Insider Threat Engineering Support Lead

Citibank (Switzerland) AG

Irving (TX)

Hybrid

USD 126,000 - 189,000

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Citi in Irving, Texas, seeks an inquisitive Insider Threat Engineering Support Lead to join Cybersecurity Operations & Engineering. The role blends security engineering, data analytics, and behavioral threat hunting to identify and mitigate internal risk, detect data movement, and tune high‑fidelity detection controls.

Responsibilities include developing and optimizing detection rules for SIEM/data platforms, proactive threat hunting across multi-source telemetry, and supporting end-to-end

Qualifications

  • 6+ years of experience constructing, tuning, and executing complex queries within SIEM, data lake, or log analytics platforms (e.g., Splunk, KQL/Sentinel, Elastic, SQL, Snowflake).
  • Experience in threat hunting to identify stealthy, anomalous, or policy-violating activity across enterprise log sources.
  • Ability to navigate, sanitize, query, and troubleshoot high-volume datasets.
  • Strong communication and ability to work independently in a fast-paced environment.

Responsibilities

  • Detection Engineering & Rule Optimization: Develop, test, tune, and maintain behavioral analytics and detection rules to identify insider threats.
  • Proactive Threat Hunting & Analytics: Conduct hypothesis-driven threat hunting across multi-source logs and telemetry data.
  • Engineering Support & Process Improvement: Support SDLC, version control, documentation, testing, and deployment of detection artifacts.

Skills

Threat hunting
Detection engineering
Data analysis
Self-directed work
Communication

Education

Bachelor’s degree
Master’s degree preferred

Tools

Splunk
KQL/Sentinel
Elastic
SQL
Snowflake

Job description

## Insider Threat Engineering Support LeadApply: Hybrid: Irving Texas United States: Full time: Posted Today: End Date: October 25, 2026 (24 days left to apply): 26996726**Role Overview** Seeking an inquisitive, analytical, and hands-on **Insider Threat Engineering Support Lead** to join our Cybersecurity Operations & Engineering team. This role sits at the intersection of security engineering, data analytics, and behavioral threat hunting. Unlike traditional perimeter-focused cybersecurity roles, this position focuses on identifying, mitigating, and engineering detection controls around internal human-risk factors, anomalous behavioral patterns, and unauthorized data movement. The ideal candidate blends an investigative mindset with engineering acumen to design, tune, and operationalize high-fidelity detections, proactively hunt across massive enterprise telemetry datasets, and continuously enhance our insider threat mitigation posture. **Key Responsibilities****Detection Engineering & Rule Optimization*** Develop, test, tune, and maintain behavioral analytics, hunt-based queries, and SIEM/data platform detection rules to identify insider threat vectors (e.g., data exfiltration, privilege abuse, unauthorized access).* Translate investigative insights and newly identified threat patterns into automated, resilient detection logic.* Monitor detection effectiveness, minimizing false positives while maximizing coverage against known insider attack methodologies.**Proactive Threat Hunting & Analytics*** Conduct hypothesis-driven threat hunting across multi-source log repositories, behavioral baselines, and disparate telemetry data to uncover undetected threats.* Analyze and troubleshoot large, complex datasets to establish normal baseline activity and isolate anomalies.* Partner with incident response and insider threat analysts to operationalize hunt findings into long-term defensive safeguards.**Engineering Support & Process Improvement*** Support the end-to-end detection engineering lifecycle, incorporating Secure Software Development Lifecycle (SDLC) best practices, version control, and comprehensive technical documentation.* Participate in testing, validation, and continuous delivery of detection artifacts.* Manage priorities autonomously in a fast-paced environment, driving deliverables from concept through deployment.**Candidate Qualifications & Requirements****Desired Skills & Experience*** **Domain Knowledge:** Strong understanding of core Cybersecurity and Insider Threat concepts, specifically the behavioral, access, and human-centric risk models that distinguish insider threats from external attacks.* **Query & Detection Engineering:** 6+ years of experience constructing, tuning, and executing complex queries within SIEM, data lake, or log analytics platforms (e.g., Splunk, KQL/Sentinel, Elastic, SQL, Snowflake).* **Threat Hunting:** Demonstrated ability to perform proactive, hypothesis-based threat hunting to identify stealthy, anomalous, or policy-violating activity across enterprise log sources.* **Data Analysis & Troubleshooting:** Exceptional attention to detail with the ability to navigate, sanitize, query, and troubleshoot high-volume, heterogeneous datasets.* **Self-Directed Execution:** Demonstrated capability to independently manage workload, prioritize high-impact initiatives, and deliver results with minimal supervision.**Behavioral Attributes & Core Competencies*** **Inquisitive & Investigative Mindset**: High natural curiosity and an \"outside-the-box\" analytical approach to solving ambiguous problems and tracing subtle anomalies.* **Hybrid Engineering & Investigation Focus**: Ability to view telemetry through both an investigator's analytical lens and a software/security engineer’s systems-building perspective.* **Effective Communication**: Ability to articulate complex data findings and engineering designs clearly to technical peers and non-technical stakeholders alike.**Education:*** Bachelor’s degree/University degree or equivalent experience* Master’s degree preferred This job description provides a high-level review of the types of work performed. Other job-related duties may be assigned as required. ------------------------------------------------------## **Job Family Group:**Technology------------------------------------------------------## **Job Family:**Information Security------------------------------------------------------## **Time Type:**Full time------------------------------------------------------## **Primary Location:**Irving Texas United States------------------------------------------------------## **Primary Location Full Time Salary Range:**$125,760.00 - $188,640.00In addition to salary, Citi’s offerings may also include, for eligible employees, discretionary and formulaic incentive and retention awards. Citi offers competitive employee benefits, including: medical, dental & vision coverage; 401(k); life, accident, and disability insurance; and wellness programs. Citi also offers paid time off packages, including planned time off (vacation), unplanned time off (sick leave), and paid holidays. For additional information regarding Citi employee benefits, please visit citibenefits.com. Available offerings may vary by jurisdiction, job level, and date of hire.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cybersecurity Insider Threat Lead
Cybersecurity Insider Threat Lead

Citi • Tampa (FL)

On-site
USD 141,000 - 212,000
Medical, dental & vision coverage
401(k)
Life, accident, and disability保险
+3
Cybersecurity Insider Threat Lead
Cybersecurity Insider Threat Lead

Citi • New York (NY)

On-site
USD 141,000 - 212,000
Cybersecurity Insider Threat Lead
Cybersecurity Insider Threat Lead

Citigroup Inc. • Tampa (FL)

On-site
USD 141,000 - 212,000
Threat & Exposure Management Platform Engineer
Threat & Exposure Management Platform Engineer

Citibank (Switzerland) AG • Irving (TX)

Hybrid
USD 156,000 - 234,000
Cybersecurity Insider Threat, Director
Cybersecurity Insider Threat, Director

Citigroup Inc. • Tampa (FL)

On-site
USD 170,000 - 300,000
Medical, dental, vision benefits
401(k) retirement plan
Paid time off and holidays
+1
Intelligence Senior Analyst
Intelligence Senior Analyst

Citibank (Switzerland) AG • Tampa (FL)

On-site
Confidential
Sr. Manager, Insider Risk & Digital Forensics
Sr. Manager, Insider Risk & Digital Forensics

Huntington • Atlanta (TX)

On-site
USD 140,000 - 190,000
Insider Threat Detection Engineering Lead
Insider Threat Detection Engineering Lead

Citibank (Switzerland) AG • Irving (TX)

Hybrid
USD 126,000 - 189,000
Data Platform Engineer, Cybersecurity Operations
Data Platform Engineer, Cybersecurity Operations

Citi • Irving (TX)

On-site
USD 156,000 - 234,000
CSIS Intelligence Lead Analyst - Advanced Analytics and Cyber OSINT
CSIS Intelligence Lead Analyst - Advanced Analytics and Cyber OSINT

Citi • Tampa (FL)

On-site
USD 117,000 - 176,000