Insider Threat Analyst
Charles Schwab · Omaha, NE · 4 wk ago
HybridFull-time
About the role
We are expanding our Insider Threat Operations Team. This role supports and analyzes threat detection for the Cybersecurity Defense Insider Threat program. You will work with a team of analysts to identify and develop new processes and techniques to analyze information, detecting risks and gaps in people, processes, and technology. You will also utilize understanding of Insider Threat principles to identify trends and patterns, assisting in the development of new detection rules and models.
The role offers a hybrid/flexible schedule, with an in-office expectation of 4 or more days per week and the flexibility to work outside the office location for the other day.
Responsibilities
- Translate complex problems into implementable, preferably automated solutions.
- Collect, analyze, and interpret qualitative and quantitative data from multiple sources to provide viable threat intelligence.
- Understand and learn technical specifications, system requirements, and application design information.
- Monitor and analyze Data Loss Prevention (DLP) and Database Activity Monitoring (DAM) incidents to ensure compliance with company policies.
- Exercise sound judgment when determining which events require follow-up response or escalation.
- Work with internal customers to respond to escalations.
- Maintain incident documentation and analyze incident trends.
- Generate and maintain audit evidence for internal and external regulatory compliance.
- Function as a technical conduit between IT and the business.
- Apply Agile Methods in your workflow.
Requirements
- Understanding of computer networking concepts, communication protocols, and primary threat actor attack methods and tools.
- Familiarity with Insider Threat technologies such as Security Information Event Management (SIEM), User Entity Behavioral Analytics (UEBA), Endpoint Detection and Response (EDR), and Data Loss Prevention (DLP).
- Understanding of investigations and/or the intelligence cycle.
- Detail-oriented with a passion for quality and innovative technology.
- Strong verbal and written communication skills, comfortable composing briefs and assessments for leadership.
- Familiarity with analytical programming languages such as SQL.
- Ability to thrive in ambiguity and rapid change.
- Comfortable with process flow diagrams.
- Basic understanding of a variety of security and compliance policies and incident response processes.
Qualifications
- Bachelor’s degree in computer science or related field (preferred).
- 4 - 7 years of related experience, including developing requirements, designing, and executing test cases in insider threat and data loss prevention (preferred).
Benefits
- 401(k) with company match and Employee Stock Purchase Plan.
- Paid time for vacation, volunteering, and a 28-day sabbatical after every 5 years of service for eligible positions.
- Paid parental leave and family building benefits.
- Tuition reimbursement.
- Health, dental, and vision insurance.