Jobs · Information Technology · Massachusetts

Senior Insider Threat Analyst

Apex Systems · Quincy, MA · Yesterday
Information TechnologyFull-time

Overview

Our client in the banking industry is seeking a Senior Insider Threat Analyst who will report into the Head of Cyber Security Operations and serves as a key contributor in the development, implementation, and operation of the organization's Insider Threat Program. This role is responsible for helping deter, detect, investigate, and mitigate insider threats through the monitoring of user activity, data loss prevention events, and behavioral indicators that may signal malicious or negligent actions. The successful candidate will work closely with Cyber Threat Intelligence, Security Operations, Incident Response, Data Protection, and Risk teams to strengthen the organization's ability to identify and respond to threats involving employees, contractors, and other trusted insiders. This individual will play a critical role in safeguarding sensitive information, intellectual property, and critical business assets from unauthorized disclosure, misuse, theft, fraud, sabotage, or compromise.

Responsibilities

  • Conduct proactive monitoring and analysis of insider threat indicators across multiple technologies and data sources.
  • Perform technical investigations involving potential insider threat activity, data exfiltration, policy violations, fraud, intellectual property theft, and unauthorized access to sensitive information.
  • Analyze user activity, network events, endpoint telemetry, data loss prevention alerts, and security logs to identify suspicious behavior and investigate anomalous activity.
  • Execute investigative requests and document findings, recommendations, and mitigation actions.
  • Partner with Cyber Security Incident Response team during complex investigations requiring advanced analysis and evidence collection.
  • Assist in defining and prioritizing Insider Threat Program objectives, roadmaps, and strategic initiatives.
  • Support the development and maturity of insider threat detection methodologies, monitoring use cases, and investigative procedures.
  • Identify opportunities to enhance existing capabilities through automation, analytics, behavioral monitoring, and emerging technologies.
  • Recommend improvements to tools, processes, and workflows to improve detection effectiveness and operational efficiency.
  • Contribute to the development of key performance indicators (KPIs), metrics, reporting, and program dashboards.
  • Develop and refine detection rules, correlation logic, and analytic use cases to identify insider risk activity.
  • Utilize trend analysis, behavioral analytics, anomaly detection, data mining, and user activity monitoring techniques to identify threats requiring further investigation.
  • Track, prioritize, and manage insider threat cases through resolution using established case management processes.
  • Collaborate with Human Resources, Legal, Compliance, Privacy, Risk Management, and Business stakeholders when appropriate.
  • Support the development and delivery of Insider Threat awareness campaigns and security education initiatives.
  • Assist with preparing presentations, reports, and executive-level summaries regarding insider threat program effectiveness, risks, and emerging trends.
  • Foster strong relationships with internal and external partners to support investigative efforts and information sharing.

Required Qualifications

  • Bachelor's degree in Cyber Security, Computer Science, Information Systems, Criminal Justice, or a related field, or an equivalent combination of education and experience.
  • 5+ years of experience in Cyber Security, Incident Response, Security Operations, Digital Forensics, Threat Detection, or Information Security disciplines.
  • Minimum 2 years of direct experience supporting an Insider Threat, Insider Risk, Data Protection, or User Activity Monitoring program.
  • Hands-on experience with Data Loss Prevention (DLP) technologies such as Microsoft Purview and Netskope DLP, or similar platforms.
  • Experience managing investigations and security incidents using case management tools such as Resilient, ServiceNow, or equivalent platforms.
  • Understanding of cyber investigation methodologies, chain of custody principles, and evidence handling.
  • Strong analytical and problem-solving skills with the ability to identify meaningful patterns within large data sets.
  • Ability to communicate effectively with both technical and non-technical stakeholders.

Preferred Qualifications

  • Experience supporting a mature enterprise Insider Threat or Insider Risk Management program.
  • Hands-on experience with Microsoft Purview Insider Risk Management, Microsoft Defender, Exabeam, ObserveIT, DTEX, Proofpoint, Forcepoint, or other insider threat platforms.
  • Experience with SIEM technologies such as Splunk, CrowdStrike, or equivalent.
  • Strong understanding of user and entity behavior analytics (UEBA).
  • Experience conducting cloud security investigations across Microsoft 365 and Azure environments.
  • Knowledge of legal, privacy, human resources, and regulatory considerations associated with insider threat investigations.
  • Experience working within a Security Operations Center (SOC) environment.
  • Experience supporting global organizations and cross-functional teams across multiple time zones.

Certifications (One or More Preferred)

  • ISACA Audit
  • Security+
  • GSEC (GIAC Security Essentials)
  • GCIH (GIAC Certified Incident Handler)

Preferred Certifications

  • CISSP (Certified Information Systems Security Professional)
  • GCFA (GIAC Certified Forensic Analyst)
  • GCTI (GIAC Cyber Threat Intelligence)
  • Insider Threat Program Manager (ITPM) or equivalent insider threat certification
  • Microsoft Security certifications focused on Purview, Defender, or Sentinel

Key Competencies

  • Investigative mindset with strong attention to detail
  • Critical thinking and analytical problem-solving
  • Ability to handle sensitive and confidential matters with discretion
  • Strong verbal and written communication skills
  • Collaboration and stakeholder management
  • Sound judgment and risk-based decision making
  • Continuous learning and passion for cybersecurity

Success Measures

  • Reduction in investigation response times.
  • Improvement in insider threat detection coverage and effectiveness.
  • Increased automation and operational efficiency within the Insider Threat Program.
  • Timely completion of investigations and reporting deliverables.
  • Growth in security awareness and insider threat education across the organization.
  • Measurable advancement of Insider Threat Program maturity and strategic objectives.
This response is AI-generated, for reference only.

Similar jobs

Insider Threat Analyst

SpaceXHawthorne, CA· 1 mo ago
Information Technology$85k–$100k/yrapply on boards.greenhouse.io