Source Job

US

  • Design and implement scalable detection logic to identify insider threats and data exfiltration across corporate and production environments.
  • Conduct proactive threat hunting and incident response, collaborating with HR, Legal, and engineering teams during complex investigations.
  • Develop automation and detection models using Python and SQL to strengthen security response capabilities and reduce risk exposure.

Python SQL AWS DLP

20 jobs similar to Senior Security Engineer, Insider Threat

Jobs ranked by similarity.

US

  • Build and scale a world-class insider threat program, including detection logic and automation.
  • Collaborate with cross-functional teams including HR, Legal, and Engineering to investigate and mitigate insider risks.
  • Participate in on-call rotation and proactively hunt for threats across corporate and production environments.

Maleda Tech is a technology consulting firm specializing in security and threat detection. They operate as a fast-paced team supporting major organizations, with a focus on building and scaling insider threat programs.

US

  • Perform investigations of security incidents using digital forensics and data analytics.
  • Apply coding, data analytics, and investigative skills to hunt, detect, and respond to threats.
  • Build automation and detection models to identify anomalous activity and support response efforts at scale.

Maleda Tech is a technology staffing and consulting firm that provides security engineering services. They are hiring for a contract role supporting a major technology organization.

$159,800–$235,000/yr
US Unlimited PTO 16w maternity 16w paternity

  • Conduct hands-on detection engineering for custom alerting, integrating threat intelligence and building agentic tooling.
  • Work with structured and unstructured telemetry to produce meaningful security signals across cloud, endpoints, and marketplace.
  • Collaborate with cross-functional teams and mentor engineers to improve detection capabilities and maintain standards.

DoorDash is a technology and logistics company that enables door-to-door delivery, empowering local economies. We grow rapidly and constantly change, with a diverse and inclusive team committed to supporting employees' happiness and well-being.

$132,000–$238,000/yr
US

  • Lead the design, implementation, and continuous improvement of Insider Threat and DLP programs.
  • Monitor and investigate DLP technologies across endpoints, network, cloud, and email systems.
  • Conduct root cause analysis and recommend remediation actions to prevent future risk.

Target is a leading American retailer offering value, innovation, and an exceptional guest experience. It is a large corporation with a commitment to community support and ethical business practices.

Australia

  • Design and optimize threat detection capabilities using SIEM, SOAR, EDR, and NDR technologies.
  • Develop automation playbooks and cybersecurity data solutions to improve detection accuracy.
  • Collaborate with customer teams to close detection gaps and adapt defenses to emerging threats.

Our partner is a cybersecurity firm focused on building threat detection capabilities for enterprise environments. They foster a collaborative, engineering-led culture with significant autonomy for engineers.

US

  • Design, build, and operate high-signal detections across endpoint, identity, cloud, and SaaS environments.
  • Implement and tune detection content across SIEM/XDR/EDR and cloud telemetry using detections-as-code with CI/CD and version control.
  • Proactively hunt for threats, operationalize threat intelligence, and contribute to incident response and automation efforts.

LinkedIn is the world's largest professional network, built to create economic opportunity for every member of the global workforce. They aspire to create a culture built on trust, care, inclusion, and fun where everyone can succeed.

$190,000–$220,000/yr
US Unlimited PTO 12w maternity 12w paternity

  • Write, tune, and maintain detections in a modern SIEM across cloud, container, and SaaS log sources.
  • Run cloud security operations in AWS, triage alerts, and help execute incident-response playbooks.
  • Build and extend security-automation tooling with code fluency in Python or TypeScript.

SmarterDx uses clinical AI to help health systems capture the full value of patient care. They are a remote-first team with a mission to make healthcare more accurate and sustainable.

$125,000–$180,000/yr
US

  • Define and execute the strategic roadmap for AI-driven security services, threat intelligence, and security automation.
  • Design AI-powered security architectures spanning detection, investigation, response, remediation, and managed service workflows.
  • Build intelligent threat intelligence and research platforms capable of collecting, correlating, enriching, and analyzing information from diverse sources.

Our partner is a company focused on transforming cybersecurity through AI, automation, and intelligent security operations. They offer a work environment with opportunity to work on challenging, high-impact AI and cybersecurity initiatives alongside experienced professionals.

$128,130–$235,287/yr
US 12w maternity 12w paternity

  • Lead DLP incident response, including investigation, containment, and remediation.
  • Deploy and tune DLP controls across endpoints, network, and cloud.
  • Develop DLP policies and automated playbooks.

Included Health is a healthcare company that delivers integrated virtual care and navigation. They have a remote-first culture and offer comprehensive benefits.

$172,279–$249,640/yr
United States Canada

  • Build and maintain SIEM infrastructure and detection systems to identify malicious behavior across corporate and production environments.
  • Investigate security incidents end-to-end, including malware analysis and timeline reconstruction, and develop runbooks for scalable response.
  • Partner with IT to enforce security standards on employee devices and drive implementation of Zero-Trust VPN and other corporate security controls.

Quora operates two platforms: Quora, a global knowledge sharing platform, and Poe, a platform for chatting with AI language models. The company fosters a culture of transparency, idea-sharing, and collaboration among its global teams.

US Unlimited PTO

  • Design, develop, and maintain secure cloud environments for distributed LogRhythm deployments.
  • Act as a technical escalation point for SIEM engineers, solving complex security and infrastructure issues.
  • Build automation and operational tooling using PowerShell, SQL, Bash, or Python.

The company specializes in cybersecurity and managed SIEM services, focusing on protecting and scaling distributed LogRhythm environments. They offer a remote work environment with a collaborative culture and opportunities for professional growth.

$70,000–$100,000/yr
US Unlimited PTO

  • Monitor SIEM, EDR/XDR, and other security platforms for threats and respond to incidents.
  • Engineer and maintain SIEM integrations, detection rules, and security automation.
  • Collaborate with IT, Engineering, and Product teams to embed security into systems.

US

  • Define and drive LinkedIn's detection strategy across endpoint, identity, cloud, and SaaS environments.
  • Architect and operate high-signal detection capabilities using detections-as-code, telemetry modeling, and data-driven effectiveness measures.
  • Provide technical leadership, mentor engineers, and drive strategic investments to improve detection fidelity, scalability, and operational efficiency.

We are the world's largest professional network, built to create economic opportunity for every member of the global workforce. We're committed to providing transformational opportunities for our own employees by investing in their growth, cultivating a culture built on trust, care, inclusion, and fun.

Portugal 4w PTO

  • Lead and mentor the Detection Engineering & Automation team, driving delivery and professional growth.
  • Own the full detection lifecycle, from use-case design to implementation, optimization, and retirement.
  • Develop SIEM/EDR rules, detection-as-code pipelines, and SOAR automation playbooks to reduce alert fatigue.

This role is listed on behalf of a partner company, which manages all applications and next steps. The company is a remote-first organization focused on building advanced cyber defense capabilities, with a collaborative culture and a proactive security program.

Canada

  • Develop processes, tooling and automation to scale incident management response and mitigate risks.
  • Collaborate with security, engineering, product, support, and business operations to identify detection use cases.
  • Maintain security logging platform and stay updated on threats to improve detection mechanisms.

ClickHouse is a leading real-time analytics, data warehousing, observability, and AI workloads company with over 4,000 customers and rapid growth, validated by a $400M Series D funding round. The company values innovation and collaboration, offering a remote-friendly culture with a global team.

$199,750–$235,000/yr
US

  • Design, build, and operate event-driven services for real-time pentest data processing.
  • Solve distributed systems challenges at scale, including data migration and batch-to-streaming conversion.
  • Set high standards for operational excellence with SLOs, instrumentation, and on-call.

Horizon3 is a remote cybersecurity company that enables organizations to find, fix, and verify exploitable attack vectors using its NodeZero autonomous pentesting platform. The company is a fusion of former US Special Operations cyber operators and engineers, fostering a culture of respect, collaboration, and ownership.

US

  • Execute day-to-day implementation, monitoring, and optimization of cybersecurity systems and data pipelines.
  • Support log onboarding, normalization, and validation, as well as detection engineering and SIEM platform operations.
  • Assist in client engagements, security architecture reviews, and automation of response workflows.

GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. The company has over 1,300 employees and maintains a culture of collaboration and mentorship.

Mexico

  • Lead cybersecurity investigations across cloud, endpoint, identity, SaaS, email, and network environments.
  • Partner with Engineering, Infrastructure, Fraud, Legal, Communications, and Product teams to manage incidents and communicate risk.
  • Support continuous improvement through automation, AI-assisted security workflows, and detection tuning.

Oportun is a mission-driven financial services company that empowers members with intelligent borrowing, savings, and budgeting capabilities. Since inception, it has provided over $21.3 billion in responsible credit and fosters a diverse, equitable, and inclusive culture.

$125,560–$173,010/yr
Canada Unlimited PTO

  • Lead and develop a team of security engineers to defend infrastructure, SaaS, and endpoints against real-world adversaries.
  • Own detection and response, including incident command, tuning CrowdStrike, and conducting cybersecurity risk assessments.
  • Drive AI security strategy and partner with cross-functional teams to build robust detection controls.

Forward Financing is a financial technology company that unlocks capital to fuel small businesses across America. Since 2012, they have provided over $4.8 billion in funding to more than 92,000 small businesses and are recognized as a Best Place to Work with a culture focused on empowerment and collaboration.

$145,000–$160,000/yr
US

  • Design, implement, and maintain enterprise security solutions to strengthen cybersecurity defenses and support Zero Trust maturity.
  • Operate and manage security technologies including EDR, SIEM, web application firewalls, and vulnerability scanners.
  • Integrate security requirements into DevSecOps processes, CI/CD pipelines, and infrastructure-as-code environments.

The partner company specializes in enterprise cybersecurity and strengthening security capabilities. They have a collaborative, security-focused team and offer fully remote work.