Назад
Company hidden
обновлено 4 дня назад

Insider Threat Engineer (Cybersecurity)

Формат работы
hybrid
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Insider Threat Engineer (Cybersecurity): Leading digital investigations, threat hunting, and detection and response improvements for insider threat incidents with an accent on digital forensics, SIEM/EDR/UEBA analysis, and privacy-compliant investigations. Focus on analyzing evidence across endpoints, networks, cloud services, and email, developing detection rules and response playbooks, and collaborating with Legal, HR, Privacy, and incident response teams.

Location: Hybrid in Austin, United States. Applicants who reach the offer stage may be asked to attend an in-person interview at a hirify.global office or hub. The position may require authorization to access technology controlled under U.S. export control laws without sponsorship for an export license.

Company

hirify.global operates a global network that protects and accelerates Internet applications and services.

What you will do

  • Lead technical investigations into data exfiltration, intellectual property theft, unauthorized access, and other insider threat incidents.
  • Collect, preserve, analyze, and document digital evidence from endpoints, network logs, cloud services, email, and related sources.
  • Conduct proactive insider threat hunts using SIEM, DLP, EDR, UEBA, and other security data sources.
  • Develop detection rules, alerts, use cases, and response playbooks for insider threat scenarios.
  • Collaborate with Security Incident Response and Threat Detection teams to mature detection and response capabilities.
  • Serve as the technical liaison for Legal, HR, Privacy, and GRC during sensitive investigations and policy development.

Requirements

  • 5+ years of experience in technical security, including 2+ years focused on insider threat, digital forensics, or security investigations.
  • Experience leading complex technical investigations and using forensic tools such as EnCase, FTK, X-Ways, or open-source alternatives.
  • Deep understanding of SIEM, EDR, and UEBA data sources.
  • Strong scripting and programming skills in Python and PowerShell for automation and large-scale data analysis.
  • Excellent written and verbal communication skills, including explaining technical concepts to non-technical audiences.
  • Experience working with Legal and HR teams on sensitive employee-related matters.

Nice to have

  • GCIH, GCFA, GCTI, or similar certification.
  • Experience with cloud security and investigations across AWS, GCP, or Azure.
  • Experience in a technology product or fast-paced startup environment.
  • Knowledge of GDPR, CCPA, digital evidence procedures, and legal or court evidence presentation.

Culture & Benefits

  • Work in a security team focused on protecting the Internet from malicious and negligent insider activity.
  • Collaborate across Security, Legal, HR, Privacy, and GRC functions.
  • Contribute to hirify.global initiatives supporting journalism, civil society, election information, and privacy-focused Internet infrastructure.
  • hirify.global provides reasonable accommodations during the application process.

Hiring process

  • Applicants progressing to the offer stage may be asked to attend an in-person interview at a hirify.global office or hub.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →