Enable job alerts via email!

Sr Engineer, Cyber Insider Threat - Network Activity Logs - Remote

Lensa

United States

Remote

USD 80,000 - 189,000

Full time

Yesterday
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

Join a forward-thinking company as a Senior Engineer in Cybersecurity, focusing on insider threat detection and prevention. In this remote role, you will lead the development of innovative strategies and systems to monitor and mitigate insider risks. Collaborate with a dynamic team of cybersecurity professionals to analyze user activity and improve detection capabilities. Your expertise in data analytics and cybersecurity protocols will be crucial in shaping the future of the insider threat program. If you're passionate about protecting organizations from internal threats and enjoy working on complex projects, this is the perfect opportunity for you.

Qualifications

  • 6+ years of experience in cybersecurity, DLP, or investigative analysis.
  • Expert understanding of insider threat concepts and tools.
  • Proficiency in automating workflows and integrating security tools.

Responsibilities

  • Lead the design and implementation of insider threat detection strategies.
  • Collaborate with cybersecurity teams to enhance monitoring capabilities.
  • Conduct in-depth analysis of logs from various data sources.

Skills

Cybersecurity
Insider Threat Detection
Data Analytics
User Activity Monitoring (UAM)
Data Loss Prevention (DLP)
Security Information and Event Management (SIEM)
Leadership Skills
Communication Skills
Technical Investigations
Automation Workflows

Education

Bachelor’s degree in Computer Science
Equivalent education or work experience

Tools

UEBA
EDR Tools
Excel
SQL
PowerPoint
Red Vector
Code42
Exabeam
DTEX

Job description

Sr Engineer, Cyber Insider Threat - Network Activity Logs - Remote

Job Summary

The Sr Engineer, Insider Threat will implement cyber intelligence (CyInt) collection, compilation, and analysis for the insider threat program. Implements data sets, tools, and provides program support to insider threat analysts and investigations. Works closely with our cybersecurity team, other technical teams, and business stakeholders to develop advanced insider threat systems and processes.

Job Duties

  1. Lead the design, development, and implementation of a comprehensive insider threat monitoring and detection strategy integrating technical and non-technical components.
  2. Collaborate with cybersecurity analysts, engineers, and other program stakeholders to develop and refine insider threat monitoring and detection capabilities.
  3. Correlate information from multiple technical user activity monitoring (UAM), user entity behavior analytics (UEBA), data loss prevention (DLP), security information and event management (SIEM), and non-technical data sources to enable proactive insider risk/threat detection.
  4. Utilize cybersecurity expertise, knowledge of insider threat detection, and data analytics to create innovative strategies for detecting and preventing malicious activities.
  5. Conduct in-depth analysis of logs received from various data sources.
  6. Architect and implement automation of investigation and escalation workflows.
  7. Contribute to internal investigations, providing support for forensic analysis, log review, and alert analysis.
  8. Execute rigorous testing on internal security mechanisms to validate their effectiveness.
  9. Develop and maintain insider risk techniques and procedures, including use cases around data exfiltration, internal fraud, privilege escalations, and sabotage.
  10. Evaluate, recommend, and improve upon existing technical and non-technical solutions to detect and respond to potential insider threats.
  11. Guide the technical architecture of insider threat systems, ensuring alignment with organizational security and business goals.
  12. Publish internal CyInt threat intelligence products and briefings to provide actionable information to stakeholders.
  13. Define security controls and metrics to measure the effectiveness of the insider threat program.
  14. Stay updated on emerging insider threat trends and adapt strategies accordingly.
  15. Coordinate with stakeholders on CyInt activities to ensure compliance with policies and regulations.

Job Qualifications

REQUIRED QUALIFICATIONS:

  • Bachelor’s degree in computer science, Cybersecurity, Information Systems, or equivalent education or work experience.
  • Expert understanding of cybersecurity and insider threat concepts, protocols, and tools.
  • Experience with UEBA deployment, administration, data source integrations, and configurations.
  • Strong knowledge of data protection and privacy regulations.
  • Exceptional leadership, communication, and presentation skills.
  • At least 6 years of experience in cybersecurity, DLP, Security Operations, investigative analysis, or the intelligence field.
  • Experience leading or conducting technical investigations utilizing insider threat tools.
  • Ability to manage confidential matters with appropriate judgment around escalation.
  • Experience with data analytics tools used for insider threat information collection and risk scoring.
  • Action-oriented engineer with the ability to work autonomously and own complex projects.
  • Experience developing and implementing defensive controls around Windows, MacOS, Linux, and SaaS applications.
  • Proficiency with automating workflows and integrating security tools within IT environments.

PREFERRED QUALIFICATIONS:

  • Experience with UEBA/SIEMs.
  • Experience with Endpoint Detection and Response (EDR) tools, device management tooling, and telemetry sources.
  • Experience working on insider threat teams or investigations.
  • Experience with broad system forensics.
  • Ability to communicate technical security concerns to non-technical audiences.
  • Experience with insider threat tools (e.g., Red Vector, Code42, Exabeam, DTEX).
  • Experience working with sensitive/confidential information.
  • Familiarity with cybersecurity fundamentals (TCP/IP, BGP, DNS), digital forensics, data exfiltration methods.
  • Experience analyzing complex datasets using Excel or SQL.
  • Experience developing PowerPoint presentations.
  • Relevant certifications (e.g., Security+, CISSP, CISM, CERT Insider Threat, CEH).

Pay Range: $80,412 - $188,164 / ANNUAL

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

DATA ARCHITECT - DIGITAL HEALTH

Premier Health Partners

Dayton

Remote

USD 131,000 - 219,000

5 days ago
Be an early applicant

Sr Engineer, Cyber Insider Threat - Network Activity Logs - Remote

Molina Healthcare

Bellevue

Remote

USD 54,000 - 112,000

Yesterday
Be an early applicant

Sr Engineer, Cyber Insider Threat - Network Activity Logs - Remote

Lensa

Albuquerque

Remote

USD 80,000 - 189,000

Today
Be an early applicant

Sr Engineer, Cyber Insider Threat - Network Activity Logs - Remote

Lensa

Augusta

Remote

USD 80,000 - 189,000

Today
Be an early applicant

Sr Engineer, Cyber Insider Threat - Network Activity Logs - Remote

Lensa

Austin

Remote

USD 80,000 - 189,000

2 days ago
Be an early applicant

Sr Engineer, Cyber Insider Threat - Network Activity Logs - Remote

Lensa

Covington

Remote

USD 80,000 - 100,000

Today
Be an early applicant

Sr Engineer, Cyber Insider Threat - Network Activity Logs - Remote

Lensa

Orlando

Remote

USD 80,000 - 189,000

Today
Be an early applicant

Senior Oracle ERP Developer

BDO USA

Tampa

Remote

USD 120,000 - 145,000

5 days ago
Be an early applicant

Senior Software Engineer Team Lead

Patriot Software, LLC

Canton

Hybrid

USD 145,000 - 170,000

2 days ago
Be an early applicant