Insider Threat Engineer

Jobtailor

Austin (TX)

On-site

USD 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor in Austin, TX is seeking an experienced Insider Threat Investigator to lead and execute digital investigations from endpoints, logs, and cloud sources. You will preserve evidence, document findings, and present outcomes to senior leadership, while ensuring privacy and legal compliance.

You will develop threat-hunting hypotheses, write detection rules, and collaborate with Legal, HR, and Privacy teams to mature the Insider Threat program.

Qualifications

  • 5+ years in a technical security role with insider threat focus.
  • Experience leading complex investigations using forensic tools.
  • Deep understanding of SIEM, EDR, and UEBA data sources.
  • Strong scripting to automate tasks and analyze large datasets.
  • Experience collaborating with Legal and HR on sensitive matters.

Responsibilities

  • Lead insider threat investigations and digital forensics activities.
  • Collect, preserve, and analyze evidence from endpoints, logs, cloud, and email.
  • Document investigative steps and findings clearly and defensibly.
  • Present findings to senior leadership and cross-functional partners.
  • Ensure investigations meet regulatory and privacy requirements.
  • Conduct proactive insider threat hunting using SIEM, DLP, EDR, and UEBA.
  • Develop threat-hunting hypotheses based on emerging threats.
  • Correlate data to identify anomalous user behavior.
  • Design, implement, and update rules, alerts, and use cases.
  • Collaborate with Legal, HR, and Privacy to mature the program.

Skills

Python
PowerShell
Communication skills
Investigation experience

Tools

SIEM
DLP
EDR
UEBA
Forensic tools

Job description

Responsibilities
  • Lead Insider Threat Digital Investigations
  • Conduct comprehensive technical investigations individually and partnering with incident response teams into potential insider threat incidents, including data exfiltration, intellectual property theft, unauthorized access, and other malicious activities
  • Collect, preserve, and analyze digital evidence from a variety of sources (endpoints, network logs, cloud services, email, etc.)
  • Document all investigative steps and findings in a clear, concise, and defensible manner
  • Present findings to senior leadership and cross‑functional partners (Legal, HR, Privacy) in a professional and objective manner
  • Ensure regulatory, legal and privacy requirements are met throughout investigations
  • Insider Threat Hunting: proactively hunt for insider threats using security tools and data sources (SIEM, DLP, EDR, UEBA)
  • Develop and execute threat hunting hypotheses based on emerging threats, attack techniques, and an understanding of the company's unique environment
  • Correlate disparate data points to identify anomalous or suspicious user behaviors
  • Detection & Response Improvement: collaborate with SIRT and Threat Detection teams to enhance insider threat detection capabilities
  • Design, develop, and implement new rules, alerts, and use cases in security tools to identify insider threat indicators
  • Evaluate and recommend new technologies and processes to mature the Insider Threat program
  • Develop and refine response playbooks for various insider threat scenarios
  • Cross‑Functional Collaboration: serve as the primary technical liaison for the Insider Threat program, building strong, trusted relationships with Legal, HR, and Privacy teams
  • Work in lockstep with these teams to ensure investigations are conducted with sensitivity, respect for employee privacy, and within legal and ethical guidelines
  • Provide technical expertise and guidance during policy development and incident response planning
Requirements
  • 5+ years of experience in a technical security role, with at least 2+ years focused on insider threat, digital forensics, or security investigations
  • Proven experience in conducting and leading complex technical investigations, including the use of forensic tools (e.g., EnCase, FTK, X-Ways, or open-source alternatives)
  • Deep understanding of security technologies such as SIEM (e.g., Splunk, Elastic), EDR (e.g., CrowdStrike, SentinelOne), and UEBA data sources
  • Strong scripting and programming skills (e.g., Python, PowerShell) to automate tasks and analyze large datasets
  • Excellent communication skills, both written and verbal, with the ability to explain complex technical concepts to non‑technical audiences
  • Experience working with legal and HR teams on sensitive employee‑related matters
Core Competencies

Demonstrates expertise in leading insider threat investigations, utilizing advanced forensic tools and security technologies to analyze and respond to potential threats. Strong collaboration with cross‑functional teams ensures compliance with legal and privacy standards while effectively communicating findings to stakeholders.

Tools & Technologies
  • Security Information and Event Management (SIEM)
  • Data Loss Prevention (DLP)
  • Endpoint Detection and Response (EDR)
  • User and Entity Behavior Analytics (UEBA)
  • Forensic Tools
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Insider Threat Engineer
Insider Threat Engineer

Cloudflare • United States

On-site
USD 180,000 - 235,000
Sr. Insider Risk Analyst
Sr. Insider Risk Analyst

Cathay Bank in • El Monte (CA)

On-site
USD 110,000 - 165,000
Senior Insider Threat Analyst
Senior Insider Threat Analyst

Jobtailor • Brooklyn (OH)

On-site
USD 120,000 - 180,000
Insider Threat Analyst
Insider Threat Analyst

NR Labs LLC • Washington

On-site
USD 95,000 - 130,000
Insider Threat Analyst
Insider Threat Analyst

Agile Defense • Washington

On-site
USD 110,000 - 160,000
Security Engineer (Insider Risk)
Security Engineer (Insider Risk)

Dragonfli Group • Washington

Hybrid
USD 120,000 - 160,000
Insurance - health, dental, and vision
Paid Time Off (PTO) and 11 Federal Holidays
401(k) employer match
Senior Cyber Security Specialist I - Insider Threat Analysis
Senior Cyber Security Specialist I - Insider Threat Analysis

Walgreens • United States

Hybrid
USD 98,000 - 158,000
Insider Threat Analytics Lead
Insider Threat Analytics Lead

FedTec • Woodlawn (MD)

On-site
USD 110,000 - 150,000
Comprehensive medical, dental, and vis
401(k) retirement plans with company
Paid time off
+4
Sr. Specialist - Digital Security Investigations
Sr. Specialist - Digital Security Investigations

Dshield • New York (NY)

On-site
USD 90,000 - 120,000
Senior Lead Insider Threat Investigator
Senior Lead Insider Threat Investigator

Jobtailor • Town of Florida (NY)

On-site
USD 110,000 - 190,000