Senior Security Engineer Insider Trust
You lead the development of Insider Trust infrastructure and automate end-to-end detection and investigation workflows. You develop, measure, and tune Sigma detection rules, drive projects addressing insider risks, and provide technical expertise and evidence during insider investigations. You conduct technical investigations and sensitive interviews, collaborate with cross-functional partners, and implement improvements to modernize security operations.
Responsibilities
- Build and lead the Insider Trust Team’s infrastructure
- Automate end-to-end detection and investigation workflows
- Develop measure and tune detection rules in Sigma
- Drive projects addressing insider risks including access abuse and intellectual property theft
- Work with Threat Management People Legal IT and Engineering on insider investigations
- Provide technical expertise and evidence during insider investigations
- Assist with sensitive interviews during insider threat investigations
- Identify and implement areas of improvement and modernization
Requirements
- 7+ years of experience conducting technical investigations and working in an Insider Threat capacity
- Deep experience in macOS-focused environments, including log collection, log analysis, digital investigations, and forensics
- Knowledge of Insider Threat tactics and attack paths
- Knowledge of data exfiltration techniques
- Experience running and leading insider incidents independently and as part of a team
- Familiarity with Insider Threat investigations of modern cloud infrastructure
- Strong critical thinking
- Integrity
- Objectivity
- Maturity
- Scripting experience with Python, Bash, or similar
- Experience with detection-as-code development and Sigma workflows
- Ability to write clear incident updates and summaries
- Ability to explain risk, impact, and trade-offs to technical and non-technical stakeholders
- Experience with blockchain/Web3 threats
Benefits
- Long-term incentives
- Comprehensive benefits