Jobs · Oregon

Insider Risk Security Engineer

Lam Research · Tualatin, OR · 3 days ago
Full-time

About the role

The Information Security Insider Risk team is responsible for protecting Lam and its customers' data from risks associated with individuals who have authorized access, while partnering with cross-functional teams to support a variety of additional investigative efforts.

As an Insider Risk Security Engineer at Lam Research, you will play a critical role in helping manage insider risk and build out our insider risk capabilities. You will drive tooling requirements to determine anomalous user activities and indicators, and provide support during active incidents alongside key stakeholders. You may also support cross-functional opportunities to identify security trends and metrics, develop innovative use cases for detecting anomalous events, and enhance insider risk efforts. Using sophisticated technology and robust partnerships, you will help enhance our insider risk posture against nation-state actors, negligent and malicious employee activity, and support high-risk populations from potential compromise. This role is focused specifically on insider risk and human-risk compromise, not external cybersecurity incident response.

Responsibilities

  • Implement and maintain Insider Risk Management (IRM) technologies, policies, and rules across Lam, ensuring effective operation, troubleshooting, and alignment with infrastructure.
  • Collaborate with Lam’s Cybersecurity Engineering team and cross-functional partners (IT, HR, Legal) to define and refine policies protecting sensitive data.
  • Drive continuous improvement by fine-tuning IRM and DLP rules to minimize false positives and maturing the Insider Risk Engineering function.
  • Serve as the technical expert and escalation point for insider risk, providing guidance and support to colleagues and collaborators.
  • Contribute to regular management reporting, offering insights into the performance and effectiveness of the IRM ecosystem.
  • Maintain confidentiality and use sound discretion and judgment in all aspects of the role.

Requirements

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Security, Information Technology, Counterintelligence, or a related discipline.
  • 5+ years of experience as a security engineer, with familiarity in DLP and UEBA tools.
  • Proven experience implementing, troubleshooting, and administering Insider Risk and DLP technologies in a global enterprise.
  • Experience with cloud security and cloud-based applications.
  • Excellent problem-solving skills and the ability to work independently.
  • Outstanding communication skills, with the ability to collaborate effectively across teams and stakeholders.

Preferred Qualifications

  • Certifications in cybersecurity, such as CISSP, CISM, or CEH.
  • Formal education and training in insider risk and/or counterintelligence.
  • Knowledge and experience with Microsoft E5 security products and UEBA tools.
  • Knowledge of KQL, YARA, Regex, JSON, and Lucene Query Syntax.
  • Knowledge of behavioral analysis and psychology.
  • Experience within a global semiconductor company or equivalent industry.

Schedule

This role follows a hybrid work model. For ‘On-site Flex,’ you’ll work 3+ days per week on-site at a Lam or customer/supplier location, with the opportunity to work remotely for the balance of the week. For ‘Virtual Flex,’ you’ll work 1-2 days per week on-site, and remotely the rest of the time.

Benefits

Lam offers a comprehensive set of benefits designed to support employees throughout various phases of life, including health, wellness, and professional development opportunities.

Similar jobs