Insider Risk Security Engineer
Core
Senior contributor refining detection capabilities, leading investigations, and developing playbooks for the Insider Risk program to prevent data loss and cyberattacks.
Role type
Senior IC insider risk security engineer
Builds
Scalable detection frameworks, investigation playbooks, and evidentiary case documentation
Domain
Cybersecurity, Insider Threat, Data Protection
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
SIEM/SOAR alert management, EDR/XDR/UEBA investigation, Python or JavaScript automation, cross-functional stakeholder engagement, detection framework design
Preferred skills
Zscaler product portfolio experience, product development collaboration, forensics certifications (GCFA/GCFE), industry frameworks (CERT/NIST/NSA)
Technologies
SIEM, SOAR, EDR, XDR, UEBA, Python, JavaScript
Responsibilities
Refine detection rules to reduce noise and close coverage gaps; Perform endpoint and user activity investigations using EDR/XDR, UEBA, and SIEM tools; Drive development and iteration of insider risk investigation playbooks; Serve as key contact for HR, Legal, and business leaders on active investigations
Seniority
Senior, hands-on IC