# Insider Threat Engineer

**Company**: Cloudflare
**Location**: Austin
**Work arrangement**: hybrid
**Experience**: senior
**Job type**: full-time
**Category**: Engineering
**Industry**: Technology

**Apply**: https://job-boards.greenhouse.io/cloudflare/jobs/8064055?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply
**Canonical**: https://yubhub.co/jobs/job_9d515b80-1de

## Description

We are seeking a highly skilled and experienced Insider Threat Tech Lead to join our dynamic and growing Security Threat Detection, Response and Emulation team. This is a critical role that will be at the forefront of protecting our company from malicious and negligent insider activities.

You will be responsible for leading the technical aspects of our Insider Threat program, including investigations, threat hunting, and the development of cutting-edge detections and responses. This role requires a unique blend of technical expertise, regulatory and legal knowledge, investigative skills, and strong interpersonal communication.

**Responsibilities:**

- Lead Insider Threat Digital Investigations:

Conduct comprehensive technical investigations individually and partnering with our incident response teams into potential insider threat incidents, including data exfiltration, intellectual property theft, unauthorized access, and other malicious activities.

- Knowledge and execution experience in collecting, preserving, and analyzing digital evidence from a variety of sources (e.g., endpoints, network logs, cloud services, email, etc.).

- Document all investigative steps and findings in a clear, concise, and defensible manner.

- Present findings to senior leadership and cross-functional partners (Legal, HR, Privacy) in a professional and objective manner.

- Ensuring regulatory, legal and privacy requirements are met through all

- Insider Threat Hunting:

Proactively hunt for insider threats using a variety of security tools and data sources (e.g., SIEM, DLP, EDR, UEBA).

- Develop and execute threat hunting hypotheses based on emerging threats, attack techniques, and an understanding of our company's unique environment.

- Correlate disparate data points to identify anomalous or suspicious user behaviors.

- Detection & Response Improvement:

Collaborate closely with the Security Incident Response Team (SIRT) and Threat Detection teams to continuously enhance our insider threat detection capabilities.

- Design, develop, and implement new rules, alerts, and use cases in our security tools to identify insider threat indicators.

- Evaluate and recommend new technologies and processes to mature our Insider Threat program.

- Develop and refine response playbooks for various insider threat scenarios.

- Cross-Functional Collaboration:

Serve as the primary technical liaison for the Insider Threat program, building strong, trusted relationships with Legal, HR, and Privacy teams.

- Work in lockstep with these teams to ensure that investigations are conducted with sensitivity, respect for employee privacy, and within legal and ethical guidelines.

- Provide technical expertise and guidance during policy development and incident response planning.

**Requirements:**

- 5+ years of experience in a technical security role, with at least 2+ years focused on insider threat, digital forensics, or security investigations.

- Proven experience in conducting and leading complex technical investigations, including the use of forensic tools (e.g., EnCase, FTK, X-Ways, or open-source alternatives).

- Deep understanding of security technologies such as SIEM (e.g., Splunk, Elastic), EDR (e.g., CrowdStrike, SentinelOne), and UEBA like data sources.

- Strong scripting and programming skills (e.g., Python, PowerShell) to automate tasks and analyze large datasets.

- Excellent communication skills, both written and verbal, with the ability to explain complex technical concepts to non-technical audiences.

- Experience working with legal and HR teams on sensitive employee-related matters.

## Skills

### Required
- SIEM
- EDR
- UEBA
- Python
- PowerShell
- Digital Forensics
- Insider Threat

### Nice to have
- GCIH
- GCFA
- GCTI
- AWS
- GCP
- Azure
- GDPR
- CCPA

---

Source: [Apply at job-boards.greenhouse.io](https://job-boards.greenhouse.io/cloudflare/jobs/8064055?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply)
