Назад
Company hidden
15 часов назад

Head of Insider Risk (Cybersecurity)

205 920 - 397 440$
Формат работы
onsite
Тип работы
fulltime
Грейд
head
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Head of Insider Risk (Cybersecurity): Building and maturing an insider risk program for protecting people, data, and systems with an accent on digital forensics, incident response, detection engineering, and cross-functional governance. Focus on leading investigators and analysts, overseeing complex data-exfiltration investigations, developing behavioral risk scoring, and operating SIEM, EDR, DLP, UEBA, and cloud logging capabilities.

Location: Washington, D.C.; fully in-person schedule up to 5 days a week

Salary: $205,920–$397,440 annually, plus potential discretionary bonuses, incentives, and restricted stock units.

Company

hirify.global operates a data privacy and cybersecurity program focused on protecting U.S. user data, applications, algorithms, and the content ecosystem.

What you will do

  • Own the insider risk program strategy, roadmap, policies, playbooks, metrics, and continuous maturity improvements.
  • Build, lead, and mentor a team of insider risk investigators and analysts.
  • Design detection and monitoring capabilities using SIEM, EDR, DLP, UEBA, and AWS, Azure, and GCP logging.
  • Oversee investigations into data exfiltration, intellectual property theft, unauthorized access, fraud, and policy violations while maintaining forensic rigor and chain-of-custody integrity.
  • Develop behavioral analytics and risk-scoring models, manage the technology stack, and establish awareness training, tabletop exercises, and simulations.
  • Partner with Security, Privacy, Legal, HR, IT, and Engineering leadership and provide executive-level reporting on investigations, trends, and program health.

Requirements

  • Bachelor’s degree in Cybersecurity, Digital Forensics, Information Technology, Computer Science, or equivalent professional experience.
  • At least 5 years of progressive experience in insider risk, digital forensics, incident response, or cybersecurity investigations, including 2 years in a team lead, manager, or program-owner capacity.
  • Experience establishing or materially maturing an insider risk program, including policy development, detection engineering, and cross-functional governance.
  • Expertise with forensic tools such as EnCase, FTK, Cellebrite, X-Ways, or AXIOM, and scripting with Python, Bash, or PowerShell.
  • Advanced forensic knowledge of Windows, macOS, and Linux, including file systems, memory analysis, artifact extraction, and log parsing.
  • Hands-on experience with EDR, SIEM, DLP, UEBA, and cloud investigation capabilities, plus strong communication skills for briefing senior leadership and external stakeholders.

Nice to have

  • Master’s degree or certifications such as GCFE, GCFA, GCIH, EnCE, CCE, CISSP, CISM, or OSCP.
  • SANS training in advanced forensics or program management coursework.
  • Experience in highly regulated environments or organizations with more than 10,000 employees.
  • Knowledge of MITRE ATT&CK, NIST SP 800-53, and CISA insider threat best practices.
  • Experience using data analytics or machine learning for behavioral anomaly detection.

Culture & Benefits

  • Medical, dental, and vision insurance from day one.
  • 401(k) savings plan with company match, paid parental leave, disability coverage, and life insurance.
  • Wellbeing benefits, 10 paid holidays, 10 paid sick days, and 17 days of paid personal time.
  • Inclusive workplace focused on creativity, curiosity, humility, resilience, and continuous innovation.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →