M
Information Security Consultant/Insider Threat Investigator
Mindlance
🇺🇸 United States
On-site
Manager or above
2 weeks ago
- triage
- DLP
- Salesforce
- Incident Response
- Splunk
- CrowdStrike
2 weeks ago
Bachelor Degree: (Required, Preferred or Not Required)
- Preferred.
Role Responsibilities: (what they will be doing)
- Support the Client’s Enterprise Insider Threat program (EInT) as a senior analyst focused on insider threat and information security alerting, triage, escalation, and investigation.
- Perform end-to-end investigations of insider-driven and employee-related information security events.
- Triage, analyze, investigate, escalate, and document insider threat and information security alerts generated from enterprise security tools.
- Act as an escalation point for alerts originating from XSOAR, Data Loss Prevention (DLP), and insider threat monitoring platforms.
- Assess alerts for risk severity, potential insider intent, data exposure, and regulatory impact.
- Conduct investigations involving:
- Employee-driven data loss or exfiltration
- Unauthorized access to systems or sensitive information
- Suspicious employee activity and potential insider threat events
- Correlate signals across endpoint, identity, network, email, browser, and collaboration data sources to establish investigative findings.
- Collect, analyze, and preserve digital evidence while maintaining appropriate chain-of-custody and evidence-handling standards.
- Prepare clear, audit-defensible investigative summaries documenting findings, conclusions, and recommended actions.
- Coordinate investigative outcomes with Insider Threat leadership, Human Resources, Legal, Compliance, and Corporate Investigations.
- Support continuous 24/7 Insider Threat operations, including structured shift handoffs and escalation of high-risk activity.
- Utilize Salesforce for engineering, development, testing, case management, and investigation-related activities as required.
Must Have Skills/Prior Experiences: (Vendor should not submit any candidate that does not have these skills/prior experience.)
7+ years of experience in one or more of the following:
- Insider threat investigations
- Information security/cybersecurity investigations
- Financial crimes or corporate investigations
- Security operations or incident response
- Hands-on experience triaging and investigating security alerts using enterprise security platforms.
Strong working knowledge and investigative experience with:
- XSOAR
- Splunk
- CrowdStrike
- Anvilogic
- Demonstrated ability to correlate multi-source security telemetry and convert findings into actionable investigative conclusions.
- Experience working in a high-tempo investigative or security environment.
- Experience conducting end-to-end investigations, including alert triage, evidence collection, analysis, escalation, documentation, and case disposition.
- Understanding of appropriate evidence preservation, chain of custody, data integrity, access controls, retention, and legal-hold requirements.
- Relevant industry certifications in cybersecurity, investigations, or interviewing techniques.
Plus/Nice to Have Skills/Prior Experiences: (Hiring Manager DOES NOT require these skills/prior experience. However candidates with any of these will be looked at first.)
- College degree or equivalent education, training, or work-related experience.
- Banking or financial services experience, particularly experience involving regulatory or audit requirements.
- Experience working directly with Human Resources, Legal, Compliance, or Financial Crimes teams.
- Experience with insider threat, UEBA, or advanced security analytics platforms.
- Experience investigating potential data exfiltration/data loss across endpoints, browsers, cloud storage, email, and collaboration platforms.
- Experience supporting enterprise-scale Insider Threat or Data Loss Prevention programs.
- Experience with Salesforce in a security, case-management, engineering, or development environment.
EEO
“Mindlance is an Equal Opportunity Employer and does not discriminate in employment on the basis of – Minority/Gender/Disability/Religion/LGBTQI/Age/Veterans.”
Information Security Consultant/Insider Threat Investigator · Mindlance