Staff Insider Risk Engineer
Job description
About the role
The is a pivotal role focused on the proactive identification, analysis, and mitigation of potential threats originating from within the organization. You will own the technical and procedural frameworks designed to protect the integrity of financial operations and sensitive data. This position requires a deep partnership with cross-functional departments to build a cohesive and security-aware organizational culture. You will architect and deploy strategic solutions that address the nuanced challenges of insider risk. The role demands a high level of autonomy and ownership over complex security initiatives. You will be responsible for translating evolving threat landscapes into actionable defense strategies. Collaboration with engineering, finance, and compliance teams is central to ensuring that security measures are seamlessly integrated into business processes. Ultimately, you will safeguard the company's assets and reputation against malicious or accidental internal actions.
Key facts
What you'll do
- Perform comprehensive threat modeling and behavioral analysis to uncover subtle indicators of potential insider risk within financial systems and user activities.
- Architect and deploy advanced monitoring strategies utilizing data from endpoints, applications, and network flows to establish baselines and detect anomalies.
- Design and implement automated response playbooks that mitigate identified risks in real-time while minimizing disruption to legitimate business operations.
- Lead in-depth investigations into suspicious activities, correlating evidence from disparate sources to determine the scope and intent of potential violations.
- Develop and maintain detailed incident documentation and forensic reports that provide clear narratives for technical and executive stakeholders.
- Evaluate and integrate emerging security technologies and methodologies to enhance the organization's insider risk posture and detection capabilities.
- Partner with Human Resources and Legal teams to ensure all investigations and remediation efforts adhere to organizational policies and regulatory standards.
- Provide expert consultation and training to department leaders on risk assessment practices and the importance of security hygiene.
- Conduct red team exercises specifically tailored to test the resilience of internal controls against credential compromise and data exfiltration attempts.
- Establish metrics and key risk indicators (KRIs) to quantitatively measure the effectiveness of implemented security controls over time.
- Liaise with external auditors and regulators to provide transparent reporting on the state of insider risk management within the organization.
- Continuously refine security policies and procedures based on lessons learned from investigations, audits, and changes in the threat environment.
Requirements
- Possess a minimum of 5 years of cumulative professional experience specifically in information security, risk management, or a closely related field.
- Hold a Bachelor's degree from an accredited institution in Computer Science, Information Technology, or a relevant discipline that provides a strong technical foundation.
- Demonstrate a thorough and current understanding of established insider threat frameworks, such as those from CERT, and formal risk assessment methodologies.
- Exhibit proven proficiency in the deployment, configuration, and administration of security information and event management (SIEM) solutions.
- Show advanced competence in the implementation and management of data loss prevention (DLP) technologies to monitor and control data transfers.
- Maintain excellent analytical capabilities to dissect complex problems, identify root causes, and formulate logical and effective solutions.
- Utilize exceptional communication skills to articulate technical risks and remediation plans to both technical engineering teams and non-technical business leaders.
- Confirm eligibility to work in the United States and maintain authorization to access systems that handle sensitive financial data.
Nice to have
- Attain industry-recognized certifications such as Certified Information Systems Security Professional (CISSP) or Certified Information Security Manager (CISM) to validate expertise.
- Bring direct experience working within the financial services sector, understanding the unique regulatory and operational pressures of the industry.
- Show familiarity with specific regulatory requirements related to data protection, privacy laws, and financial compliance standards like PCI DSS or SOX.
Practical notes
This position is open to candidates who are authorized to work in the United States. We offer a competitive salary and benefits package, including health insurance, retirement plans, and professional development opportunities. Interested applicants should submit their resume and cover letter by [insert application deadline].
About the company
An American company operates from San Jose, California. Focus centers on automated software for financial tasks aimed at United States small businesses. The cloud based system handles operations. Financial institutions receive a white labeled, full payments automation platform called Bill.com Connect. This platform integrates into online banking systems that offer single sign on access. Company serves clients through this ecosystem.