Insider Threat Engineer
Core
Leading technical investigations, threat hunting, and detection/response development to protect the company from malicious and negligent insider activities.
Role type
Senior IC Insider Threat Tech Lead
Builds
Insider threat detection rules, alerts, use cases, and response playbooks for the company's global network
Domain
Cybersecurity / Insider Threat / Digital Forensics
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
technical security investigations, digital forensics, threat hunting, SIEM analysis, EDR analysis, UEBA analysis, scripting (Python/PowerShell), legal/privacy compliance, cross-functional collaboration
Preferred skills
cloud security investigations (AWS/GCP/Azure), GCIH/GCFA/GCTI certifications, legal/regulatory framework knowledge (GDPR/CCPA)
Technologies
Splunk, Elastic, CrowdStrike, SentinelOne, EnCase, FTK, X-Ways, SIEM, EDR, UEBA
Responsibilities
Conduct comprehensive technical investigations into potential insider threat incidents including data exfiltration and unauthorized access; Proactively hunt for insider threats using security tools and data sources; Design and implement new detection rules and response playbooks; Serve as primary technical liaison with Legal, HR, and Privacy teams
Seniority
Senior, hands-on IC