Remote job
Insider Risk Security Engineer
Job details
About this role
Role overview
This is a senior individual contributor role on an Insider Risk team within an Enterprise Security organization. The position focuses on strengthening detection capabilities, leading complex investigations, and translating casework into durable playbooks and processes. It is fully remote within the United States and partners closely with HR, Legal, and business leadership on sensitive matters.
Responsibilities
- Tune and refine insider risk detection logic to reduce noise, close coverage gaps, and surface high-fidelity alerts in a timely manner - Conduct endpoint and user activity investigations using EDR/XDR, UEBA, and SIEM tooling, managing cases end-to-end and building factual timelines - Author, maintain, and iterate insider risk investigation playbooks, capturing repeatable patterns from real cases - Act as a primary liaison with HR, Legal, and executive stakeholders during active matters, producing clear and defensible documentation - Mentor junior analysts and help mature the team's operating model
Requirements
- 6+ years of hands-on experience in insider risk, data protection, fraud investigation, or security operations, including senior investigative work - Demonstrated ownership of detection frameworks, playbooks, and end-to-end case disposition - Practical experience managing and resolving alerts inside a SIEM or SOAR platform - Working proficiency in Python or JavaScript, with applied use of automation in investigative workflows - Foundational understanding of AI/ML concepts and how they apply within a security domain - Strong written and verbal communication skills, with the ability to engage cross-functionally while exercising discretion - U.S. citizenship
Nice to have
- Hands-on familiarity with zero-trust networking, data protection, and cyber-risk protection platforms in a large enterprise setting - Experience partnering with product engineering teams to ship security use cases - Industry certifications such as GCFA or GCFE, or equivalent digital forensics credentials - Familiarity with CERT, NIST, or NSA insider threat frameworks
Benefits and work setup
- Remote within the United States - Base salary range of $134,000 to $167,500 USD, benchmarked by role and level - Comprehensive benefits program covering health plans, paid time off, parental leave, retirement options, education reimbursement, and additional in-office perks