We are seeking an experienced Insider Threat Analyst to join our Cybersecurity team. The ideal candidate will have a strong background in Identity & Access Management (IAM) along with hands-on experience detecting, investigating, and mitigating insider threat activities. This role requires an analytical mindset, familiarity with user behavior analytics, and the ability to collaborate with IT security and compliance teams.
Responsibilities
- Monitor and analyze user activities across systems to identify indicators of insider threats, misuse, or anomalous behavior.
- Perform investigations on potential insider threat incidents and document findings.
- Collaborate with Cybersecurity, IAM, HR, and Legal teams during investigations.
- Support development and enhancement of the Insider Threat Program, including policies, procedures, and use cases.
- Use tools such as SIEM, UEBA, DLP, and IAM platforms to detect threats and enforce controls.
- Conduct risk assessments and recommend control improvements.
- Assist with IAM security activities, including access reviews, role-based access control, MFA enforcement, and SSO operations.
- Work with Identity & Access tools such as SailPoint, Active Directory, and CyberArk to monitor and maintain secure access.
- Prepare reports on insider threat trends and present findings to management.
- Maintain awareness of emerging insider threat methodologies, tools, and compliance requirements.
Required Qualifications
Minimum 3+ years of experience in Insider Threat, Cybersecurity, IAM, SOC, or IT Security roles.Strong understanding of IAM concepts : SSO, RBAC, Identity Federation, MFA, provisioning, and access governance.Experience with IAM tools : SailPoint, Active Directory, CyberArk , or equivalent.Hands-on experience with SIEM / UEBA platforms (Splunk, Exabeam, Microsoft Sentinel, etc.).Knowledge of DLP technologies and incident response processes.Ability to analyze user behavior logs and correlate events across multiple systems.Strong written / verbal communication and ability to work cross-functionally.Preferred Skills
Experience supporting an enterprise Insider Threat Program.Background in forensics, threat Client, or behavioral analytics.Experience working in regulated industries (Finance).Certifications such as Security+, CySA+, CEH, SSCP, or similar.