Job Summary
We are seeking a Senior Insider Threat Analyst to support the development, implementation, and operation of an enterprise Insider Threat Program. This role will help deter, detect, investigate, and mitigate insider threats through monitoring user activity, analyzing Data Loss Prevention (DLP) events, and evaluating behavioral indicators of potentially malicious or negligent activity. The position will collaborate with Cyber Threat Intelligence, Security Operations, Incident Response, Data Protection, Risk, Human Resources, Legal, Compliance, Privacy, and business stakeholders to protect sensitive information, intellectual property, and critical business assets from unauthorized disclosure, misuse, theft, fraud, sabotage, or compromise.
Key Responsibilities
• Conduct proactive monitoring and analysis of insider threat indicators across multiple technologies and data sources.
• Perform technical investigations involving potential insider threat activity, data exfiltration, policy violations, fraud, intellectual property theft, and unauthorized access to sensitive information.
• Analyze user activity, network events, endpoint telemetry, DLP alerts, and security logs to identify suspicious or anomalous behavior.
• Execute investigative requests and document findings, recommendations, and mitigation actions.
• Partner with Cyber Security Incident Response teams on complex investigations requiring advanced analysis and evidence collection.
• Assist in defining and prioritizing Insider Threat Program objectives, roadmaps, and strategic initiatives.
• Support the development and maturity of insider threat detection methodologies, monitoring use cases, and investigative procedures.
• Identify opportunities to enhance insider threat capabilities through automation, analytics, behavioral monitoring, and emerging technologies.
• Recommend improvements to tools, processes, and workflows to improve detection effectiveness and operational efficiency.
• Contribute to the development of KPIs, metrics, reporting, and program dashboards.
• Develop and refine detection rules, correlation logic, and analytical use cases to identify insider risk activity.
• Utilize trend analysis, behavioral analytics, anomaly detection, data mining, and user activity monitoring techniques to identify potential threats.
• Track, prioritize, and manage insider threat cases through resolution using established case management processes.
• Collaborate with Human Resources, Legal, Compliance, Privacy, Risk Management, and business stakeholders when appropriate.
• Support the development and delivery of Insider Threat awareness campaigns and security education initiatives.
• Prepare presentations, reports, and executive-level summaries regarding program effectiveness, risks, and emerging trends.
• Foster relationships with internal and external partners to support investigative efforts and information sharing.
Required Qualifications
• Bachelor's degree in Cyber Security, Computer Science, Information Systems, Criminal Justice, or a related field, or an equivalent combination of education and experience.
• 5+ years of experience in Cyber Security, Incident Response, Security Operations, Digital Forensics, Threat Detection, or Information Security.
• 2+ years of direct experience supporting an Insider Threat, Insider Risk, Data Protection, or User Activity Monitoring program.
• Hands-on experience with Data Loss Prevention (DLP) technologies such as Microsoft Purview, Netskope DLP, or similar platforms.
• Experience managing investigations and security incidents using case management platforms such as Resilient, ServiceNow, or equivalent tools.
• Understanding of cyber investigation methodologies, chain of custody principles, and evidence handling.
• Strong analytical and problem-solving skills, with the ability to identify meaningful patterns within large datasets.
• Ability to communicate effectively with technical and non-technical stakeholders.
• Strong investigative mindset, critical thinking, and attention to detail.
• Ability to handle sensitive and confidential information with discretion.
Preferred Qualifications
• Experience supporting a mature enterprise Insider Threat or Insider Risk Management program.
• Hands-on experience with Microsoft Purview Insider Risk Management, Microsoft Defender, Exabeam, ObserveIT, DTEX, Proofpoint, Forcepoint, or other insider threat platforms.
• Experience with SIEM technologies such as Splunk, CrowdStrike, or equivalent platforms.
• Strong understanding of User and Entity Behavior Analytics (UEBA).
• Experience conducting cloud security investigations across Microsoft 365 and Azure environments.
• Knowledge of legal, privacy, human resources, and regulatory considerations associated with insider threat investigations.
• Experience working within a Security Operations Center (SOC) environment.
• Experience supporting global organizations and cross-functional teams across multiple time zones.
• CISSP (Certified Information Systems Security Professional).
• GCFA (GIAC Certified Forensic Analyst).
• GCTI (GIAC Cyber Threat Intelligence).
• Insider Threat Program Manager (ITPM) or equivalent insider threat certification.
• Microsoft Security certifications focused on Purview, Defender, or Sentinel.
Certifications
• ISACA Audit certification.
• Security+ certification.
• GSEC (GIAC Security Essentials).
• GCIH (GIAC Certified Incident Handler).