Senior Insider Threat Analyst

Compunnel

$110K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Cyber Security, Computer Science, Information Systems, or related field or equivalent experience.
  • 5+ years in Cyber Security, Incident Response, or Information Security.
  • 2+ years in Insider Threat, User Activity Monitoring, or Data Protection programs.
  • Hands-on with Data Loss Prevention technologies like Microsoft Purview or Netskope DLP.
  • Experience with case management tools such as Resilient or ServiceNow.
  • Strong analytical skills for detecting patterns in large datasets.
  • Effective communication with both technical and non-technical audiences.

Responsibilities

  • Monitor and analyze insider threat indicators from various technologies.
  • Conduct investigations related to insider threats, data exfiltration, and policy violations.
  • Analyze user activities and security logs for suspicious behavior.
  • Document investigative findings, recommendations, and mitigation actions.
  • Collaborate on complex investigations requiring detailed analysis and evidence.
  • Define and prioritize objectives and initiatives for the Insider Threat Program.
  • Enhance detection methodologies and monitoring processes.

Benefits

  • Opportunity to support a critical and emerging area of cybersecurity.
  • Collaborative environment working with multiple departments and stakeholders.
  • Focus on development and maturity of insider threat capabilities.
  • Engagement in data-driven analysis and automation projects.
  • Exposure to advanced security technologies and methodologies.
Full Job Description
Job Summary
We are seeking a Senior Insider Threat Analyst to support the development, implementation, and operation of an enterprise Insider Threat Program. This role will help deter, detect, investigate, and mitigate insider threats through monitoring user activity, analyzing Data Loss Prevention (DLP) events, and evaluating behavioral indicators of potentially malicious or negligent activity. The position will collaborate with Cyber Threat Intelligence, Security Operations, Incident Response, Data Protection, Risk, Human Resources, Legal, Compliance, Privacy, and business stakeholders to protect sensitive information, intellectual property, and critical business assets from unauthorized disclosure, misuse, theft, fraud, sabotage, or compromise.

Key Responsibilities
• Conduct proactive monitoring and analysis of insider threat indicators across multiple technologies and data sources.
• Perform technical investigations involving potential insider threat activity, data exfiltration, policy violations, fraud, intellectual property theft, and unauthorized access to sensitive information.
• Analyze user activity, network events, endpoint telemetry, DLP alerts, and security logs to identify suspicious or anomalous behavior.
• Execute investigative requests and document findings, recommendations, and mitigation actions.
• Partner with Cyber Security Incident Response teams on complex investigations requiring advanced analysis and evidence collection.
• Assist in defining and prioritizing Insider Threat Program objectives, roadmaps, and strategic initiatives.
• Support the development and maturity of insider threat detection methodologies, monitoring use cases, and investigative procedures.
• Identify opportunities to enhance insider threat capabilities through automation, analytics, behavioral monitoring, and emerging technologies.
• Recommend improvements to tools, processes, and workflows to improve detection effectiveness and operational efficiency.
• Contribute to the development of KPIs, metrics, reporting, and program dashboards.
• Develop and refine detection rules, correlation logic, and analytical use cases to identify insider risk activity.
• Utilize trend analysis, behavioral analytics, anomaly detection, data mining, and user activity monitoring techniques to identify potential threats.
• Track, prioritize, and manage insider threat cases through resolution using established case management processes.
• Collaborate with Human Resources, Legal, Compliance, Privacy, Risk Management, and business stakeholders when appropriate.
• Support the development and delivery of Insider Threat awareness campaigns and security education initiatives.
• Prepare presentations, reports, and executive-level summaries regarding program effectiveness, risks, and emerging trends.
• Foster relationships with internal and external partners to support investigative efforts and information sharing.

Required Qualifications
• Bachelor's degree in Cyber Security, Computer Science, Information Systems, Criminal Justice, or a related field, or an equivalent combination of education and experience.
• 5+ years of experience in Cyber Security, Incident Response, Security Operations, Digital Forensics, Threat Detection, or Information Security.
• 2+ years of direct experience supporting an Insider Threat, Insider Risk, Data Protection, or User Activity Monitoring program.
• Hands-on experience with Data Loss Prevention (DLP) technologies such as Microsoft Purview, Netskope DLP, or similar platforms.
• Experience managing investigations and security incidents using case management platforms such as Resilient, ServiceNow, or equivalent tools.
• Understanding of cyber investigation methodologies, chain of custody principles, and evidence handling.
• Strong analytical and problem-solving skills, with the ability to identify meaningful patterns within large datasets.
• Ability to communicate effectively with technical and non-technical stakeholders.
• Strong investigative mindset, critical thinking, and attention to detail.
• Ability to handle sensitive and confidential information with discretion.

Preferred Qualifications
• Experience supporting a mature enterprise Insider Threat or Insider Risk Management program.
• Hands-on experience with Microsoft Purview Insider Risk Management, Microsoft Defender, Exabeam, ObserveIT, DTEX, Proofpoint, Forcepoint, or other insider threat platforms.
• Experience with SIEM technologies such as Splunk, CrowdStrike, or equivalent platforms.
• Strong understanding of User and Entity Behavior Analytics (UEBA).
• Experience conducting cloud security investigations across Microsoft 365 and Azure environments.
• Knowledge of legal, privacy, human resources, and regulatory considerations associated with insider threat investigations.
• Experience working within a Security Operations Center (SOC) environment.
• Experience supporting global organizations and cross-functional teams across multiple time zones.
• CISSP (Certified Information Systems Security Professional).
• GCFA (GIAC Certified Forensic Analyst).
• GCTI (GIAC Cyber Threat Intelligence).
• Insider Threat Program Manager (ITPM) or equivalent insider threat certification.
• Microsoft Security certifications focused on Purview, Defender, or Sentinel.

Certifications
• ISACA Audit certification.
• Security+ certification.
• GSEC (GIAC Security Essentials).
• GCIH (GIAC Certified Incident Handler).

Similar Jobs

More Jobs at Compunnel

More Information Technology Jobs

Find similar Senior Insider Threat Analyst jobs: