Haystack
← Back to Jobs
Other
MI

Insider Threat Investigators

MindlanceUnited States🇺🇸United StatesPosted Sep 21, 2026

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
United States
Posted
1 week ago
SalesforceSplunkCase ManagementComplianceTriage

Job Description

Description:

Bachelor Degree: (Required, Preferred or Not Required)

  • Preferred.

Role Responsibilities: (what they will be doing)

  • Support the Client’s Enterprise Insider Threat program (EInT) as a senior analyst focused on insider threat and information security alerting, triage, escalation, and investigation.
  • Perform end-to-end investigations of insider-driven and employee-related information security events.
  • Triage, analyze, investigate, escalate, and document insider threat and information security alerts generated from enterprise security tools.
  • Act as an escalation point for alerts originating from XSOAR, Data Loss Prevention (DLP), and insider threat monitoring platforms.
  • Assess alerts for risk severity, potential insider intent, data exposure, and regulatory impact.
  • Conduct investigations involving:
  • Employee-driven data loss or exfiltration
  • Unauthorized access to systems or sensitive information
  • Suspicious employee activity and potential insider threat events
  • Correlate signals across endpoint, identity, network, email, browser, and collaboration data sources to establish investigative findings.
  • Collect, analyze, and preserve digital evidence while maintaining appropriate chain-of-custody and evidence-handling standards.
  • Prepare clear, audit-defensible investigative summaries documenting findings, conclusions, and recommended actions.
  • Coordinate investigative outcomes with Insider Threat leadership, Human Resources, Legal, Compliance, and Corporate Investigations.
  • Support continuous 24/7 Insider Threat operations, including structured shift handoffs and escalation of high-risk activity.
  • Utilize Salesforce for engineering, development, testing, case management, and investigation-related activities as required.

Must Have Skills/Prior Experiences: (Vendor should not submit any candidate that does not have these skills/prior experience.)

  • 7+ years of experience in one or more of the following:
  • Insider threat investigations
  • Information security/cybersecurity investigations
  • Financial crimes or corporate investigations
  • Security operations or incident response
  • Hands-on experience triaging and investigating security alerts using enterprise security platforms.

Strong working knowledge and investigative experience with:

  • XSOAR
  • Splunk
  • CrowdStrike
  • Anvilogic
  • Demonstrated ability to correlate multi-source security telemetry and convert findings into actionable investigative conclusions.
  • Experience working in a high-tempo investigative or security environment.
  • Experience conducting end-to-end investigations, including alert triage, evidence collection, analysis, escalation, documentation, and case disposition.
  • Understanding of appropriate evidence preservation, chain of custody, data integrity, access controls, retention, and legal-hold requirements.
  • Relevant industry certifications in cybersecurity, investigations, or interviewing techniques.

PlNice to Have Skills/Prior Experiences: (Hiring Manager DOES NOT require these skills/prior experience. However, candidates with any of these will be looked at first.)

  • College degree or equivalent education, training, or work-related experience.
  • Banking or financial services experience, particularly experience involving regulatory or audit requirements.
  • Experience working directly with Human Resources, Legal, Compliance, or Financial Crimes teams.
  • Experience with insider threat, UEBA, or advanced security analytics platforms.
  • Experience investigating potential data exfiltration/data loss across endpoints, browsers, cloud storage, email, and collaboration platforms.
  • Experience supporting enterprise-scale Insider Threat or Data Loss Prevention programs.
  • Experience with Salesforce in a security, case-management, engineering, or development environment.

EEO
“Mindlance is an Equal Opportunity Employer and does not discriminate in employment on the basis of – Minority/Gender/Disability/Religion/LGBTQI/Age/Veterans.”

Similar jobs