Full Job Description
Job Summary This position supports the enterprise insider threat program as a senior analyst, focusing on insider threat and information security alerting, triage, escalation, and investigation. The role performs end-to-end investigations of insider-driven and employee-related information security events using enterprise security monitoring and case management platforms. The position supports continuous monitoring, investigation, and escalation of high-risk activity.
Key Responsibilities • Triage, analyze, investigate, escalate, and document insider threat and information security alerts generated from enterprise security tooling. • Act as an escalation point for alerts originating from XSOAR, Data Loss Prevention (DLP), and insider threat monitoring platforms. • Assess alerts for risk severity, insider intent, data exposure, and regulatory impact to determine appropriate investigative and escalation actions. • Conduct end-to-end insider threat and information security investigations, including employee-driven data loss and unauthorized access to systems or sensitive data. • Conduct interviews as part of insider threat and information security investigations. • Correlate signals across endpoint, identity, network, email, and collaboration data sources to establish investigative findings. • Collect, analyze, and preserve evidence while maintaining documentation and chain of custody standards. • Prepare clear, audit-defensible investigative summaries with findings, conclusions, and recommended actions. • Perform Salesforce engineering, development, and testing.
Required Qualifications • 7+ years of experience in one or more of the following areas: insider threat investigations, information security or cybersecurity investigations, financial crimes or corporate investigations, security operations, or incident response. • Hands-on experience triaging and investigating security alerts using enterprise security platforms. • Experience operating in high-tempo investigative or security environments. • Experience conducting interviews as part of investigative activities. • Working knowledge and investigative experience with XSOAR, Splunk, CrowdStrike, and Anvilogic. • Ability to correlate multi-source security telemetry into actionable investigative findings. • Relevant industry certifications in cybersecurity, investigations, or interviewing techniques.
Preferred Qualifications • Bachelor's degree or equivalent education, training, or work-related experience. • Banking or financial services experience, including regulatory or audit exposure. • Prior collaboration with Human Resources, Legal, Compliance, or Financial Crimes teams. • Experience with insider threat, UEBA, or advanced security analytics platforms.