
Insider Risk Investigator
- London
- Permanent
- Full-time
- Analyze and interpret data from both technical and non-technical sources to detect, assess, and respond to insider risk and data loss incidents.
- Lead and conduct thorough security investigations by developing strategies, interviewing relevant parties, collaborating with cross-functional teams, and producing objective, well-documented case summaries.
- Create and maintain executive-level documentation, including standard operating procedures (SOPs), playbooks, process flows, and risk reports, using diverse tools and data sources.
- Develop, refine, and maintain insider threat indicators and use case scenarios to enhance detection capabilities.
- Design and deliver insider risk awareness initiatives, highlighting emerging trends and fostering a culture of security, accountability, and vigilance.
- Identify and implement improvements to detection and response processes based on lessons learned and evolving threat landscapes.
- Collaborate with internal partners on threat detection and response initiatives to strengthen organizational resilience.
- Bachelor's degree in Information Security, Cybersecurity, Computer Science, or a related field; advanced degree preferred.
- Experience in insider risk, counterintelligence, cybersecurity, or a related discipline.
- Hands-on experience with insider threat detection tools such as SIEM, UEBA, UAM, DLP, and other monitoring technologies.
- Strong understanding of insider risk frameworks, regulatory and privacy requirements, and relevant laws.
- Familiarity with SOC or Fusion Centre operations, including threat monitoring, intrusion detection, incident response, and analysis.
- In-depth knowledge of the cyber threat landscape, including adversary tactics, campaigns, and the intersection of insider and external threats.
- Demonstrated ability to analyze anomalies, conduct link analysis, and assess enterprise-level risks.
- Effective communicator capable of translating complex technical data into actionable insights for non-technical stakeholders.
- Proven problem-solving skills, with a detail-oriented, process-driven mindset focused on efficiency, automation, and continuous improvement.
- Strong documentation skills and experience working in cross-functional teams (e.g., HR, Legal, Risk).
- Relevant certifications preferred: ITPM, GCITP, PMP, CISSP, GCIH, SANS, GIAC