Enable job alerts via email!

Sr Engineer, Cyber Insider Threat - Network Activity Logs - Remote

Lensa

San Antonio (TX)

Remote

USD 80,000 - 189,000

Full time

Yesterday
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

A leading career site is seeking a Sr Engineer for Cyber Insider Threat to implement and analyze cyber intelligence for insider threat programs. This role involves developing monitoring strategies, collaborating with cybersecurity teams, and ensuring compliance with security protocols. Ideal candidates will have extensive experience in cybersecurity and a strong understanding of insider threat concepts.

Qualifications

  • 6+ years of experience in cybersecurity or related fields.
  • Expert understanding of insider threat concepts and tools.
  • Proficient in programming or scripting languages (Java, Python, etc.).

Responsibilities

  • Lead the design and implementation of insider threat monitoring strategies.
  • Collaborate with cybersecurity teams to refine detection capabilities.
  • Conduct in-depth analysis of logs from various data sources.

Skills

Leadership
Communication
Data Protection
Data Analytics
Cybersecurity

Education

Bachelor’s degree in computer science, Cybersecurity, Information Systems

Tools

UEBA
SIEM
EDR
PowerShell
SQL

Job description

Sr Engineer, Cyber Insider Threat - Network Activity Logs - Remote

1 day ago Be among the first 25 applicants

Get AI-powered advice on this job and more exclusive features.

Lensa is the leading career site for job seekers at every stage of their career. Our client, Molina Healthcare, is seeking professionals. Apply via Lensa today!

Job Description
Job Summary

The Sr Engineer, Insider Threat will implement cyber intelligence (CyInt) collection, compilation, and analysis for the insider threat program. Implements data sets, tools, and provides program support to insider threat analysts and investigations. Works closely with our cybersecurity team, other technical teams, and business stakeholders to develop advanced insider threat systems and processes.

Job Duties
  1. Lead the design, development, and implementation of a comprehensive insider threat monitoring and detection strategy integrating technical and non-technical components
  2. Collaborate with cybersecurity analysts, engineers, and other program stakeholders to develop and refine insider threat monitoring and detection capabilities
  3. Correlate information from multiple technical user activity monitoring (UAM), user entity behavior analytics (UEBA), data loss prevention (DLP), security information and event management (SIEM), and non-technical data sources to enable proactive insider risk/threat detection
  4. Utilize cybersecurity expertise, knowledge of insider threat detection, and data analytics to create innovative strategies for detecting and preventing malicious activities
  5. Conduct in-depth analysis of logs received from various data sources
  6. Architect and implement automation of investigation and escalation workflows
  7. Contribute to internal investigations by providing support for forensic analysis, log review, and alert analysis
  8. Execute rigorous testing on internal security mechanisms to validate their effectiveness
  9. Develop and maintain insider risk techniques and procedures, including use cases surrounding data exfiltration, internal fraud, privilege escalations, and sabotage
  10. Evaluate, recommend, and improve existing technical and non-technical solutions to detect and respond to potential insider threats
  11. Guide the technical architecture of insider threat systems, ensuring alignment with security and business goals
  12. Publish internal CyInt threat intelligence products and briefings for stakeholders
  13. Define security controls and metrics to measure the effectiveness of the insider threat program
  14. Stay updated on emerging insider threat trends and adjust strategies accordingly
  15. Coordinate with stakeholders on CyInt activities to ensure policy and regulatory compliance
Job Qualifications
REQUIRED QUALIFICATIONS:
  1. Bachelor’s degree in computer science, Cybersecurity, Information Systems, or equivalent experience
  2. Expert understanding of cybersecurity and insider threat concepts, protocols, and tools
  3. Experience with UEBA deployment, administration, data source integrations, and configurations
  4. Strong knowledge of data protection and privacy regulations
  5. Proficient in at least one programming or scripting language such as Java, Python, .NET, JavaScript, or C+
  6. Experience in scripting languages such as PowerShell, Perl, or Bash
  7. Exceptional leadership, communication, and presentation skills
  8. At least 6 years of experience in cybersecurity, DLP, Security Operations, investigative analysis, or the intelligence field
  9. Experience leading or conducting technical investigations utilizing insider threat tools
  10. Ability to professionally manage confidential matters with appropriate judgment around escalation
  11. Experience with data analytics tools used for insider threat information collection and knowledge of other insider threat risk scoring data analytics tools
  12. Action-oriented engineer with the ability to work autonomously and take ownership of complex projects
  13. Experience developing and implementing defensive controls around Windows, MacOS, Linux, and SaaS applications
  14. Proficiency with automating workflows and integrating security tools within IT environments
Preferred Qualifications
  1. Experience with UEBA/SIEMs
  2. Experience with Endpoint Detection and Response (EDR) tools, device management tooling, and other telemetry sources
  3. Experience working on insider threat teams or investigations
  4. Experience with broad system forensics
  5. Ability to communicate technical security concerns to non-technical audiences
  6. Experience with insider threat tools (e.g., Red Vector, Code42, Exabeam, DTEX)
  7. Experience working with confidential or sensitive information
  8. Familiarity with cybersecurity fundamentals (TCP/IP, BGP, DNS), digital forensics, data exfiltration methods
  9. Experience with Excel or SQL for analyzing complex datasets
  10. Experience developing PowerPoint presentations
  11. Relevant security certifications (e.g., Security+, CISSP, CISM, CERT Insider Threat, CEH)
Pay Range

$80,412 - $188,164 / ANNUAL

Note: Actual compensation may vary based on location, experience, education, and skills.

Additional Details
  • Seniority level: Mid-Senior level
  • Employment type: Full-time
  • Job function: Engineering and Information Technology
  • Industries: IT Services and IT Consulting
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Sr Engineer, Cyber Insider Threat - Network Activity Logs - Remote

Lensa

Kenosha

Remote

USD 80.000 - 189.000

7 days ago
Be an early applicant

Sr Engineer, Cyber Insider Threat - Network Activity Logs - Remote

Lensa

San Antonio

Remote

USD 80.000 - 189.000

7 days ago
Be an early applicant

Sr Engineer, Cyber Insider Threat - Network Activity Logs - Remote

Lensa

Saint Petersburg

Remote

USD 80.000 - 189.000

Today
Be an early applicant

Senior Software Engineer - Content

Automox

Tampa

Remote

USD 140.000 - 175.000

7 days ago
Be an early applicant

Sr Engineer, Cyber Insider Threat - Network Activity Logs - Remote

Lensa

Grand Rapids

Remote

USD 80.000 - 189.000

Today
Be an early applicant

Sr Engineer, Cyber Insider Threat - Network Activity Logs - Remote

Lensa

Cincinnati

Remote

USD 80.000 - 189.000

Today
Be an early applicant

Specialist Systems Engineering

Pearson

City of Albany

Remote

USD 60.000 - 140.000

Yesterday
Be an early applicant

Senior Staff Engineer - PaaS File Exchange (REMOTE)

GEICO

Louisville

Remote

USD 105.000 - 260.000

Yesterday
Be an early applicant

Sr Engineer, Cyber Insider Threat - Network Activity Logs - Remote

Lensa

Rio Rancho

Remote

USD 80.000 - 189.000

6 days ago
Be an early applicant