Senior Insider Risk Analyst
Core
Conduct proactive insider risk investigations and design detection engineering rules to identify and mitigate insider threats across hybrid enterprise environments.
Role type
Senior Insider Risk Analyst (Threat Hunting & Detection Engineering)
Builds
Insider risk detection rules, investigation packages, and automated response playbooks
Domain
Cybersecurity / Insider Threat / Enterprise Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
SIEM detection rule development, structured query languages, insider risk platform triage, CASB/SSE telemetry analysis, Linux audit log investigation, PAM session monitoring, Python/PowerShell/Bash scripting, MITRE ATT&CK frameworks
Preferred skills
Semiconductor industry experience, engineering IP workflows, VDI session security controls, network detection and response (NDR), Philippine Data Privacy Act knowledge
Technologies
SIEM platforms, insider risk management platforms, endpoint detection and response (EDR), cloud access security brokers (CASB), privileged access management (PAM), Linux audit logs, VDI session logs
Responsibilities
Conduct proactive insider risk sweeps targeting high-risk user populations; investigate privileged access abuse and unauthorized data uploads; design and tune detection rules to reduce false positives; develop automated response playbooks for containment; onboard new log sources into SIEM environments; prepare investigation packages for Legal/HR handoff
Seniority
Senior, hands-on IC