Insider Threat EngineerActive
The opportunity
We’re not just a highly ambitious, large-scale technology company. We’re a highly ambitious, large-scale technology company with a soul.
What you'll do
Lead Insider Threat Digital Investigations: Conduct comprehensive technical investigations individually and partnering with our incident response teams into potential insider threat incidents, including data exfiltration, intellectual property theft, unauthorized access, and other malicious activities.
Knowledge and execution experience in collecting, preserving , and analyzing: digital evidence from a variety of sources (e.g., endpoints, network logs, cloud services, email, etc.).
Document all investigative steps and findings in a clear, concise, and defensible manner.
Present findings to senior leadership and cross-functional partners (Legal,: HR, Privacy) in a professional and objective manner.
Ensuring regulatory, legal and privacy requirements are met through all
Insider Threat Hunting: Proactively hunt for insider threats using a variety of security tools and data sources (e.g., SIEM, DLP, EDR, UEBA).
What they're looking for
- Develop and execute threat hunting hypotheses based on emerging threats,: attack techniques, and an understanding of our company's unique environment.
- Correlate disparate data points to identify anomalous or suspicious user behaviors.
- Detection & Response Improvement: Collaborate closely with the Security Incident Response Team (SIRT) and Threat Detection teams to continuously enhance our insider threat detection capabilities.
- Design, develop, and implement new rules, alerts, and use cases in our: security tools to identify insider threat indicators.