Insider Threat Engineer
Listed on 2026-02-21
-
IT/Tech
Cybersecurity, Data Security, Systems Engineer
At Early Warning, we’ve powered and protected the U.S. financial system for over thirty years with cutting‑edge solutions like Zelle®, Paze℠, and so much more. As a trusted name in payments, we partner with thousands of institutions to increase access to financial services and protect transactions for hundreds of millions of consumers and small businesses.
Positions located in Scottsdale, San Francisco, Chicago, or New York follow a hybrid work model to allow for a more collaborative working environment.
Candidates responding to this posting must independently possess the eligibility to work in the United States, for any employer, at the date of hire. This position is ineligible for employment Visa sponsorship.
Overall PurposeThe Staff Insider Threat Engineer is part of a high‑performance team, responsible for detecting, identifying, mitigating, and responding to critical or urgent insider threat situations. The individual will work closely with CSIRT, HR, Legal, Privacy, and other teams to identify, triage, and respond to insider threats.
Essential Functions- Lead the deployment, configuration, and tuning of insider threat detection tools to ensure optimal performance and integration with existing security systems.
- Mature and improve the comprehensive insider threat program aligned with organizational goals and regulatory standards.
- Monitor user and entity behavior analytics to identify suspicious activities and policy violations.
- Perform detection and investigative analysis activities for a variety of digital devices, computers, storage media, servers, networks, and cloud‑based services.
- Perform advanced host and network forensics and malware analysis; investigate and respond to incidents; provide recommendations to improve company’s security posture;
Escalate complex issues as needed. - Track investigations and incidents through resolution.
- Help analyze vulnerabilities from insider threat perspectives and elevate & remediate as needed.
- Use data collected from a variety of cyber defense tools (e.g., DLP, IDS alerts, firewalls, network traffic logs) to analyze events that occur within their environments for the purposes of mitigating insider threats.
- Maintain awareness of trends in security, regulatory, technology, and operational requirements.
- Maintain awareness of current threat landscape, including adversary tactics, techniques, and procedures.
- Create intellectual property such as procedural documentation and tools for automated analysis and correlation activities.
- Represent the Insider threat team at internal and external threat intelligence and cybersecurity forums.
- Perform on‑call activities when required.
- Ensure the company's commitment to protect the integrity and confidentiality of systems and data.
- Education and/or experience typically obtained through completion of a Bachelor’s degree or 2‑year degree in Computer Science, Engineering, Math or Physical Science or equivalent experience.
- Minimum 10 years of progressive information security technology experience.
- Proven advanced analytical skills across various technologies.
- Advanced understanding of networking and security concepts.
- Advanced understanding of insider threat techniques and detection.
- Ability to generate incident and event write‑ups for a non‑technical audience.
- Experience in identifying, triaging, and escalating tickets based on severity and malicious activity.
- Experience in responding to malicious threats coming from various sources.
- Experience with the incident response process.
- Ability to work within a team environment as well as independently.
- Effective communication skills to speak and write for all technology experience levels.
- Effective interpersonal skills, able to comfortably present to peers, coworkers, and customers.
- A propensity for continued development of skills through research and training.
- Background and drug screen.
- Additional related education, certifications and/or experience is beneficial.
- Subject matter expert within insider threat domains, threat actors, and data engineering.
- Subject matter expert in one or more security tools such as EDR platforms, SIEMs or UBA tools.
- Working…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).