Information Security Engineer - Insider Risk
Core
Engineer and automate end-to-end detection and investigation workflows to prevent, detect, and investigate security events and insider risks across the enterprise.
Role type
Senior IC insider threat detection engineer
Builds
Detection and Response infrastructure and alerting strategies
Domain
Cybersecurity / Insider Threat / Threat Intelligence
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
Security forensics, Threat intelligence, Incident response, SIEM/SOAR query writing, Endpoint telemetry analysis, Network/host/memory artifact analysis, Python, PowerShell, Multi-platform OS experience (AWS/Azure/Windows/Linux/macOS)
Preferred skills
Conference talks, Public tool development, Autonomous operation
Technologies
SIEM, SOAR, Python, PowerShell, AWS, Azure, Windows, OS X, Linux
Responsibilities
Engineer and automate detection and investigation workflows, Develop alerting strategies for malicious or anomalous behavior, Dissect network/host/memory artifacts, Investigate security events and active attacks, Influence security controls, Partner with the Information Security team to lead defense posture changes
Seniority
Senior, hands-on IC