This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
The Engineer II, Insider Threat, is a mid-level technical role within the Cyber Defense organization responsible for monitoring, investigating, and responding to risks posed by malicious, negligent, or compromised insiders. This role conducts investigative analysis of user activity, escalates complex cases, and supports the development of detection and monitoring capabilities. The Engineer II will also play a key role in administering and tuning Data Loss Prevention (DLP) technologies, ensuring that sensitive data is safeguarded against unauthorized disclosure. The Engineer II will collaborate with Human Resources, Legal, Compliance, and Corporate Security on sensitive investigations and contribute to the continuous improvement of the insider threat program.
Job Responsibility:
Monitor and analyze user activity logs, alerts, and behavioral indicators to identify potential insider threats
Conduct investigations into moderate-complexity insider threat cases, including data misuse, exfiltration, fraud, and policy violations
Administer, monitor, and tune Data Loss Prevention (DLP) technologies to detect and prevent unauthorized movement of sensitive data
Investigate and respond to DLP alerts, escalating incidents when necessary with clear documentation and supporting evidence
Support the development and refinement of insider threat detection rules, analytics, and use cases
Contribute to the creation and improvement of playbooks and investigative workflows, including DLP-related scenarios
Collaborate with HR, Legal, and Corporate Security to ensure coordinated responses to insider incidents
Document findings and prepare clear reports for management and other stakeholders
Share knowledge with Engineer I analysts and contribute to team training efforts
Participate in awareness and deterrence initiatives by providing technical input to educational campaigns
Requirements:
Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Behavioral Science, or equivalent work experience
Knowledge of insider threat detection methodologies, user activity monitoring, DLP, and investigative practices
Familiarity with privacy, compliance, and employment standards (e.g., GDPR, HIPAA, SOX, CCPA)
3–5 years of progressive experience in cybersecurity, investigations, or risk management, with at least 1–2 years dedicated to insider threat or DLP operations
Hands-on experience with insider threat monitoring platforms, behavioral analytics, and DLP tools
Demonstrated ability to handle confidential investigations with discretion
Strong communication and writing skills for documenting findings and Briefing Stakeholders
Nice to have:
Certified Insider Threat Program Manager (CITPM) or Certified Insider Threat Vulnerability Assessor (CITVA)
GIAC Cyber Threat Intelligence (GCTI)
CompTIA Security+ or CySA+
Certified Ethical Hacker (CEH)
What we offer:
medical
dental
vision care
comprehensive suite of benefits focusing on physical, emotional, financial, and social wellness
support for working families
backup dependent care
adoption assistance
infertility coverage
family building support
behavioral health solutions
paid parental leave
paid caregiver leave
training programs
professional development resources
opportunities to participate in mentorship programs