22 Π΄Π½Ρ Π½Π°Π·Π°Π΄
Staff Insider Threat Analyst (Cybersecurity)
ΠΡΡΡ & Π‘ΠΎΠΏΡΠΎΠ²ΠΎΠ΄
ΠΠ»Ρ ΠΌΡΡΡΠ° Ρ ΡΡΠΎΠΉ Π²Π°ΠΊΠ°Π½ΡΠΈΠ΅ΠΉ Π½ΡΠΆΠ΅Π½ Plus
ΠΠΏΠΈΡΠ°Π½ΠΈΠ΅ Π²Π°ΠΊΠ°Π½ΡΠΈΠΈ
Π’Π΅ΠΊΡΡ:
TL;DR
Staff Insider Threat Analyst (Cybersecurity): Conducting full-lifecycle technical analysis of insider threat cases in Taipei, correlating DLP, EDR, SIEM, and other data sources with an accent on behavioral analysis, host-based investigation, and detection engineering. Focus on managing sensitive investigations, building comprehensive event timelines, automating analysis with Python, PowerShell, and Bash, and translating technical findings into actionable security recommendations.
Location: Taipei, Taiwan
Company
operates an e-commerce business in Taiwan, including Rocket Delivery and Rocket Oversea services.
What you will do
- Perform the full lifecycle of technical analysis for insider threat cases, from alert triage through complex data-driven reviews.
- Hunt for anomalous user behavior by correlating DLP, EDR, SIEM/SOR, and other data sources.
- Review user activity, system artifacts, endpoint data, application logs, and network evidence to build event timelines.
- Support Investigations, Legal, and HR teams with clear, objective technical findings and reports.
- Act as a technical subject matter expert and guide other analysts on insider threat data sources.
- Develop and refine detection logic, playbooks, alert criteria, and strategic security recommendations.
Requirements
- 6+ years of information security experience, including at least 3+ years of hands-on insider threat analysis.
- Expertise with UBA or insider threat platforms, EDR solutions, SIEM, data lakes, and host-based analysis.
- Experience reviewing endpoint, application, and network log artifacts and managing complex, sensitive cases autonomously.
- Strong investigative mindset with analytical, detail-oriented, skeptical, objective, and root-cause-focused approach.
- Scripting skills in Python, PowerShell, and Bash for automation and data analysis.
- Bachelorβs degree in Computer Science, Information Security, or equivalent practical experience.
Nice to have
- Experience building or significantly maturing an insider threat program.
- Relevant certifications such as GCIH or CISSP.
- Native Mandarin and proficient business English.
- Familiarity with digital forensic toolsets and forensic principles.
Culture & Benefits
- High-autonomy role serving as the teamβs primary technical expert.
- Collaboration with Investigations, Legal, HR, and technical and non-technical partners.
- Opportunity to improve insider threat detection maturity and security controls.
Hiring process
- Application review.
- Phone interview.
- Onsite or virtual onsite interview, followed by an offer.
ΠΡΠ΄ΡΡΠ΅ ΠΎΡΡΠΎΡΠΎΠΆΠ½Ρ: Π΅ΡΠ»ΠΈ ΡΠ°Π±ΠΎΡΠΎΠ΄Π°ΡΠ΅Π»Ρ ΠΏΡΠΎΡΠΈΡ Π²ΠΎΠΉΡΠΈ Π² ΠΈΡ ΡΠΈΡΡΠ΅ΠΌΡ, ΠΈΡΠΏΠΎΠ»ΡΠ·ΡΡ iCloud/Google, ΠΏΡΠΈΡΠ»Π°ΡΡ ΠΊΠΎΠ΄/ΠΏΠ°ΡΠΎΠ»Ρ, Π·Π°ΠΏΡΡΡΠΈΡΡ ΠΊΠΎΠ΄/ΠΠ, Π½Π΅ Π΄Π΅Π»Π°ΠΉΡΠ΅ ΡΡΠΎΠ³ΠΎ - ΡΡΠΎ ΠΌΠΎΡΠ΅Π½Π½ΠΈΠΊΠΈ. ΠΠ±ΡΠ·Π°ΡΠ΅Π»ΡΠ½ΠΎ ΠΆΠΌΠΈΡΠ΅ "ΠΠΎΠΆΠ°Π»ΠΎΠ²Π°ΡΡΡΡ" ΠΈΠ»ΠΈ ΠΏΠΈΡΠΈΡΠ΅ Π² ΠΏΠΎΠ΄Π΄Π΅ΡΠΆΠΊΡ. ΠΠΎΠ΄ΡΠΎΠ±Π½Π΅Π΅ Π² Π³Π°ΠΉΠ΄Π΅ β