Share this job
Insider Threat Investigator
Washington, DC
Apply for this job

As a Cyber Security Operations Insider Threat Investigator, you will play a critical role in protecting our clients from cyber threats. You will be responsible for investigating suspicious activities, anomalous events, and behaviors that may pose a security risk to the company. Your contributions will be vital in ensuring our systems are secure and our clients’ data is protected, making a direct impact on overall security strategy.

What you'll do:

  • Investigate potential insider threat, sabotage, data exfiltration, misuse, and misrepresentation cases
  • Analyze and interpret SIEM, DLP, EUBA, proxy, system logs, email, DLP, CASB, endpoint, network, database, application logs and other potential case related artifacts
  • Execute complex investigations, conduct interviews, write objective reports
  • Advise on root cause analysis, preventative controls, and new detections
  • Aid in maturing the Enterprise Insider Threat Program
  • Perform threat hunts and new alert triage to determine efficacy of UEBA alert program feeding investigations
  • Perform deep analysis of large data sets to identify trends, tuning opportunities, and control creation
  • Through analysis, identify root cause themes including bad business practices and work with control owners to reduce risk & enhance overall security posture
  • Perform security reviews, cyber defense trend analysis and open-source research, partnering with Threat Intelligence on emerging risks

Experience you'll need to have:

  • 7+ years of experience in insider threat investigations, cybersecurity, incident response, law enforcement, or financial crimes with deep knowledge of Insider Threat UEBA platforms, User Activity Monitoring (UAM) or other similar Machine Learning /Risk Score methodologies/concepts
  • Experience conducting complex technical investigations including deep log analysis of systems, network, applications and tools, managing chain of custody and evidence preservation
  • Experience conducting interviews
  • Deep understanding of Insider Threat anatomy of attack and nation-state sponsored espionage / cyber espionage activities
  • Strong written communication skills with experience writing fact-based objective reports for legal, HR, and other business partners.
  • Maintain thorough documentation for each case and meticulously curate artifacts and evidence.
  • Recommend risk mitigation and root cause analysis for cases and develop case scoping queries on the fly while working cases
  • Understanding and experience of investigative procedures including preservation, analysis, reporting, and presentation.
  • Experience with OSINT, public records, and link analysis
  • Experienced with SIEM/SOAR technologies such as Splunk, Google SecOps, log sourcing, forwarders, parsing, data pipeline and management, data architecture
  • Working knowledge of EDR, NDR, DLP, CASB solutions
  • Working knowledge of information security operations frameworks and standards – MITRE, NIST, Cyber Kill Chain, etc.
  • Familiar with best practice security principles on identity & access management, network security, endpoint security, vulnerability management, and application security
  • Ability to obtain security clearance and/or active C6 security clearance (or higher) preferred
  • Knowledge of computer networking concepts, protocols, and network security methodologies.
  • Knowledge of cyber-attack stages and techniques used by malicious insiders.
  • Working knowledge of global data protection privacy regulations

Experience that would be great to have:

  • (Preferred) Experience in technical investigations, law enforcement, HUMINT, and/or Counterintelligence,
  • (Preferred) Training and/or experience with financial crimes
  • Certifications such as CMU CERT ITPM/ ITVA, CCITP, CISM, CDPSE or similar
  • Experience in data science and analytics solutions applicable to the insider threat detection space.
  • Exposure to programming, scripting and query languages such as Python, bash, SQL, Lucene, YARA-L, and SPL.
  • Experience working in financial services or financial technology desired.


Apply for this job
Powered by