Security Engineer - Insider Threat

HR Tech Job

Atlanta (GA)

On-site

USD 152,000 - 228,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Bonus eligibility
Stock grants

Job summary

Workday, Inc. seeks a Senior Insider Threat Investigator in Atlanta, Georgia. The role involves monitoring and mitigating insider risks through detailed investigations and collaborative work with the Security Incident Response Team.

The ideal candidate will have over 8 years of experience in insider threat investigations and strong proficiency in SIEM and UEBA tools. The salary range for this position is between $152,000 and $228,000 annually, with potential bonuses and stock options.

Qualifications

  • 8+ years of experience in insider threat investigations or related discipline.
  • Proven track record in leading complex investigations.
  • Functional proficiency with SIEM and UEBA tools.

Responsibilities

  • Monitor, detect, and mitigate insider risks.
  • Conduct end-to-end insider threat investigations.
  • Collaborate with Security Incident Response Team.

Skills

Insider threat investigations
Intelligence analysis
Incident response
Communication skills
Analytical skills

Education

Bachelor’s degree in Criminal Justice or related field

Tools

SIEM platforms (e.g., Splunk, QRadar)
UEBA tools (e.g., Exabeam)
DLP tools

Job description

About the Role

We are seeking a Senior Insider Threat Investigator to join our Insider Threat organization to assist with monitoring, detecting, and mitigating insider risk. This role sits at the intersection of investigations, intelligence, and risk. You will help Workday identify patterns for detections and build out processes and controls to mitigate identified areas of opportunity. You will work closely with our Security Incident Response Team and Cyber Incident Management team to identify and mitigate enterprise threats to the confidentiality, integrity, and availability of Workday information systems and information. This position will lead and conduct end‑to‑end insider threat investigations, spanning initial detection to triage and through resolution and closeout.

Responsibilities
  • Assist with monitoring, detecting, and mitigating insider risk.
  • Help Workday identify patterns for detections and build out processes and controls to mitigate identified areas of opportunity.
  • Work closely with the Security Incident Response Team and Cyber Incident Management team to identify and mitigate enterprise threats to the confidentiality, integrity, and availability of Workday information systems and information.
  • Lead and conduct end‑to‑end insider threat investigations, spanning initial detection to triage and through resolution and closeout.
  • Interview subjects, witnesses, and stakeholders; manage document review and preservation; and execute investigative inquiries in alignment with company policies, establish investigative procedures, and law.
  • Coordinate with SIRT, IT, and Legal to collect, preserve, and analyze digital evidence in accordance with chain of custody requirements, industry best practices and legal hold requirements.
Basic Qualifications
  • 8+ years of progressive experience in insider threat investigations, counterintelligence, corporate investigations, incident response, intelligence analysis, or closely related discipline.
  • Bachelor’s degree in Criminal justice, Cybersecurity, Intelligence Studies, Law, or closely related field.
  • Demonstrated track record leading or materially contributing to insider threat programs and complex, sensitive, cross‑functional investigations in a government, corporate, or law enforcement environment.
  • Functional proficiency with SIEM platforms (e.g., Splunk, QRadar, Sentinel) and UEBA tools (e.g., Exabeam, Proofpoint, DTEX, Purview); able to construct and execute queries, triage and prioritize alerts, and interpret behavioral analytics outputs.
  • Working knowledge of DLP tools, endpoint detection, and digital forensic concepts.
  • Familiarity with Insider threat framework, threat assessment principles, including CERT, CISA, and NTTF standards.
  • Strong interpersonal and communication skills; able to operate with discretion and credibility across Legal, P&P, and executive stakeholder groups on sensitive matters.
  • Sound judgment and integrity; able to navigate ambiguous situations, manage competing priorities, and make defensible decisions under pressure.
Other Qualifications
  • Background in federal law enforcement (FBI, NCIS, AFOSI, ACIC), the U.S. Intelligence Community, U.S. military or government intelligence, federal insider threat programs, and cybersecurity.
  • Experience building or maturing a formal insider threat program, including development of investigation processes, detection logic, governance and documentation.
  • Experience with case management platforms and maintaining investigation documentation.
  • Exposure to behavioral threat assessment and threat management programs; participation in industry working groups and forums.
  • Relevant certifications: CERT Insider Threat Program Manager (ITPM), Global Counter‑Insider Threat Professional (GCITP), Certified Counter‑Insider Threat Professional – F/A(CCITP), Certified Protection Professional (CPP), Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), CompTIA Certifications, GIAC certification, Certified Fraud Examiner (CFE).
Pay Transparency Statement

Primary Location: USA.GA.Atlanta
Base Pay Range: $152,000 USD – $228,000 USD
Additional US Locations Base Pay Range: $144,400 USD – $258,000 USD
If performed in Colorado, the pay range for this job is $152,000 – $228,000 USD based on min and max pay range for that role if performed in CO.
As a part of the total compensation package, this role may be eligible for the Workday Bonus Plan or a role‑specific commission/bonus, as well as annual refresh stock grants.

EEO and Equal Opportunity Statement

Workday is an Equal Opportunity Employer including individuals with disabilities and protected veterans. Pursuant to applicable Fair Chance law, Workday will consider for employment qualified applicants with arrest and conviction records. Workday is committed to providing an accessible and inclusive hiring experience where all candidates can fully demonstrate their skills. If you require assistance or an accommodation at any point, please email accommodations@workday.com.

EEO Statement (Expanded)

Workday is proud to be an equal opportunity workplace. Individuals seeking employment at Workday are considered without regards to age, ancestry, color, gender (including pregnancy, childbirth, or related medical conditions), gender identity or expression, genetic information, marital status, medical condition, mental or physical disability, national origin, protected family care or medical leave status, race, religion (including beliefs and practices or the absence thereof), sexual orientation, military or veteran status, or any other characteristic protected by federal, state, or local laws. Further, pursuant to applicable local ordinances, Workday will consider for employment qualified applicants with arrest and conviction records. We do not accept resumes from headhunters, placement agencies, or other suppliers that have not signed a formal agreement with us. Workday is committed to providing reasonable accommodations for qualified individuals with disabilities, disabled veterans, and others during our application process. If you need assistance or an accommodation due to a disability or for religious reasons, contact us at accommodations@workday.com.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Insider Threat Analyst
Senior Insider Threat Analyst

Socket.dev • Atlanta (CO)

Hybrid
USD 152,000 - 228,000
Senior Insider Threat Analyst
Senior Insider Threat Analyst

Workday • Boulder (CO)

Hybrid
USD 152,000 - 228,000
Flex Work option
Senior Insider Threat Analyst
Senior Insider Threat Analyst

Workday • Atlanta (GA)

Hybrid
USD 144,000 - 258,000
Senior Cybersecurity Engineer - US Federal
Senior Cybersecurity Engineer - US Federal

Workday, Inc. • Reston (VA), Northern (KY)

Hybrid
USD 144,000 - 258,000
Cybersecurity Engineer - US Federal
Cybersecurity Engineer - US Federal

Workday • Reston (VA)

On-site
USD 130,000 - 195,000
Principal Cybersecurity Engineer
Principal Cybersecurity Engineer

Workday • Boulder (CO)

Hybrid
USD 176,000 - 264,000
Principal Active Defense Engineer
Principal Active Defense Engineer

Workday, Inc. • Reston (VA), Northern (KY)

Hybrid
USD 167,000 - 300,000
Sr Active Defense Engineer
Sr Active Defense Engineer

Workday, Inc. • Reston (VA)

On-site
USD 160,000 - 239,000
Senior Cybersecurity Engineer - US Federal
Senior Cybersecurity Engineer - US Federal

Workday • Reston (VA)

Hybrid
USD 160,000 - 239,000
Principal Cybersecurity Engineer - US Federal
Principal Cybersecurity Engineer - US Federal

Workday, Inc. • Reston (VA), Northern (KY)

On-site
USD 190,000 - 280,000