×
Register Here to Apply for Jobs or Post Jobs. X

Senior Insider Threat Analyst

Job in Atlanta, Fulton County, Georgia, 30301, USA
Listing for: Workday
Full Time position
Listed on 2026-08-31
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, Security Management & Operations
Job Description & How to Apply Below

Insider Threat Analyst

Workday is seeking a skilled Insider Threat Analyst to support a dynamic environment. In this role, you will play a critical part in identifying, analyzing, and mitigating insider threats by leveraging advanced security tools, behavioral analytics, and investigative techniques. You will collaborate with cross-functional teams to assess risks, detect anomalies, and enhance the organization's overall insider threat posture.

Key Responsibilities:

  • Detection Engineering & Alert Fidelity Optimization:
    Design, build, and continuously refine insider threat detection logic, use cases, and analytics to improve signal quality. Focus on reducing false positives and increasing the percentage of actionable insider threat alerts.
  • Alert Triage, Investigation, & Feedback Loop:
    Lead triage and investigation of insider threat alerts, applying structured methodologies to assess risk Translate investigation outcomes into detection improvements, ensuring a continuous feedback loop between operations and engineering.
  • Detection Strategy & Use Case Development:
    Develop and implement a scalable detection strategy aligned to key insider threat risks (i.e., data exfiltration, employee exit risk, misuse). Identify gaps and prioritize new detection use cases to expand coverage and effectiveness
  • Threat Hunting & Advanced Analytics:
    Conduct proactive threat hunting using behavioral, endpoint, and data activity signals to identify emerging insider risks. Translate findings into new detection use cases and improvements to existing detection logic.
  • Cross-Functional Partnership:
    Partner with Data Protection, Legal, HR, and Cyber teams to ensure detections are risk-aligned, context-aware, and operationally actionable. Incorporate business context and investigation requirements into detection design to improve alert fidelity and response effectiveness.

Basic Qualifications:

  • 8+ years of experience in Insider Threat, Security operations, Threat Hunting, Intelligence analysis, corporate investigations or counterintelligence.
  • Threat hunting experience in a corporate or government environment.
  • Hand On experience designing, tuning, and operationalizing detection logic and policies in tools such as Proofpoint, DTEX, Exabeam, Netskope, or similar UEBA and DLP tools.
  • Experience working with and analyzing data or related telemetry to identify and investigate insider risk activity in DLP UEBA, UAM, and SIEM solutions.
  • Experience developing program metrics and presenting finding to senior leadership.

Other

Qualifications:

  • Experience mapping detections to MITRE ATT&CK and other Insider threat TTP knowledge bases.
  • Strong experience with insider threat detection methodologies, behavioral analytics, and risk indicators
  • Proven ability to design, tune, and operationalize detection logic to improve alert quality and reduce noise
  • Analytical mindset with ability to translate investigation outcomes into detection improvements
  • Understanding of data classification, data movement patterns, and exfiltration techniques
  • Ability to measure and improve detection effectiveness (i.e., alert fidelity, actionable alert rate)
  • Strong collaboration and communication skills to influence cross-functional stakeholders
  • Bachelor's degree in a relevant discipline such as Computer Science, Cybersecurity, Information Security, or a related discipline, or equivalent practical experience.
  • Experience implementing automation or orchestration in security operations (SOAR, APIs, pipelines, scripted workflows) to accelerate response and improve consistency.
  • Experience applying AI-assisted analytics for alert enrichment, correlation/deduplication, prioritization, and operational reporting.
  • Experience contributing to training, playbooks, and tabletop exercise development.
  • Relevant industry certifications (e.g., GCIA, GCIH, GCFA, ITPM, SEC+)
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary