Staff Insider Risk Engineer
Core
Design, build, and optimize insider threat detection logic and workflows within the Security Operations Center to protect data, systems, and employees.
Role type
Staff Insider Risk Engineer (Security Operations)
Builds
Insider risk detection use cases, alert triage workflows, and forensic investigation processes
Domain
Fintech, Cybersecurity, Insider Risk Management
Deliverable
production ML models | product features | dashboards & analysis
Required skills
Insider risk investigation, digital forensics, alert triage, behavioral analysis, risk assessment, cross-functional partnership, incident response, data protection, compliance, AI-assisted investigation automation
Preferred skills
macOS/Windows/cloud forensic analysis, SIEM/UEBA/EDR tooling, log data interpretation, employee interview techniques, playbook development
Technologies
AWS, Google Workspace, SIEM, UEBA, EDR, Endpoint DLP platforms
Responsibilities
Conduct investigations into suspected insider threats including data exfiltration and policy violations; Triage and validate alerts from the insider risk management program; Partner with HR, Legal, and Privacy on remediation of confirmed incidents; Maintain chain-of-custody documentation and adhere to digital forensics standards; Author clear investigation reports supporting disciplinary or remediation actions; Support the design and tuning of detection use cases and monitoring baselines; Track metrics for leadership to highlight trends and improvement opportunities
Seniority
Staff, hands-on IC with strategic influence