Staff Insider Threat Engineer
At Early Warning, we’ve powered and protected the U.S. financial system for over thirty years with cutting-edge solutions like Zelle®, Paze℠, and so much more. As a trusted name in payments, we partner with thousands of institutions to increase access to financial services and protect transactions for hundreds of millions of consumers and small businesses.Positions located in Scottsdale, San Francisco, Chicago, or New York follow a hybrid work model to allow for a more collaborative working environment. Candidates responding to this posting must independently possess the eligibility to work in the United States, for any employer, at the date of hire. This position is ineligible for employment Visa sponsorship.Overall PurposeThe Staff Insider Threat Engineer is part of a high-performance team, responsible for detecting, identifying, mitigating, and responding to critical or urgent insider threat situations. The individual will work closely with CSIRT, HR, Legal, Privacy, and other teams to identify, triage, and respond to insider threats.Essential Functions Lead the deployment, configuration, and tuning of insider threat detection tools to ensure optimal performance and integration with existing security systems.Mature and improve the comprehensive insider threat program aligned with organizational goals and regulatory standards.Monitor user and entity behavior analytics to identify suspicious activities and policy violations.Performs detection and investigative analysis activities for a variety of digital devices, computers, storage media, servers, networks, and cloud-based servicesPerforms advanced host and network forensics and malware analysis; Investigates and responds to incidents; provides recommendations to improve company’s security posture. Escalates complex issues as needed.Performs the tracking of investigations and incidents through resolutionHelps analyze vulnerabilities from insider threat perspectives and escalate & remediate as neededUses data collected from a variety of cyber defense tools (e.g., DLP, IDS alerts, firewalls, network traffic logs) to analyze events that occur within their environments for the purposes of mitigating insider threats.Maintains awareness of trends in security, regulatory, technology, and operational requirements, includingMaintains awareness of current threat landscape, including adversary tactics, techniques, and procedures.Creates intellectual property such as procedural documentation and tools for automated analysis and correlation activitiesRepresents the Insider threat team at internal and external threat intelligence and cybersecurity forumsPerforms on-call activities when requiredEnsures the company's commitment to protect the integrity and confidentiality of systems and data.Minimum QualificationsEducation and/or experience typically obtained through completion of a Bachelor’s degree or 2 year degree in Computer Science, Engineering, Math or Physical Science or equivalent experienc...