Senior Security Engineer, Insider Trust
Lead Insider Trust infrastructure, automate detection and investigation workflows, develop Sigma detection rules, investigate insider risks, and support sensitive interviews and cross-functional security operations.
Responsibilities
- Build and lead the Insider Trust Team’s infrastructure
- Automate end-to-end detection and investigation workflows
- Develop, measure, and tune Sigma detection rules
- Drive projects addressing insider risks, access abuse, intellectual property theft, and emerging blockchain/Web3 risks
- Collaborate with Threat Management, People, Legal, IT, and Engineering on insider investigations
- Provide technical expertise and evidence during insider investigations
- Assist with sensitive insider threat interviews
- Identify and implement improvements and modernization
Requirements
- 7+ years of experience conducting technical investigations and working in an Insider Threat capacity
- Deep experience in macOS-focused environments, including log collection, log analysis, digital investigations, and forensics
- Knowledge of Insider Threat tactics, attack paths, and data exfiltration techniques
- Experience leading insider incidents independently and as part of a team
- Familiarity with Insider Threat investigations of modern cloud infrastructure
- Strong critical thinking, integrity, objectivity, and maturity
- Python, Bash, or similar scripting experience
- Experience with detection-as-code development and Sigma workflows
- Ability to write clear incident updates and explain risk, impact, and trade-offs to technical and non-technical stakeholders
- Experience with blockchain/Web3 threats
Benefits
- Long-term incentives
- Comprehensive benefits