Position Overview
We are seeking an experienced Information Security Engineer with a strong background in cybersecurity operations, insider threat management, incident response, security monitoring, and data protection. The ideal candidate will have hands-on experience implementing and supporting Insider Threat Programs, DLP controls, investigative processes, and user behavior analytics within an enterprise environment.
This role will work closely with security, IT, compliance, legal, HR, and other business stakeholders to identify and mitigate security risks, investigate potential threats, and strengthen the organization's overall security posture.
Key Responsibilities
- Design, implement, and support Insider Threat Program capabilities, processes, and controls.
- Develop and maintain Data Loss Prevention (DLP) policies, controls, monitoring, and investigative workflows.
- Conduct security investigations involving potential insider threats, data exfiltration, policy violations, and suspicious user activity.
- Leverage User and Entity Behavior Analytics (UEBA/UBA) to identify anomalous or potentially risky behavior.
- Monitor and investigate security events using SIEM, EDR, and enterprise security monitoring platforms.
- Support incident response activities, including investigation, containment, remediation, documentation, and lessons learned.
- Collaborate with IAM/PAM teams to identify and address risks associated with privileged and user access.
- Develop and improve security monitoring use cases, detection logic, alerts, dashboards, and investigative procedures.
- Partner with cross-functional stakeholders to implement security controls and manage security-related projects.
- Maintain documentation, procedures, metrics, and reporting related to insider threat, DLP, investigations, and security operations.
- Support regulatory, audit, and compliance requirements related to information security, data protection, and monitoring.
- Identify opportunities to improve security processes, controls, automation, and operational efficiency.
Required Qualifications
- 5+ years of experience in Cybersecurity Operations, Insider Threat, Incident Response, Security Monitoring, Information Security, or a related discipline.
- Hands-on experience implementing or supporting Insider Threat Programs.
- Experience with DLP controls, data protection, security investigations, and investigative workflows.
- Experience with User Behavior Analytics (UBA/UEBA) and identifying anomalous user activity.
- Strong understanding of cybersecurity operations, incident response, threat detection, and security monitoring.
- Experience working with enterprise security technologies such as SIEM, EDR, IAM/PAM, and security monitoring platforms.
- Strong analytical, investigative, problem-solving, and communication skills.
- Ability to manage multiple security initiatives and collaborate effectively with technical and business stakeholders.
Preferred Qualifications
- Experience with project management and security program implementation.
- Experience working with regulatory, audit, risk, and compliance requirements.
- Experience developing security policies, procedures, controls, and operational processes.
- Familiarity with enterprise-scale cybersecurity environments and security operations centers (SOC).
- Experience with security automation, orchestration, and workflow optimization.
- Relevant cybersecurity certifications such as CISSP, CISM, GIAC, Security+, or equivalent.