Insider Threat Engineer

Cloudflare
Austin
Workplace: HybridFull timeFunction: Administration & Executive AssistanceSkills: ["Communication","Collaboration","Investigation"]

Lead Cloudflare’s Insider Threat program within the Security Threat Detection, Response and Emulation team. Drive digital investigations into insider incidents, conduct proactive threat hunting using SIEM/DLP/EDR/UEBA data, and improve detections and responses by building new alerts, rules, and playbooks. Partner closely with Privacy, Legal, GRC, and HR to ensure investigations are handled with care and in compliance with legal and ethical standards.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Cloudflare
Cloudflare
1 month ago

Insider Threat Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 2 hours agoStatus: Live

Job Summary

Lead Cloudflare’s Insider Threat program within the Security Threat Detection, Response and Emulation team. Drive digital investigations into insider incidents, conduct proactive threat hunting using SIEM/DLP/EDR/UEBA data, and improve detections and responses by building new alerts, rules, and playbooks. Partner closely with Privacy, Legal, GRC, and HR to ensure investigations are handled with care and in compliance with legal and ethical standards.
Location: Austin
Workplace: Hybrid
Employment Type: Full time
Job Function: Administration & Executive Assistance
Seniority: Sr. Manager level

Key Responsibilities

  • •Lead insider threat digital investigations, including data exfiltration, intellectual property theft, unauthorized access, and other malicious activities.
  • •Collect, preserve, and analyze digital evidence from endpoints, network logs, cloud services, and email; document findings clearly and defensibly.
  • •Proactively hunt for insider threats using SIEM, DLP, EDR, and UEBA data; develop hunting hypotheses and identify anomalous user behavior.
  • •Collaborate with the Security Incident Response Team and Threat Detection teams to enhance insider threat detections and responses.
  • •Develop detection rules, alerts, use cases, and response playbooks; serve as the primary technical liaison with Legal, HR, and Privacy.

Key Requirements

  • •5+ years in a technical security role, including at least 2+ years focused on insider threat, digital forensics, or security investigations.
  • •Proven experience leading complex technical investigations using forensic tools such as EnCase, FTK, X-Ways, or open-source alternatives.
  • •Deep understanding of security technologies including SIEM (Splunk, Elastic), EDR (CrowdStrike, SentinelOne), and UEBA data sources.
  • •Strong scripting/programming skills (Python, PowerShell) to automate tasks and analyze large datasets.
  • •Excellent communication skills for presenting findings to senior leadership and collaborating with Legal and HR on sensitive matters.
Experience:Digital forensicsInsider threatSecurity investigations
Skills:CommunicationCollaborationInvestigation
Certifications:GCIHGCFAGCTI
Languages:English
Tech Stack:SIEMSplunkElasticEDRCrowdStrikeSentinelOneUEBADLPEnCaseFTKX-WaysPythonPowerShellAWSGCPAzureSIRT

Company Brief

Cloudflare
Provides a global network and cloud platform that delivers security, performance, and reliability services for web applications, APIs, and Internet properties, including CDN, DDoS protection, DNS, and zero-trust security solutions.
Industry: Cybersecurity
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: San Francisco, United States
Founded: 2009
WebsiteLinkedIn