Quick Overview
Job Description
Position: Senior Insider Threat Analyst
Location: Remote
Duration: 3+ month contract; Potential for extension or full-time conversion
Overview:
Our client in the banking industry is seeking a Senior Insider Threat Analyst who will report into the Head of Cyber Security Operations and serves as a key contributor in the development, implementation, and operation of the organization's Insider Threat Program. This role is responsible for helping deter, detect, investigate, and mitigate insider threats through the monitoring of user activity, data loss prevention events, and behavioral indicators that may signal malicious or negligent actions.
The successful candidate will work closely with Cyber Threat Intelligence, Security Operations, Incident Response, Data Protection, and Risk teams to strengthen the organization's ability to identify and respond to threats involving employees, contractors, and other trusted insiders. This individual will play a critical role in safeguarding sensitive information, intellectual property, and critical business assets from unauthorized disclosure, misuse, theft, fraud, sabotage, or compromise.
Insider Threat Operations & Investigations
Conduct proactive monitoring and analysis of insider threat indicators across multiple technologies and data sources.
Perform technical investigations involving potential insider threat activity, data exfiltration, policy violations, fraud, intellectual property theft, and unauthorized access to sensitive information.
Analyze user activity, network events, endpoint telemetry, data loss prevention alerts, and security logs to identify suspicious behavior and investigate anomalous activity.
Execute investigative requests and document findings, recommendations, and mitigation actions.
Partner with Cyber Security Incident Response team during complex investigations requiring advanced analysis and evidence collection.
Program Development & Continuous Improvement
Assist in defining and prioritizing Insider Threat Program objectives, roadmaps, and strategic initiatives.
Support the development and maturity of insider threat detection methodologies, monitoring use cases, and investigative procedures.
Identify opportunities to enhance existing capabilities through automation, analytics, behavioral monitoring, and emerging technologies.
Recommend improvements to tools, processes, and workflows to improve detection effectiveness and operational efficiency.
Contribute to the development of key performance indicators (KPIs), metrics, reporting, and program dashboards.
Monitoring & Detection
Develop and refine detection rules, correlation logic, and analytic use cases to identify insider risk activity.
Utilize trend analysis, behavioral analytics, anomaly detection, data mining, and user activity monitoring techniques to identify threats requiring further investigation.
Track, prioritize, and manage insider threat cases through resolution using established case management processes.
Stakeholder Engagement & Awareness
Collaborate with Human Resources, Legal, Compliance, Privacy, Risk Management, and Business stakeholders when appropriate.
Support the development and delivery of Insider Threat awareness campaigns and security education initiatives.
Assist with preparing presentations, reports, and executive-level summaries regarding insider threat program effectiveness, risks, and emerging trends.
Foster strong relationships with internal and external partners to support investigative efforts and information sharing.
Required Qualifications
Bachelor's degree in Cyber Security, Computer Science, Information Systems, Criminal Justice, or a related field, or an equivalent combination of education and experience.
5+ years of experience in Cyber Security, Incident Response, Security Operations, Digital Forensics, Threat Detection, or Information Security disciplines.
Minimum 2 years of direct experience supporting an Insider Threat, Insider Risk, Data Protection, or User Activity Monitoring program.
Hands-on experience with Data Loss Prevention (DLP) technologies such as Microsoft Purview and Netskope DLP, or similar platforms.
Experience managing investigations and security incidents using case management tools such as Resilient, ServiceNow, or equivalent platforms.
Understanding of cyber investigation methodologies, chain of custody principles, and evidence handling.
Strong analytical and problem-solving skills with the ability to identify meaningful patterns within large data sets.
Ability to communicate effectively with both technical and non-technical stakeholders.
Required Certifications (one or more preferred)
ISACA Audit
Security+
GSEC (GIAC Security Essentials)
GCIH (GIAC Certified Incident Handler)
Preferred Qualifications
Experience supporting a mature enterprise Insider Threat or Insider Risk Management program.
Hands-on experience with Microsoft Purview Insider Risk Management, Microsoft Defender, Exabeam, ObserveIT, DTEX, Proofpoint, Forcepoint, or other insider threat platforms.
Experience with SIEM technologies such as Splunk, CrowdStrike, or equivalent.
Strong understanding of user and entity behavior analytics (UEBA).
Experience conducting cloud security investigations across Microsoft 365 and Azure environments.
Knowledge of legal, privacy, human resources, and regulatory considerations associated with insider threat investigations.
Experience working within a Security Operations Center (SOC) environment.
Experience supporting global organizations and cross-functional teams across multiple time zones.
Preferred Certifications
CISSP (Certified Information Systems Security Professional)
GCFA (GIAC Certified Forensic Analyst)
GCTI (GIAC Cyber Threat Intelligence)
Insider Threat Program Manager (ITPM) or equivalent insider threat certification
Microsoft Security certifications focused on Purview, Defender, or Sentinel
Key Competencies
Investigative mindset with strong attention to detail
Critical thinking and analytical problem-solving
Ability to handle sensitive and confidential matters with discretion
Strong verbal and written communication skills
Collaboration and stakeholder management
Sound judgment and risk-based decision making
Continuous learning and passion for cybersecurity
Success Measures
Reduction in investigation response times.
Improvement in insider threat detection coverage and effectiveness.
Increased automation and operational efficiency within the Insider Threat Program.
Timely completion of investigations and reporting deliverables.
Growth in security awareness and insider threat education across the organization.
Measurable advancement of Insider Threat Program maturity and strategic objectives.
Similar jobs
- BA
Digital Network Exploitation Analyst
NewBooz Allen Hamilton
Fort Meade, MD🇺🇸$99k - $225k/yrOn-site23 hours agoEncryptionC++Penetration Testing+1Technology - CR
Application Security Engineer / Security Engineer
NewCode Repo
Charlotte, NC🇺🇸Hybrid23 hours agoAWSOWASPSOC 2+13Technology - GS
Cybersecurity Engineer
NewGlobal Sumi Technologies Inc
Richmond, VA🇺🇸Hybrid23 hours agoSplunkTechnology - VC
Cyber Security Analyst III-
NewV-Soft Consulting Group, Inc
New York, NY🇺🇸Hybrid23 hours agoAgileAzureTechnology - 4C
Information Security Analysts
New4 Consulting Inc
Princeton, TX🇺🇸On-site23 hours agoTechnology - PT
Network Security Engineer– L3
NewPrudent Technologies and Consulting
King of Prussia, PA🇺🇸On-site23 hours agoPrismaTechnology