Sr. Security Engineer, Insider Threat Detection & Response

Cypress HCM

United States

On-site

USD 169,000 - 190,000

Full time

3 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Cypress HCM is seeking a security engineer to develop and execute insider threat detection and response capabilities. You will work across engineering, HR, and Legal to build scalable detection and investigation tooling and participate in 24/7 threat monitoring.

The role emphasizes hands-on security operations, threat hunting, and collaboration to mitigate insider threats across corporate and production environments in a fast-paced setting.

Qualifications

  • Bachelor's degree or equivalent practical experience.
  • Experience with Insider Threat technologies (DLP, UEBA, etc.).
  • Exposure to data science and analytics solutions in insider threat space.

Responsibilities

  • Identify gaps in infrastructure and gain visibility through logging and detection.
  • Be part of on-call rotation to provide 24/7 coverage for threat detection and incident response.
  • Use coding, data analytics and investigation skills to hunt, detect and respond to insider threats.
  • Write detections to identify data abuse and data exfiltration at scale.
  • Build automation and detection models to identify anomalous activity and mitigation actions.
  • Hunt for insider threats in corporate and production environments.
  • Collaborate with engineering to build advanced detection solutions and with HR/Legal for investigations.
  • Consult on countermeasures to mitigate insider threats.

Skills

Detection engineering
Threat hunting
Incident response
Digital forensics
Threat intelligence
Security operations
On-call/24-7 coverage

Education

Bachelor's degree

Tools

Python
AWS
SQL

Job description

Description
  • The Threat Detection and Response Team (TDR) is focused on automating security detection, responding to security incidents, and working with partner teams to build capabilities that support the security incident response lifecycle. This is the front-line team that detects, investigates, and responds to security threats and malicious activity against our data, systems and infrastructure.
  • To further increase our coverage, the team is looking to build a mature and world-class insider threat program. This is a key role to implement and execute our vision for insider threat detection capabilities while working closely with other team members. As a security engineer, you will have direct impact building capabilities for a new program through influence and technical contributions.
Duties
  • Identify gaps in our infrastructure, and work with business partners to gain visibility through logging and detection.
  • Be part of the on‑call rotation to provide 24/7 coverage for threat detection and incident response.
  • Use your coding, data analytics and investigation skills to hunt, detect and respond to insider threats.
  • Write detection to detect data abuse and data exfiltration at scale.
  • Build automation and detection models to support identification of anomalous activity and response activities to mitigate insider threats at scale.
  • Hunt for insider threats in our corporate and production environments to proactively identify anomalous activity.
  • Work side by side with our engineering teams to build advanced detection solutions to help keep systems and information safe, and partner closely with our Human Resources and Legal teams to carry out complex investigations.
  • Identify and consult on the design of countermeasures to mitigate insider threats in our environment.
  • Partner with stakeholders to contribute to Security Awareness messaging and Training.
  • Participate in incident response activities and provide expertise during Insider Threat incidents.
Requirements
  • 5+ years of hands‑on in‑depth knowledge and technical experience in security operations including detection engineering, threat hunting, incident response, digital forensics, and/or threat intelligence.
  • Bachelor's degree in a related technical field or equivalent practical experience.
  • Exposure to data science and analytics solutions applicable to the insider threat detection space.
  • Experience with Insider Threat technologies (Data Loss Prevention solutions, UEBA, ).
  • Foundational understanding of the relationship between insider threat and Incident Response, including how to effectively coordinate responses to insider threat incidents.
  • Mid‑level knowledge of insider threats within B2C companies, with a focus on security challenges specific to this industry.
  • Knowledge and familiarity of the Cyber Kill Chain Framework and MITRE ATT&CK Framework and how these apply to the insider threat landscape.
  • Experience automating security detection and response.
  • Experience in AWS services (EC2, S3, Lambda, RDS) preferred
  • We are not focused on specific tools but we often use Python, AWS, SQL, and more.
  • Self‑motivated and creative problem‑solver able to work independently with minimal guidance.
  • Ability to work calmly and collaboratively in critical high‑stress situations with expediency.
  • Outstanding organizational, prioritization, and multitasking skills.
Compensation
  • $122.56 – 137.93/hr W—2
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Insider Threat Investigator III
Insider Threat Investigator III

Jobtailor • Atlanta (GA)

On-site
USD 110,000 - 140,000
Insider Threat Analyst
Insider Threat Analyst

Motion Recruitment Partners LLC • Washington, Northern (KY)

Hybrid
USD 90,000 - 140,000
Security Engineer (Insider Risk)
Security Engineer (Insider Risk)

Dragonfli Group • Washington

Hybrid
USD 120,000 - 160,000
Insurance - health, dental, and vision
Paid Time Off (PTO) and 11 Federal Holidays
401(k) employer match
Information Security Engineer - Insider Risk
Information Security Engineer - Insider Risk

Palantir • Washington

On-site
USD 145,000 - 200,000
Medical, dental, and vision insurance
Paid time off
401k plan
+2
Senior Security Operations & Incident Response Engineer
Senior Security Operations & Incident Response Engineer

SCIGON • Chicago (IL)

On-site
USD 113,000 - 150,000
Senior Cyber Security Specialist I - Insider Threat Analysis
Senior Cyber Security Specialist I - Insider Threat Analysis

Walgreens • United States

Hybrid
USD 98,000 - 158,000
Senior Security Analyst
Senior Security Analyst

Yardi Systems • Santa Barbara (CA)

Hybrid
USD 97,000 - 110,000
Flexible work arrangements
100% paid employee medical premiums
Company profit-sharing plan
Insider Threat Associate Director
Insider Threat Associate Director

The Depository Trust & Clearing Corporation (DTCC) • Tampa (FL)

Hybrid
USD 90,000 - 120,000
Competitive compensation
Comprehensive health and life insurance
Pension / Retirement benefits
+1
Security Tools Engineer
Security Tools Engineer

Total Quality Logistics • Cincinnati (OH)

On-site
USD 95,000 - 135,000
Performance bonus
Comprehensive benefits package
Health, dental, and vision coverage
+1
Detection & Response Engineering Manager
Detection & Response Engineering Manager

InfraTech Solutions LLC • Chicago (IL)

Hybrid
USD 150,000 - 180,000
Health, dental, and vision insurance
Paid time off and holidays
Parental leave
+2