Source Job

US

  • Build and scale a world-class insider threat program, including detection logic and automation.
  • Collaborate with cross-functional teams including HR, Legal, and Engineering to investigate and mitigate insider risks.
  • Participate in on-call rotation and proactively hunt for threats across corporate and production environments.

Python SQL AWS DLP

20 jobs similar to Senior Security Engineer, Insider Threat

Jobs ranked by similarity.

$132,000–$238,000/yr
US

  • Lead the design, implementation, and continuous improvement of Insider Threat and DLP programs.
  • Monitor and investigate DLP technologies across endpoints, network, cloud, and email systems.
  • Conduct root cause analysis and recommend remediation actions to prevent future risk.

Target is a leading American retailer offering value, innovation, and an exceptional guest experience. It is a large corporation with a commitment to community support and ethical business practices.

$159,800–$235,000/yr
US Unlimited PTO 16w maternity 16w paternity

  • Conduct hands-on detection engineering for custom alerting, integrating threat intelligence and building agentic tooling.
  • Work with structured and unstructured telemetry to produce meaningful security signals across cloud, endpoints, and marketplace.
  • Collaborate with cross-functional teams and mentor engineers to improve detection capabilities and maintain standards.

DoorDash is a technology and logistics company that enables door-to-door delivery, empowering local economies. We grow rapidly and constantly change, with a diverse and inclusive team committed to supporting employees' happiness and well-being.

US

  • Design, build, and operate high-signal detections across endpoint, identity, cloud, and SaaS environments.
  • Implement and tune detection content across SIEM/XDR/EDR and cloud telemetry using detections-as-code with CI/CD and version control.
  • Proactively hunt for threats, operationalize threat intelligence, and contribute to incident response and automation efforts.

LinkedIn is the world's largest professional network, built to create economic opportunity for every member of the global workforce. They aspire to create a culture built on trust, care, inclusion, and fun where everyone can succeed.

US

  • Perform investigations of security incidents using digital forensics and data analytics.
  • Apply coding, data analytics, and investigative skills to hunt, detect, and respond to threats.
  • Build automation and detection models to identify anomalous activity and support response efforts at scale.

Maleda Tech is a technology staffing and consulting firm that provides security engineering services. They are hiring for a contract role supporting a major technology organization.

US

  • Define and drive LinkedIn's detection strategy across endpoint, identity, cloud, and SaaS environments.
  • Architect and operate high-signal detection capabilities using detections-as-code, telemetry modeling, and data-driven effectiveness measures.
  • Provide technical leadership, mentor engineers, and drive strategic investments to improve detection fidelity, scalability, and operational efficiency.

We are the world's largest professional network, built to create economic opportunity for every member of the global workforce. We're committed to providing transformational opportunities for our own employees by investing in their growth, cultivating a culture built on trust, care, inclusion, and fun.

Canada

  • Develop processes, tooling and automation to scale incident management response and mitigate risks.
  • Collaborate with security, engineering, product, support, and business operations to identify detection use cases.
  • Maintain security logging platform and stay updated on threats to improve detection mechanisms.

ClickHouse is a leading real-time analytics, data warehousing, observability, and AI workloads company with over 4,000 customers and rapid growth, validated by a $400M Series D funding round. The company values innovation and collaboration, offering a remote-friendly culture with a global team.

$190,000–$220,000/yr
US Unlimited PTO 12w maternity 12w paternity

  • Write, tune, and maintain detections in a modern SIEM across cloud, container, and SaaS log sources.
  • Run cloud security operations in AWS, triage alerts, and help execute incident-response playbooks.
  • Build and extend security-automation tooling with code fluency in Python or TypeScript.

SmarterDx uses clinical AI to help health systems capture the full value of patient care. They are a remote-first team with a mission to make healthcare more accurate and sustainable.

Mexico

  • Lead cybersecurity investigations across cloud, endpoint, identity, SaaS, email, and network environments.
  • Partner with Engineering, Infrastructure, Fraud, Legal, Communications, and Product teams to manage incidents and communicate risk.
  • Support continuous improvement through automation, AI-assisted security workflows, and detection tuning.

Oportun is a mission-driven financial services company that empowers members with intelligent borrowing, savings, and budgeting capabilities. Since inception, it has provided over $21.3 billion in responsible credit and fosters a diverse, equitable, and inclusive culture.

Argentina

  • Own end-to-end security incident response, from triage to recovery, and drive post-incident learnings.
  • Build and improve detection coverage across cloud, endpoint, identity, and SaaS systems.
  • Develop security automation and workflows to reduce manual toil and improve response speed.

Front is the customer operations platform for B2B complexity, keeping teams, tools, and conversations in sync. Over 9,000 companies rely on Front, and it's backed by Sequoia Capital and Salesforce Ventures, with a highly recognized workplace culture.

$128,130–$235,287/yr
US 12w maternity 12w paternity

  • Lead DLP incident response, including investigation, containment, and remediation.
  • Deploy and tune DLP controls across endpoints, network, and cloud.
  • Develop DLP policies and automated playbooks.

Included Health is a healthcare company that delivers integrated virtual care and navigation. They have a remote-first culture and offer comprehensive benefits.

$170,000–$240,000/yr
US Unlimited PTO

  • Design, build, and maintain static and dynamic file analysis pipelines processing artifacts at scale.
  • Operate and extend threat indicator enrichment systems for real-time file metadata extraction.
  • Build and maintain threat graph intelligence systems modeling relationships between indicators and actors.

Censys provides real-time Internet intelligence and threat insights to global governments and over 50% of the Fortune 500. They are a growing, research-driven company focused on building comprehensive maps of the internet with a collaborative culture.

$159,800–$235,000/yr
US Unlimited PTO 16w maternity 16w paternity

  • Own multi-terabyte-per-day log pipelines across AWS and GCP, including ingest, enrichment, schema management, and cost control.
  • Model security data and tune query performance in Snowflake, BigQuery, and Redshift for detection engineering.
  • Build automation, AI agents, and infrastructure as code to support cyber defense and incident response.

DoorDash is a technology and logistics company that connects consumers, merchants, and Dashers through its delivery network. It is a large, rapidly growing company with a culture of empowerment and inclusion, committed to supporting employee well-being.

$70,000–$100,000/yr
US Unlimited PTO

  • Monitor SIEM, EDR/XDR, and other security platforms for threats and respond to incidents.
  • Engineer and maintain SIEM integrations, detection rules, and security automation.
  • Collaborate with IT, Engineering, and Product teams to embed security into systems.

Portugal 4w PTO

  • Lead and mentor the Detection Engineering & Automation team, driving delivery and professional growth.
  • Own the full detection lifecycle, from use-case design to implementation, optimization, and retirement.
  • Develop SIEM/EDR rules, detection-as-code pipelines, and SOAR automation playbooks to reduce alert fatigue.

This role is listed on behalf of a partner company, which manages all applications and next steps. The company is a remote-first organization focused on building advanced cyber defense capabilities, with a collaborative culture and a proactive security program.

$123,850–$161,000/yr
US

  • Monitor, detect, and respond to security events across enterprise environments using the SIEM.
  • Build and maintain dashboards, visualizations, and KPIs that demonstrate SIEM effectiveness and security visibility.
  • Use frameworks such as MITRE ATT&CK to contextualize detections and identify coverage gaps.

Horizon3.ai is a fast-growing, remote cybersecurity company that provides production-safe autonomous pentests through its NodeZero platform to organizations of all sizes. We are a fusion of former U.S. Special Operations cyber operators and startup engineers, committed to a culture of respect, collaboration, ownership, and results.

Global

  • Design and implement security controls across applications, cloud infrastructure, and development environments.
  • Conduct architecture reviews, threat modeling, and security assessments for new products.
  • Identify, prioritize, and remediate vulnerabilities across the technology stack.

SignalFire partners with top early-stage startups that are shaping the future of technology. They have a portfolio of over 200 innovative companies across AI, cybersecurity, healthtech, fintech, developer tools, and enterprise SaaS.

EMEA

  • Own insider risk investigations from triage through closure, including case timelines and escalation.
  • Mature the Insider Risk Management Program and DLP capabilities across environments.
  • Partner with People, Legal, Compliance, and IT on sensitive cases involving data misuse and departures.

Alpaca is a global leader in agent-first brokerage infrastructure for stocks, ETFs, options, crypto, and more. With over 400 employees worldwide, we foster a diverse, remote-first culture centered on curiosity, empathy, and accountability.

Asia

  • Design, develop, and maintain security automation and SOC tooling, including integrations with SIEM, EDR, cloud services, and internal security platforms.
  • Participate in security detection engineering, including log parsing, data normalization, and detection logic implementation.
  • Assist in security incident response, including triage, investigation, containment, eradication, and post-incident analysis.

Binance is a leading global blockchain ecosystem behind the world's largest cryptocurrency exchange by trading volume and registered users. We are trusted by 300+ million users in 100+ countries with a focus on security and innovation.

Germany

  • Lead threat modeling and security reviews across Wiz's products and cloud infrastructure, identifying attack surfaces and developing scalable mitigation strategies.
  • Build automation, policy-as-code, and security tooling to enable development teams to shift left and integrate security into workflows.
  • Design and implement secure baselines for cloud resources and Kubernetes-based infrastructure, and drive vulnerability management efforts.

Wiz is a cloud security company enabling teams to secure cloud and AI applications by connecting code, cloud, and runtime. As one of the fastest-growing startups, trusted by over 65% of the Fortune 100, Wiz values world-class talent and creativity.

Costa Rica

  • Analyze EDR telemetry, alerts, and log sources across Endpoint, Identity, Network, and Cloud/SaaS domains.
  • Publish and review threats for customers using concisely written communication to convey key indicators and remediation context.
  • Improve and innovate Detection Operations workflows through orchestration and automation to manage high volumes of telemetry.

Zscaler accelerates digital transformation to make customers more agile, efficient, resilient, and secure. They are an AI-forward enterprise using the world's largest security data lake, with a culture of execution centered on customer obsession, collaboration, and accountability.