Full-Time

Insider Threat Analyst

Posted on 1/30/2025

Charles Schwab

Charles Schwab

Mid

Lone Tree, CO, USA + 2 more

More locations: Westlake, TX, USA | Phoenix, AZ, USA

Hybrid position requiring 3 or more days in-office.

Category
Cybersecurity
IT & Security
Required Skills
PowerShell
Python
BigQuery
Data Analysis

You match the following Charles Schwab's candidate preferences

Employers are more likely to interview you if you match these preferences:

Degree
Experience
Requirements
  • Bachelor’s degree in cybersecurity, information technology, or a related field; advanced degree preferred.
  • Minimum of 3 years of experience in cybersecurity, with a focus on insider threat analysis.
  • Strong understanding of UEBA tools and technology, digital forensics, and data loss prevention (DLP) strategies.
  • Experience with analytical problem solving and familiar with conducting investigations.
  • Experience developing policies, procedures, and workflows for insider threat management.
  • Familiarity with SIEM platforms, data analytics tools, and insider threat indicators and detection methods.
  • Experience with scripting and automation (e.g., BigQuery, Python, PowerShell) is a plus.
Responsibilities
  • Monitor user and entity behavior analytics to identify suspicious activities and policy violations.
  • Conduct in-depth investigations into insider threat incidents, working closely with cybersecurity, HR, and legal teams.
  • Decipher underlying trends or uncover anomalies and discern obscure patterns and attributes.
  • Refine detection capabilities by creating and optimizing rules, alerts, and risk scoring models.
  • Support the investigation and resolution of insider threat incidents, ensuring thorough documentation and root-cause analysis.
  • Execute response playbooks for various insider threat scenarios and assist in developing and maintaining additional playbooks/runbooks as needed.
  • Contribute to the development of policies, processes, and workflows for detecting, investigating, and mitigating insider threats.
  • Recommend metrics and reporting enhancements to measure the effectiveness of the program.
  • Participate in the configuration of a new insider threat detection tool.
  • Ensure seamless integration with existing security systems, such as SIEM and SOAR solutions.
  • Collaborate with vendors and IT teams to customize the tool for organization-specific use cases.
Desired Qualifications
  • Relevant certifications such as CISSP, CISM, CISA, GIAC, or insider threat-specific credentials (e.g., Certified Insider Threat Program Manager).
  • Knowledge of legal and regulatory requirements surrounding insider threat and data protection (e.g., GDPR, CCPA, etc.).

Company Stage

N/A

Total Funding

N/A

Headquarters

N/A

Founded

N/A