обновлено 4 дня назад
Insider Threat Engineer (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Insider Threat Engineer (Cybersecurity): Leading digital investigations, threat hunting, and detection and response improvements for insider threat incidents with an accent on digital forensics, SIEM/EDR/UEBA analysis, and privacy-compliant investigations. Focus on analyzing evidence across endpoints, networks, cloud services, and email, developing detection rules and response playbooks, and collaborating with Legal, HR, Privacy, and incident response teams.
Location: Hybrid in Austin, United States. Applicants who reach the offer stage may be asked to attend an in-person interview at a office or hub. The position may require authorization to access technology controlled under U.S. export control laws without sponsorship for an export license.
Company
operates a global network that protects and accelerates Internet applications and services.
What you will do
- Lead technical investigations into data exfiltration, intellectual property theft, unauthorized access, and other insider threat incidents.
- Collect, preserve, analyze, and document digital evidence from endpoints, network logs, cloud services, email, and related sources.
- Conduct proactive insider threat hunts using SIEM, DLP, EDR, UEBA, and other security data sources.
- Develop detection rules, alerts, use cases, and response playbooks for insider threat scenarios.
- Collaborate with Security Incident Response and Threat Detection teams to mature detection and response capabilities.
- Serve as the technical liaison for Legal, HR, Privacy, and GRC during sensitive investigations and policy development.
Requirements
- 5+ years of experience in technical security, including 2+ years focused on insider threat, digital forensics, or security investigations.
- Experience leading complex technical investigations and using forensic tools such as EnCase, FTK, X-Ways, or open-source alternatives.
- Deep understanding of SIEM, EDR, and UEBA data sources.
- Strong scripting and programming skills in Python and PowerShell for automation and large-scale data analysis.
- Excellent written and verbal communication skills, including explaining technical concepts to non-technical audiences.
- Experience working with Legal and HR teams on sensitive employee-related matters.
Nice to have
- GCIH, GCFA, GCTI, or similar certification.
- Experience with cloud security and investigations across AWS, GCP, or Azure.
- Experience in a technology product or fast-paced startup environment.
- Knowledge of GDPR, CCPA, digital evidence procedures, and legal or court evidence presentation.
Culture & Benefits
- Work in a security team focused on protecting the Internet from malicious and negligent insider activity.
- Collaborate across Security, Legal, HR, Privacy, and GRC functions.
- Contribute to initiatives supporting journalism, civil society, election information, and privacy-focused Internet infrastructure.
- provides reasonable accommodations during the application process.
Hiring process
- Applicants progressing to the offer stage may be asked to attend an in-person interview at a office or hub.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
3 дня назад
Senior Insider Threat Analyst (Cybersecurity)
152 000 - 228 000$
13 часов назад
Insider Threat Investigator (Cybersecurity)
90 000 - 150 000$
8 часов назад
Lead Analyst – Cyber Incident Response (AI)
6 дней назад
Threat Intelligence Lead (Cybersecurity)
240 000 - 280 000$
LinkedIn
2 дня назад
Staff Information Security Engineer (Detection Engineering)
156 000 - 255 000$
4 дня назад