CrawlJobs Logo

Insider Risk Engineer – Cyber

softwareresources.com Logo

Software Resources

Location Icon

Location:
United States , Phoenix

Category Icon

Job Type Icon

Contract Type:
Employment contract

Salary Icon

Salary:

Not provided

Job Description:

Software Resources has an immediate, direct hire job opportunity for an Insider Risk Engineer – Cyber with a major corporation in Phoenix, AZ. 4 days per week on-site, Friday Remote. Our Insider Risk Program is a strategic initiative within the Security Risk & Compliance function, supporting the bank’s growth into a Large Financial Institution. It focuses on identifying, preventing, and mitigating risks to the bank and its customers that may arise from inadvertent or intentional actions by employees, contractors, or third parties.

Job Responsibility:

  • Manage and provide ownership of innovative threat detection, security audit, and logging solutions
  • Communicate, collaborate and justify cyber recommendations to a broad base of stakeholders
  • Be a key member of a multidisciplinary team that partners closely with Data Security, the Security Monitoring Center, Privacy, Legal, and HR
  • Manage the full stack (front end and back end) of applications utilized to help prevent, detect and respond to insider risk events of interest
  • Own the review and development of new processes and technologies to enhance the program’s ongoing maturity
  • Lead the continuous review and improvement of the defense, auditing, access standards, tactics, and techniques to meet regulatory guidelines
  • Own the resiliency of insider risk applications and platforms via routine disaster recovery exercises
  • Partner with vendors routinely to optimize insider risk products, as well as ensure costs/licenses do not exceed expectations, while maintaining capacity planning
  • Proactively identify and fix issues to improve backend service scalability, resiliency, and fault tolerance
  • Respond to insider risk events of interest in a timely manner alongside team members and key stakeholders
  • Respond to audit inquiries and ensure processes and procedures are within regulatory guidelines
  • Foster the highest level of engineering practices and follow relevant company procedures
  • Be held accountable for relevant documentation
  • Design and implement advanced detection logic to surface subtle behavioral anomalies indicative of insider risk across diverse data sources
  • Continuously refine and tune Insider Risk policies to reduce false positives and improve signal-to-noise ratio in alerting workflows
  • Engineer scalable data pipelines to ingest, normalize, and correlate identity, access, and activity data for risk modeling
  • Collaborate with security monitoring, threat intelligence and modeling teams to incorporate contextual enrichment and behavioral baselines into Insider Risk analytics
  • Prototype and evaluate emerging technologies (e.g., ML models, graph analytics) to enhance Insider Risk detection capabilities
  • Revisit Insider Risk tooling architecture design routinely with vendor and peers to either or all: minimize cost, optimize performance, scale, and meet new requirements

Requirements:

  • Insider risk experience
  • User Entity Behavior Analytics (UEBA)
  • Must be able to integrate API with the tool and build the API
  • Cyber Security experience and development expertise
  • C# .net, Python, API Development
  • CISSP CISM Desired but not required
  • No front End
  • More API Backend candidate
  • 6+ years of related experience in IT–Security, IT–App Support, IT–Development or similar field
  • Bachelor’s degree in related field required
  • Previous leadership experience preferred
  • Advanced knowledge of general Financial Services or Banking is preferred
  • Advanced to expert experience with and knowledge of Linux, Python, PowerShell, SIEM and Bash
  • Solid understanding of authentication protocols SAML, SSO, and LDAP
  • Solid understanding of concepts regarding SIEM, SOAR, Firewall, Proxies, SSL/TLS, Secure Mail Gateways, Application Firewalls, NAC, Vulnerability Scanners, and EDR
  • Advanced experience with logging infrastructure concepts: syslog
  • log parsing
  • log de-duping
  • methods for log pulling
  • RFC 5424
  • CEF Format
  • JSON
  • key value pair format
  • log enrichment
  • log maintenance
  • log troubleshooting
  • Solid understanding of load balancers, DNS, SMTP, etc. for troubleshooting application functionality
  • Advanced experience of NIST, MITRE and Administration of either or all of an IT Automation platform, SOAR, Firewall, IAM platform, SIEM, cloud cyber defense platform etc
  • Hands-on experience deploying and operating a User & Entity Behavioral Analytics (UEBA) platform in a mid-large sized corporation, preferably in Financial Services
  • Expertise building Application Program Interfaces (APIs) from source systems of record to bring technical and non-technical indicators into the UEBA
  • Intermediate – Advanced ability to query and extract data from security monitoring systems (e.g., SIEM, EDR, NDR, etc.) for performing Insider Risk analysis
  • Experience correlating UEBA signals with identity, access, and data movement logs to detect anomalous behavior
  • Familiarity with government and industry best practice frameworks for managing Insider Risk (e.g., Carnegie Mellon, SIFMA, MITRE, NIST, etc.)
  • Ability to translate behavioral indicators into risk scoring models and escalation thresholds
  • Experience working cross-functionally with Legal, HR, and Compliance teams to investigate and respond to Insider Risk cases
  • Advanced speaking and writing communication skills

Nice to have:

  • CISSP CISM Desired but not required
  • Previous leadership experience preferred
  • Advanced knowledge of general Financial Services or Banking is preferred
  • Hands-on experience deploying and operating a User & Entity Behavioral Analytics (UEBA) platform in a mid-large sized corporation, preferably in Financial Services
What we offer:
  • Competitive salaries
  • An ownership stake in the company
  • Medical and dental insurance
  • Time off
  • A great 401k matching program
  • Tuition assistance program
  • An employee volunteer program
  • A wellness program

Additional Information:

Job Posted:
January 01, 2026

Employment Type:
Fulltime
Work Type:
On-site work
Job Link Share:

Looking for more opportunities? Search for other job offers that match your skills and interests.

Briefcase Icon

Similar Jobs for Insider Risk Engineer – Cyber

Senior Cyber Security Engineer

Join a specialized team of analysts and engineers dedicated to detecting and res...
Location
Location
United States , Milwaukee
Salary
Salary:
Not provided
tier4group.com Logo
Tier4 Group
Expiration Date
December 31, 2026
Flip Icon
Requirements
Requirements
  • 5+ years of experience in enterprise security or platform engineering
  • Hands-on expertise with Microsoft E5 security stack (Purview DLP, Information Protection, eDiscovery)
  • Proven ability to build policy-as-code for DLP/labels and automate administration using Graph API and PowerShell
  • Experience designing secure-by-default guardrails for SaaS/AI adoption, including Copilot
Job Responsibility
Job Responsibility
  • Engineer Secure-by-Default E5 Data Protection
  • Build Policy-as-Code Pipelines
  • Integrate Security Telemetry
  • Develop Automations & Guardrails
  • Operate and Continuously Improve
  • Collaborate Across Teams
What we offer
What we offer
  • Competitive Rates
  • Benefits
  • free daily lunch when onsite
Read More
Arrow Right

Senior Detection Engineer

This is a detection engineering role that leverages knowledge of monitoring, ana...
Location
Location
Singapore , Singapore
Salary
Salary:
Not provided
https://www.marriott.com Logo
Marriott Bonvoy
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Bachelor’s degree in Computer Sciences or related field or equivalent experience/certification
  • 3+ years of collective experience in Splunk SIEM (Splunk Enterprise Security) threat detection use case development or UEBA (Exabeam) use case development for insider threat use case development
  • 5+ years of experience in security functions such as SOC, CIRT, security engineering, risk management, vulnerability management or technical infrastructure operations, administration, or systems engineering
  • scripting or programming language, including Python
  • Current information security certification such as Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP) preferred
  • offensive and defensive security certifications such as CEH, IGAC Cyber Defense, OSCP or other related certifications preferred
  • Splunk Certification, including Splunk Enterprise Security Certified Admin preferred
  • use case development experience on the Exabeam platform preferred
  • working knowledge of the NIST Cyber Security Framework and ISO/IEC 27001:2022 preferred
  • working knowledge of the MITRE ATT&CK Framework preferred
Job Responsibility
Job Responsibility
  • Lead collaboration sessions within the cyber security tower and other business units to devise security monitoring use cases
  • engage and collaborate with other security engineers and architects as needed to keep pace with the evolution of corporate infrastructure and applications and share that knowledge with peers as appropriate
  • document prospective security monitoring use cases with MITRE ATT&ACK mappings using standard templates and methodologies
  • inform and consult other cyber ops teams of required data onboarding and integrations for use case development
  • develop analytics, correlation searches, dashboards, reports and alerts within the SIEM and UEBA platforms
  • solicit feedback for pre-production security monitoring content through peer review process and user acceptance testing for tuning
  • document developed security monitoring content in a documentation registry using department standard templates and methodologies
  • manage field mapping and transmission of security monitoring alerts to the security incident response platform for SOC analyst consumption as outlined in process documentation
  • provide governance support for the content development function entailing content development standards compliance, change management approvals for SIEM or UEBA content, and lifecycle management of developed security monitoring content
  • service operational requests in queue such as analytics content performance tuning, filtering, search refinement, parsing issues
  • Fulltime
Read More
Arrow Right

Cyber Security Operations Analyst

Responsible for progressing cybersecurity operations, maintaining proactive thre...
Location
Location
United States , Bethesda
Salary
Salary:
Not provided
anavationllc.com Logo
AnaVation
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Active TS/SCI Clearance with CI Polygraph
  • 6-10 years of Cyber Security/Operations support OR Bachelor’s degree in Network Engineering, Computer Science or related technical field and 2-4 years of experience
  • DoD 8140 IAT Level II Certification (CCNA-Security, CySA+, CND, Security+)
  • Documenting network schemas and cyber operation tool solutions
  • Provide security posture, vulnerability, threat and risk situational awareness to support staff, leadership, workforce, stakeholder organizations and community
  • Halt or minimize cyber-attack and insider threat efforts or damage
  • Designing, modeling, and securing networks
  • Troubleshooting network issues and recommendation of network modifications to optimize performance while adhering to all relevant security policies
  • Knowledgeable on the use of different SIEM applications, its interfaces, and how to retrieve data from its database
  • Knowledgeable on log aggregation and event correlation of any SIEM
Job Responsibility
Job Responsibility
  • Progressing cybersecurity operations
  • Maintaining proactive threat detection capabilities
  • Conducting vulnerability scanning and risk assessment using security tools such as Assured Compliance Assessment Solution (ACAS), Host Based Security System (HBSS), and Security Information Event Management (SIEM)
  • Performing real-time monitoring and defense of the IT environment to ensure resilience against cyber threats and vulnerabilities
  • Responding to alerts from HBSS and SIEM systems by conducting analysis and taking appropriate responses
  • Managing IPS/IDS systems to detect and prevent unauthorized access and protect network and data integrity
What we offer
What we offer
  • Generous cost sharing for medical insurance for the employee and dependents
  • 100% company paid dental insurance for employees and dependents
  • 100% company paid long-term and short term disability insurance
  • 100% company paid vision insurance for employees and dependents
  • 401k plan with generous match and 100% immediate vesting
  • Competitive Pay
  • Generous paid leave and holiday package
  • Tuition and training reimbursement
  • Life and AD&D Insurance
  • Fulltime
Read More
Arrow Right

Network/System Administrator Expert

The Network/System Administrator is responsible for the configuration, managemen...
Location
Location
United States , Vandenberg SFB
Salary
Salary:
140000.00 - 160000.00 USD / Year
deltasands.com Logo
Delta Solutions & Strategies
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • TS/SCI Clearance Security Clearance
  • Minimum 7 or more years of progressively responsible experience managing network and system infrastructure in DoD or similar mission-critical environments
  • Master’s degree in Information Technology, Computer Science, or a related field, or an equivalent combination of education and experience
  • Must meet position and certification requirements outlined in DoD 8140 for the System Administrator or Network Operations Specialist role (Advanced Level) within six months of hire
Job Responsibility
Job Responsibility
  • Configure, manage, and troubleshoot routers, switches, firewalls, and load balancers across LAN, WAN, and data center environments
  • Implement and maintain routing protocols such as OSPF, EIGRP, and BGP to ensure secure, efficient, and redundant traffic flow across enterprise networks
  • Design and manage VLANs, trunking, link aggregation, and port security configurations to maintain segmentation, performance, and network resiliency
  • Manage and allocate IP address space, maintaining detailed documentation and ensuring efficient IP utilization across all networks
  • Monitor network performance and availability, proactively addressing bottlenecks, latency, and congestion using enterprise monitoring tools
  • Install, terminate, and troubleshoot facility and network cabling to ensure proper connectivity and signal integrity
  • Install, configure, and maintain physical and virtual servers, including operating system deployment, patch management, and resource optimization
  • Administer enterprise infrastructure services including Active Directory, DNS, DHCP, Group Policy, file/print services, and certificate authorities
  • Install, configure, and maintain Virtual Desktop Infrastructure (VDI) environments, managing profile persistence, resource pooling, and user access control policies
  • Perform system and data backups, restore operations, patching, and recovery testing to ensure operational continuity and data integrity
What we offer
What we offer
  • medical
  • dental
  • vision
  • life insurance
  • 401(k)
  • PTO
  • paid holidays
  • parental, military and jury duty paid leaves
  • Fulltime
Read More
Arrow Right

Network/System Administrator Specialist

Delta Solutions & Strategies is seeking a Network/System Administrator Specialis...
Location
Location
United States , Vandenberg SFB
Salary
Salary:
130000.00 - 150000.00 USD / Year
deltasands.com Logo
Delta Solutions & Strategies
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • TS/SCI Clearance
  • Minimum 4–6 years of related experience in enterprise network and system administration
  • Bachelor’s degree in Information Technology, Computer Science, or a related field, or an equivalent combination of education and experience
  • Must meet position and certification requirements outlined in DoD 8140 for the System Administrator or Network Operations Specialist role (Intermediate Level) within six months of hire
  • Will provide after-hours support as required to maintain operational readiness
  • Provide support for exercises, contingencies, and real-world operations
  • Demonstrated proficiency in enterprise monitoring tools, virtualization platforms (e.g., VMware, Hyper-V), and configuration management utilities
  • Strong knowledge of DoD network architectures, DISA standards, and enterprise-level troubleshooting procedures
Job Responsibility
Job Responsibility
  • Configure, manage, and troubleshoot routers, switches, firewalls, and load balancers across LAN, WAN, and data center environments
  • Implement and maintain routing protocols such as OSPF, EIGRP, and BGP to ensure secure, efficient, and redundant traffic flow across enterprise networks
  • Design and manage VLANs, trunking, link aggregation, and port security configurations to maintain segmentation, performance, and network resiliency
  • Manage and allocate IP address space, maintaining detailed documentation and ensuring efficient IP utilization across all networks
  • Monitor network performance and availability, proactively addressing bottlenecks, latency, and congestion using enterprise monitoring tools
  • Install, terminate, and troubleshoot facility and network cabling to ensure proper connectivity and signal integrity
  • Install, configure, and maintain physical and virtual servers, including operating system deployment, patch management, and resource optimization
  • Administer enterprise infrastructure services including Active Directory, DNS, DHCP, Group Policy, file/print services, and certificate authorities
  • Install, configure, and maintain Virtual Desktop Infrastructure (VDI) environments, managing profile persistence, resource pooling, and user access control policies
  • Perform system and data backups, restore operations, patching, and recovery testing to ensure operational continuity and data integrity
What we offer
What we offer
  • medical
  • dental
  • vision
  • life insurance
  • 401(k)
  • PTO
  • paid holidays
  • parental, military and jury duty paid leaves
  • Fulltime
Read More
Arrow Right

Senior Cybersecurity Engineer

As a Senior Cybersecurity Engineer, you will be at the forefront of driving secu...
Location
Location
United States , Bellevue; Overland Park; Frisco; Herndon
Salary
Salary:
103400.00 - 186400.00 USD / Year
https://www.t-mobile.com Logo
T-Mobile
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Bachelor's Degree Computer Science or Information Technology or equivalent work experience
  • 4-7 years Experience in info security technology or related field
  • Experience with incident handling for Security breaches
  • Expert in security subject areas
  • 2-4 years Technical Project Management
  • Experience with high level design architecture, security technologies, Networking, web services and SOA
  • Understanding of encryption, obfuscation, tokenization technologies
  • Medium to advance knowledge of Scripting tools (Python/Perl/Shell/HTML/PHP)
  • Knowledge of federal & compliance regulations e.g. SOX, PCI & CPNI
  • Familiarity with load balancers (ex – A10, F5), firewalls (ex – CheckPoint), Venafi, MDM (ex - Mobile Iron), Cloud (ex - AWS, Azure), Malware Protection (ex -FireEye), Advanced Persistent Threats (ex - Damballa), Privileged Accounts (ex – CyberArk), SIEM (ex – ArcSight), Log & Event (ex – Splunk), Intrusion IDS/IPS (ex – Symantec) , Cloud Platform (ex – PCF, Docker), Scanning (ex – Qualys), AppSec (ex - Veracode)
Job Responsibility
Job Responsibility
  • Leads security, compliance, and risk assessments on projects throughout project lifecycle
  • Improves process efficiency by creating and implementing creative and sustainable changes to existing deployment methodologies
  • Leads the identification of security needs & recommends plans/resolutions
  • Implements, tests & monitors info security improvements
  • Maintains transparency inside & outside of information security at the People management level
  • Communicate with groups such as application support, engineering ops, finance, privacy, risk management, etc
  • Leads information security policy lifecycle throughout, including intake, creation, review, approval, implementation, publishing, communication & maintenance
  • Implements security projects driven by groups both internal and external to info security
  • Mentors peers and junior team members in security technologies, enterprise solution design and facilitation and effective customer interaction
  • Experience with implementation of various threat modeling approaches pertaining to one or more of the following STRIDE, PASTA, TRIKE, ATTACK TREE, DREAD, KILL CHAIN, CAPEC, Mobile Application threat model, Cyber Threat Tree, and data flow diagram
What we offer
What we offer
  • Competitive base salary and compensation package
  • Annual stock grant
  • Employee stock purchase plan
  • 401(k)
  • Access to free, year-round money coaches
  • Medical, dental and vision insurance
  • Flexible spending account
  • Paid time off
  • Up to 12 paid holidays
  • Paid parental and family leave
  • Fulltime
Read More
Arrow Right

Head of Cloud Device Protection

The Head of Cloud Device Protection is responsible for developing and leading po...
Location
Location
Poland
Salary
Salary:
23300.00 - 34500.00 PLN / Month
https://www.hsbc.com Logo
HSBC
Expiration Date
February 16, 2026
Flip Icon
Requirements
Requirements
  • A background in information systems, technology, architecture, design, and service delivery of defense-in-depth capabilities
  • Strong stakeholder management skills, with experience of understanding and meeting the needs of multiple stakeholders
  • An ability to communicate complex and technical issues to diverse audiences, orally and in writing, in an easily understood, authoritative and actionable manner
  • Likely from a technology or engineering background with developed understanding of Technology Delivery Lifecycle, engineering practices, underlying infrastructure, tooling and architecture & design principles
  • Deep SME knowledge of containers
  • Experience working in a highly regulated, large multi-national environment
  • Ability to understand the potential business impact of security decisions and align initiatives with business needs
  • Strong inter-personal skills to work effectively with other areas inside and outside of cyber
Job Responsibility
Job Responsibility
  • Developing and leading policy and strategies to protect device and processes hosted in “Cloud” ecosystems (Cattle, Containers and Serverless etc) and that they are working in line with HSBC Cloud strategies
  • Ensuring that the right processes and escalations are in place and consistent across the different Cloud environments to ensure effective operation of capabilities
  • Implementation and oversight of the Group’s Risk Management Framework
  • Ongoing and targeted controls assessments
  • Implementing and maintaining robust risk governance
  • Championing a proactive risk culture
  • Maintaining positive relationships with our regulators and external partners
  • Managing relationships with key stakeholders with in the relevant Cloud Service Provider Teams within HSBC
  • Reviewing Coverage and Compliance across the Cloud Environments and Escalating as required
  • Collaborating with other Cloud related Security teams like Security Operations, Incident Management and Cloud Security to ensure joined up decisions are made
What we offer
What we offer
  • Additional car allowance in the amount of 4,620 PLN (monthly, gross)
  • Variable pay
  • Comprehensive and competitive package of benefits covering healthcare, family friendly leaves, pension and life assurance
  • Competitive salary
  • Annual performance-based bonus
  • Additional bonuses for recognition awards
  • Multisport card
  • Private medical care
  • Life insurance
  • One-time reimbursement of home office set-up (up to 800 PLN)
  • Fulltime
!
Read More
Arrow Right

Service Operations Specialist

To assure SITA's competitive strength and business growth through the provision ...
Location
Location
India , Bengaluru
Salary
Salary:
Not provided
sita.aero Logo
SITA
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Minimum 3 -5 years of proven experience in the network and/or application/system support domain, IT System Administrator and application support role, or in a similar infrastructure-focused role
  • Must have dealt directly with external customers delivering to SLAs
  • A background in hybrid IT environments (on-premises and cloud), with practical knowledge of virtualization platforms (e.g., VMware) and cloud services (e.g., AWS)
  • Strong hands-on experience in managing and troubleshooting servers, network infrastructure, enterprise applications, and client systems in complex IT environments
  • Experience in operation and maintenance of airport IT systems, networking and airline-specific applications is highly preferred
  • A background in Airport IATA standards, airline infrastructure/applications, SBD, E-Gates, and airport passenger/baggage (Pax/Bags) systems would be an added advantage
  • Proficiency in Windows and Linux server environments, including installation, configuration, and administration
  • Strong knowledge of networking concepts and protocols such as TCP/IP, DNS, DHCP, and VPN
  • Strong hardware knowledge such as server, router, switch etc.
  • Knowledge on web server such as Apache, Tomcat
Job Responsibility
Job Responsibility
  • Provide Service Operations support to internal and external customers in accordance with the terms of the customer contract and Service Level Agreements (SLAs)
  • Ensure the correct functioning and maintenance of all internal and external systems and products serviced by Service Operations
  • When required act as the customer SPOC and co-ordinate the scheduling of intervention with Customer's internal resolver groups and the Service Desk ensuring the highest level of customer services and communications are maintained to resolve the fault and incident within the prescribed SLA
  • Carry out incident and problem management support to the highest standards and co-ordinate the resolution with the appropriate resolver groups
  • Ensure shortest restoral times possible initiating the timely escalations to specialized resolver groups inside and outside SITA according to the customer contracts SLAs and monitoring requirements
  • To ensure the Service Operations team adheres to the highest working standards for all incidents and problems by providing guidance support and direct management
  • Proactively detect problems related to service and infrastructure operations and delivery services conduct diagnostics and provide service request ownership to ensure resolution of customer problems
  • Support the senior team members in the management reporting and co-ordination of day-day tasks during absence of the Lead Engineer
  • Adhere to installation guidelines and industry best practices in order to deliver quality service and infrastructure operations
  • Use the appropriate tools and equipment to perform the installation intervention and repairs in accordance with Service Operations and Delivery guidelines and instructions where provided
What we offer
What we offer
  • Flex Week: Work from home up to 2 days/week (depending on your team's needs)
  • Flex Day: Make your workday suit your life and plans
  • Flex-Location: Take up to 30 days a year to work from any location in the world
  • Employee Wellbeing: Employee Assistance Program (EAP), for you and your dependents 24/7, 365 days/year
  • Champion Health - a personalized platform that supports a range of wellbeing needs
  • Professional Development: Level up your skills with our training platforms, including LinkedIn Learning
  • Competitive Benefits: Competitive benefits that make sense with both your local market and employment status
  • Fulltime
Read More
Arrow Right