Senior Insider Threat Engineer
Core
Configure, tune, and optimize enterprise insider threat technologies (Microsoft Purview, Proofpoint) to detect, investigate, and mitigate insider risks within a healthcare ecosystem.
Role type
Senior IC insider threat engineer
Builds
Insider threat detection policies, alert triage workflows, and investigative support for legal/HR inquiries
Domain
Cybersecurity / Insider Threat / Data Loss Prevention
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure
Required skills
Microsoft Purview Insider Risk Management, Microsoft Purview Communication Compliance, Microsoft Purview eDiscovery, Proofpoint Insider Threat Management, KQL, PowerShell, SIEM/UEBA correlation, regulatory compliance (HIPAA/HITRUST/PCI-DSS/SOC2)
Preferred skills
Microsoft Graph API, adaptive scopes, trainable classifiers, agentic AI development tools (Claude Code), endpoint agent deployment
Technologies
Microsoft Purview, Proofpoint ITM, Splunk, Defender XDR, KQL, PowerShell
Responsibilities
Configure and tune Microsoft Purview IRM and CC policies; investigate Purview alerts and perform root-cause analysis; support eDiscovery activities for legal holds and investigations; operate and tune Proofpoint ITM for endpoint telemetry; correlate telemetry with SIEM/UEBA/EDR data; develop automation scripts for policy deployment and reporting; ensure compliance with HIPAA, HITRUST, PCI-DSS, and SOC2.
Seniority
Senior, hands-on IC