Contract Compliance Programs (OFCCP) website at .

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your major life activities. If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinsons disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.

The foundation for secure connections between people and technology

Okta is the leading independent provider of identity for the enterprise. The Okta Identity Cloud enables organizations to securely connect the right people to the right technologies at the right time. With over 7,000 pre-built integrations to applications and infrastructure providers, Okta customers can easily and securely use the best technologies for their business. More than 19,300 organizations, including JetBlue, Nordstrom, Slack, T-Mobile, Takeda, Teach for America, and Twilio, trust Okta to help protect the identities of their workforces and customers.

Follow Okta

First Name

Last Name

Email

Phone

Resume

Upload PDF

Paste

Resume/CV Upload Resume/CV (PDF must be less than 8 MB )

Resume/CV

Upload PDF

Paste

Upload Cover Letter (PDF must be less than 8 MB )

#J-18808-Ljbffr