Insider Threat Engineering Support Lead

Citigroup Inc.

Irving (TX)

On-site

USD 126,000 - 189,000

Full time

8 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Citigroup Inc. is seeking an Insider Threat Engineering Support Lead to join the Cybersecurity Operations & Engineering team in Irving, TX.

This role focuses on detecting, mitigating, and engineering controls around internal human-risk factors, with a hands-on engineering and analytics emphasis. The ideal candidate blends investigative thinking with engineering to design, tune, and operationalize high-fidelity detections, and to hunt across massive telemetry datasets while improving insider

Qualifications

  • Core cybersecurity/insider threat concepts with human-centric risk models.
  • 6+ years building/tuning queries in SIEM/data platforms (Splunk, KQL/Sentinel, Elastic, SQL, Snowflake).
  • Proactive, hypothesis-based threat hunting across enterprise logs.
  • Detail-oriented data analysis and troubleshooting of large datasets.
  • Ability to work independently and manage high-impact priorities.

Responsibilities

  • Develop, test, tune, and maintain behavioral analytics and SIEM detection rules.
  • Translate insights into automated, resilient detection logic.
  • Monitor detection effectiveness and minimize false positives while maximizing coverage.
  • Conduct hypothesis-driven threat hunting across multi-source logs.
  • Collaborate with incident response to operationalize findings into safeguards.

Skills

Domain knowledge
Query & detection engineering
Threat hunting
Data analysis
Self-directed execution
Hybrid engineering

Education

Bachelor’s degree
Master’s degree preferred

Tools

Splunk
KQL/Sentinel
Elastic
SQL
Snowflake

Job description

Role Overview


Seeking an inquisitive, analytical, and hands-onInsider Threat Engineering Support Lead to join our Cybersecurity Operations & Engineering team. This role sits at the intersection of security engineering, data analytics, and behavioral threat hunting. Unlike traditional perimeter-focused cybersecurity roles, this position focuses on identifying, mitigating, and engineering detection controls around internal human-risk factors, anomalous behavioral patterns, and unauthorized data movement.


The ideal candidate blends an investigative mindset with engineering acumen to design, tune, and operationalize high-fidelity detections, proactively hunt across massive enterprise telemetry datasets, and continuously enhance our insider threat mitigation posture.


Key Responsibilities

Detection Engineering & Rule Optimization

  • Develop, test, tune, and maintain behavioral analytics, hunt-based queries, and SIEM/data platform detection rules to identify insider threat vectors (e.g., data exfiltration, privilege abuse, unauthorized access).
  • Translate investigative insights and newly identified threat patterns into automated, resilient detection logic.
  • Monitor detection effectiveness, minimizing false positives while maximizing coverage against known insider attack methodologies.

Proactive Threat Hunting & Analytics

  • Conduct hypothesis-driven threat hunting across multi-source log repositories, behavioral baselines, and disparate telemetry data to uncover undetected threats.
  • Analyze and troubleshoot large, complex datasets to establish normal baseline activity and isolate anomalies.
  • Partner with incident response and insider threat analysts to operationalize hunt findings into long-term defensive safeguards.

Engineering Support & Process Improvement

  • Support the end-to-end detection engineering lifecycle, incorporating Secure Software Development Lifecycle (SDLC) best practices, version control, and comprehensive technical documentation.
  • Participate in testing, validation, and continuous delivery of detection artifacts.
  • Manage priorities autonomously in a fast-paced environment, driving deliverables from concept through deployment.

Candidate Qualifications & Requirements

Desired Skills & Experience

  • Domain Knowledge:Strong understanding of core Cybersecurity and Insider Threat concepts, specifically the behavioral, access, and human-centric risk models that distinguish insider threats from external attacks.
  • Query & Detection Engineering:6+ years of experience constructing, tuning, and executing complex queries within SIEM, data lake, or log analytics platforms (e.g., Splunk, KQL/Sentinel, Elastic, SQL, Snowflake).
  • Threat Hunting:Demonstrated ability to perform proactive, hypothesis-based threat hunting to identify stealthy, anomalous, or policy-violating activity across enterprise log sources.
  • Data Analysis & Troubleshooting:Exceptional attention to detail with the ability to navigate, sanitize, query, and troubleshoot high-volume, heterogeneous datasets.
  • Self-Directed Execution:Demonstrated capability to independently manage workload, prioritize high-impact initiatives, and deliver results with minimal supervision.

Behavioral Attributes & Core Competencies

  • Inquisitive & Investigative Mindset:High natural curiosity and an "outside-the-box" analytical approach to solving ambiguous problems and tracing subtle anomalies.
  • Hybrid Engineering & Investigation Focus:Ability to view telemetry through both an investigator's analytical lens and a software/security engineer’s systems-building perspective.
  • Effective Communication:Ability to articulate complex data findings and engineering designs clearly to technical peers and non-technical stakeholders alike.

Education:

  • Bachelor’s degree/University degree or equivalent experience
  • Master’s degree preferred

This job description provides a high-level review of the types of work performed. Other job-related duties may be assigned as required.

Job Family Group:

Technology

Job Family:

Information Security

Time Type:

Full time

Primary Location:

Irving Texas United States

Primary Location Full Time Salary Range:

$125,760.00 - $188,640.00

In addition to salary, Citi’s offerings may also include, for eligible employees, discretionary and formulaic incentive and retention awards. Citi offers competitive employee benefits, including: medical, dental & vision coverage; 401(k); life, accident, and disability insurance; and wellness programs. Citi also offers paid time off packages, including planned time off (vacation), unplanned time off (sick leave), and paid holidays. For additional information regarding Citi employee benefits, please visit citibenefits.com. Available offerings may vary by jurisdiction, job level, and date of hire.

Anticipated Posting Close Date:

Oct 25, 2026

Automated Processing and AI

Illinois residents – AI Notice and Right

We use automated processing, including artificial intelligence, for our legitimate business interests (or our reasonable and appropriate business purposes) to identify and align the candidate's skills and abilities with a specific job opening. Additionally, if you so choose, or consent, we can match your skills and abilities to other suitable roles at Citi.

Importantly, all our hiring processes and decisions, including determining your suitability for a role, are conducted, checked, and decided by individuals. Our automated processing and AI do not involve relying on automatic or autonomous decision-making. Please refer to any Jurisdictional Considerations, with specific provisions for your country (where relevant) for further details.

Citi is an equal opportunity employer, and qualified candidates will receive consideration without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other characteristic protected by law.

If you are a person with a disability and need a reasonable accommodation to use our search tools and/or apply for a career opportunity review Accessibility at Citi. View Citi’s EEO Policy Statement and the Know Your Rights poster.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cybersecurity Insider Threat Lead
Cybersecurity Insider Threat Lead

Citi • New York (NY)

On-site
USD 141,000 - 212,000
Cybersecurity Insider Threat Lead
Cybersecurity Insider Threat Lead

Citigroup Inc. • Tampa (FL)

On-site
USD 141,000 - 212,000
Insider Threat Engineering Support Lead
Insider Threat Engineering Support Lead

Citibank (Switzerland) AG • Irving (TX)

Hybrid
USD 126,000 - 189,000
Intelligence Lead Analyst
Intelligence Lead Analyst

Citigroup Inc. • Tampa (FL)

On-site
USD 114,000 - 171,000
Medical, dental & vision coverage
401(k)
Paid time off
+1
Cybersecurity Insider Threat Lead
Cybersecurity Insider Threat Lead

Citi • Tampa (FL)

On-site
USD 141,000 - 212,000
Medical, dental & vision coverage
401(k)
Life, accident, and disability保险
+3
Cybersecurity Insider Threat, Director
Cybersecurity Insider Threat, Director

Citigroup Inc. • Tampa (FL)

On-site
USD 170,000 - 300,000
Medical, dental, vision benefits
401(k) retirement plan
Paid time off and holidays
+1
Data Platform Engineer, Cybersecurity Operations
Data Platform Engineer, Cybersecurity Operations

Citigroup Inc. • Irving (TX)

On-site
USD 156,000 - 234,000
Citi Security and Investigative Services - Intelligence Lead Analyst
Citi Security and Investigative Services - Intelligence Lead Analyst

Citi • New York (NY)

Hybrid
USD 142,000 - 213,000
Threat & Exposure Management Platform Engineer
Threat & Exposure Management Platform Engineer

Citigroup Inc. • Irving (TX)

On-site
USD 156,000 - 234,000
Citi Security and Investigative Services - Intelligence Lead Analyst
Citi Security and Investigative Services - Intelligence Lead Analyst

Citigroup Inc. • New York (NY)

On-site
USD 142,000 - 213,000