Insider Threat Engineer
Job in
Austin, Travis County, Texas, 78716, USA
Listed on 2026-07-21
Listing for:
Jobtailor
Full Time
position Listed on 2026-07-21
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Security Management & Operations
Job Description & How to Apply Below
Responsibilities
- Lead Insider Threat Digital Investigations
- Conduct comprehensive technical investigations individually and partnering with incident response teams into potential insider threat incidents, including data exfiltration, intellectual property theft, unauthorized access, and other malicious activities
- Collect, preserve, and analyze digital evidence from a variety of sources (endpoints, network logs, cloud services, email, etc.)
- Document all investigative steps and findings in a clear, concise, and defensible manner
- Present findings to senior leadership and cross‑functional partners (Legal, HR, Privacy) in a professional and objective manner
- Ensure regulatory, legal and privacy requirements are met throughout investigations
- Insider Threat Hunting: proactively hunt for insider threats using security tools and data sources (SIEM, DLP, EDR, UEBA)
- Develop and execute threat hunting hypotheses based on emerging threats, attack techniques, and an understanding of the company's unique environment
- Correlate disparate data points to identify anomalous or suspicious user behaviors
- Detection & Response Improvement: collaborate with SIRT and Threat Detection teams to enhance insider threat detection capabilities
- Design, develop, and implement new rules, alerts, and use cases in security tools to identify insider threat indicators
- Evaluate and recommend new technologies and processes to mature the Insider Threat program
- Develop and refine response playbooks for various insider threat scenarios
- Cross‑Functional
Collaboration:
serve as the primary technical liaison for the Insider Threat program, building strong, trusted relationships with Legal, HR, and Privacy teams - Work in lockstep with these teams to ensure investigations are conducted with sensitivity, respect for employee privacy, and within legal and ethical guidelines
- Provide technical expertise and guidance during policy development and incident response planning
- 5+ years of experience in a technical security role, with at least 2+ years focused on insider threat, digital forensics, or security investigations
- Proven experience in conducting and leading complex technical investigations, including the use of forensic tools (e.g., EnCase, FTK, X-Ways, or open-source alternatives)
- Deep understanding of security technologies such as SIEM (e.g., Splunk, Elastic), EDR (e.g., Crowd Strike, Sentinel One), and UEBA data sources
- Strong scripting and programming skills (e.g., Python, Power Shell) to automate tasks and analyze large datasets
- Excellent communication skills, both written and verbal, with the ability to explain complex technical concepts to non‑technical audiences
- Experience working with legal and HR teams on sensitive employee‑related matters
Demonstrates expertise in leading insider threat investigations, utilizing advanced forensic tools and security technologies to analyze and respond to potential threats. Strong collaboration with cross‑functional teams ensures compliance with legal and privacy standards while effectively communicating findings to stakeholders.
Tools & Technologies- Security Information and Event Management (SIEM)
- Data Loss Prevention (DLP)
- Endpoint Detection and Response (EDR)
- User and Entity Behavior Analytics (UEBA)
- Forensic Tools
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×