United States•Canada
Remote
Senior
Full Time
22 days ago
💰$ 110,000 - $ 269,000
securityinsider threatblockchainweb3remote
Requirements
- •7+ years of experience conducting technical investigations and working in an Insider Threat capacity
- •Deep experience in macOS focused environments, including log collection, log analysis, digital investigations, and forensics
- •Knowledge of Insider Threat tactics and attack paths, data exfiltration techniques, and experience running and leading insider incidents independently and as part of a team
- •Broad familiarity with Insider Threat investigations of modern cloud infrastructure
- •Strong critical thinking skills, as well as integrity, objectivity, and maturity
What You'll Do
- •Own and lead building out the Insider Trust Team’s infrastructure to engineer and automate end-to-end detection and investigation workflows
- •Develop, measure, and tune detection rules in Sigma to ensure effective and sustainable operations
- •Drive projects with a focus on Insider Risks, ranging from access abuse and intellectual property theft, to novel risks emerging within the blockchain/Web3 space
- •Work closely with cross-functional teams, including Threat Management, People, Legal, IT, and Engineering, and provide technical expertise and evidence to lead insider investigations
- •Assist in conducting sensitive interviews during insider threat investigations, bringing your technical subject matter expertise to support fact finding
- •Proactively identify and implement areas of improvement and modernization
Nice to Have
- •Prior success in remote-first environments as a self-starter Insider Threat security engineer
- •Previous scripting experience (Python, Bash, or similar) to include scripting for data parsing/enrichment and automations
- •Experience with detection‑as‑code development and workflows in Sigma
- •Collaborative, straightforward communication skills with the ability to write clear incident updates and summaries
- •Ability to explain risk, impact, and trade‑offs to both technical and non‑technical stakeholders and have a proven record of building trust with partner teams during high‑pressure situations
- •Domain experience with blockchain/Web3 threats
- •Usage of AI technology to augment and enhance Insider Threat investigations
- •Open-source contributions to security related projects, with a focus on Insider Threat
