
Insider Risk Security Engineer
Posted 8 hours ago

Posted 8 hours ago
This is a fully remote position, open to applicants in United States.
• Enhance the Insider Risk Program detection rules to minimize noise, bridge coverage gaps, and generate high-fidelity alerts promptly.
• Conduct investigations into endpoint and user activities utilizing EDR/XDR, UEBA, and SIEM tools, managing cases from start to finish to establish factual timelines.
• Create and refine insider risk investigation playbooks, converting case patterns and insights gained into scalable and defensible processes.
• Act as a primary contact for HR, Legal, business leaders, and other stakeholders regarding ongoing investigations.
• Draft clear evidentiary case documentation.
• Guide junior analysts and represent the team in interactions with HR, Legal, and executive stakeholders.
• Report directly to the Senior Architect in the Enterprise Security Department and follow operational guidance from the Insider Risk Team Lead.
• Fundamental knowledge of AI/ML technologies and experience in leveraging, securing, or positioning AI-driven solutions to enhance outcomes within your functional area.
• U.S. Citizenship is mandatory.
• At least 6+ years of experience in insider risk, data protection, fraud investigation, or security operations, with a demonstrated history in senior investigative roles, process ownership, and the creation of detection frameworks and playbooks.
• Experience in managing and resolving alerts within a SIEM or SOAR environment.
• Excellent communication skills with a proven ability to engage cross-functionally with HR, Legal, business leaders, and other stakeholders while upholding discretion and sound judgment.
• Proficiency in Python or JavaScript, with experience in applying automation to investigative processes.
• Hands-on experience with Zscaler's product suite in a large enterprise setting is preferred.
• Experience collaborating with product development teams to implement security use cases is preferred.
• Relevant certifications such as GCFA or GCFE, or equivalent forensics credentials are preferred.
• Familiarity with CERT, NIST, and NSA frameworks is preferred.
• Various health plans.
• Time off plans for vacation and sick leave.
• Parental leave options.
• Retirement options.
• Education reimbursement.
• In-office perks.
Viatris
ActBlue
AlphaSense
SysMap Solutions
Get handpicked remote jobs straight to your inbox weekly.