Security Engineer
Job Title: Junior Security Engineer – Insider Risk ProgramLocation: RemotePosition Type: Full-TimeAbout the RoleWe are seeking a detail-oriented Junior Security Engineer to support the engineering and continuous improvement of our Insider Risk Program (IRP). In this role, you will focus on investigating potential risks, developing insider risk use cases, creating and maintaining detection rules, and testing security telemetry across our enterprise security platforms.You will work closely with security data sources to understand how logs are generated, ingested, parsed, and correlated within our SIEM. By translating business requirements, investigation trends, emerging threats, and monitoring gaps into practical detection mechanisms, you will help protect our organization against sensitive data exposure and insider threats across the full lifecycle of detection engineering.Key ResponsibilitiesAlert Monitoring & Investigation: Monitor and investigate daily Insider Risk alerts to identify potential threats or policy violations.Detection Engineering & Optimization: Perform gap analysis on existing detections, proactively fine-tuning rules to reduce false positives, address coverage gaps, and automate workflows where possible.Use Case Development: Research and develop new Insider Risk use cases driven by emerging threats, investigation feedback, and changing business requirements.Data Modeling & Analytics: Utilize data modeling, processing, and transformations to enhance scan and inventory results, generating actionable metrics, dashboards, and executive reports. Implement configuration, development, scripting, and data analytics using internal tooling.Lifecycle Documentation: Maintain clear, comprehensive documentation for all investigation workflows, detection logic, configurations, and tuning activities.Stakeholder Collaboration: Build strong working relationships with IT Engineering, Security Operations, and cross-functional teams to remediate identified risks.Continuous Growth: Engage with industry experts to learn, explore, and adapt modern security best practices.Required Skills & QualificationsEducation: Bachelor’s degree in Information Technology, Cybersecurity, or a related field.Experience:1–2 years of experience in IT Security or general Information Technology.6 months to 1 year of hands-on experience operating within an enterprise-level SIEM environment.Core Technical Knowledge:Basic knowledge of endpoint, identity, network, cloud, email, and SaaS security concepts.Good understanding of Insider Risk principles, user-based security risks, data loss prevention (DLP), data exfiltration, and sensitive data exposure.Understanding of core SIEM fundamentals (log ingestion, parsing, normalization, enrichment, correlation, and alert generation).Skills:Strong analytical, troubleshooting, research, and problem-solving abilities.Proven capability to document technical workflows and present clear detection logic for SOC investigators.Demonstrated ability to collaborate with IT and business stakeholders to maintain production-quality log management and SIEM visualization reports.Preferred QualificationsExperience with industry-leading SIEM platforms such as Elastic, IBM QRadar, or ArcSight.Familiarity with enterprise security tools, including Microsoft Purview, CrowdStrike, Zscaler, Nightfall, Abstract Security, ServiceNow, AWS, Microsoft 365, Okta / Entra ID.Awareness of or exposure to Generative AI (GenAI) security monitoring.