Insider Risk Security Engineer

CloudWalk Inc
      24 days ago

      Job Description

      We're hiring a hands-on Insider Risk Security Engineer to build, tune, and operate our insider threat program. This is not a ticket-triage or compliance-report role. You'll be in the trenches analyzing user behavior, tuning detection engines, reconstructing timelines across our entire stack, and writing the automation that makes investigations faster, deeper, and more consistent.

      You'll act as the technical engine of our team, bridging security operations, detection engineering, and automation - while partnering discreetly with Legal, People, and IT to protect our most critical data from accidental exposure and malicious exfiltration. One day you're reconstructing a user's timeline across five platforms to determine if a data exfiltration happened. Next, you're writing a detection rule in YARA-L to catch that class of behavior going forward, or shipping a tool that automates the triage you just did manually.

      What You'll Do

      • Build & Tune Detections: Design, implement, and fine-tune rules across Chronicle (YARA-L), Wiz, and SentinelOne, plus our DLP and UEBA surfaces. Move beyond out-of-the-box alerts, actively cut false positives, and own the detection lifecycle from rule creation to retirement.
      • Investigate & Triage: Act as the primary technical investigator for insider risk alerts. Analyze logs, reconstruct user timelines across our entire stack, and determine what happened, why, and what to do about it - including intent behind data movement.
      • Reduce the Noise: Continuously tune alerts and detection logic to drive down false positives and keep the signal high.
      • Automate Workflows: Write code (TypeScript) to automate repetitive triage tasks and integrate our insider risk tools with our SIEM and SOAR platforms. If you repeat a triage step twice, automate it.
      • Weaponize AI for Investigations: Build and tune LLM-powered agents that triage alerts, enrich them with cross-platform context, and reconstruct investigation timelines automatically. Turn repetitive forensic work into autonomous workflows.
      • Cross-Functional Operations: Partner directly with Legal, People, and other Security teams to safely and discreetly conduct forensic investigations and coordinate remediation efforts.
      • Threat Hunting: Proactively hunt for undetected anomalous behavior, unauthorized shadow IT usage, or risky data handling practices across endpoints and cloud environments.

      What You Need to Succeed

      • Hands-on Experience in a Security Operations Center (SOC), Cyber Threat Intelligence, Incident Response, Security Engineering, or dedicated Insider Threat role.
      • Investigative & Analytical Mindset: You know how to differentiate between a malicious data exfiltration event and an engineer who just doesn't understand the company's cloud storage policy.
      • Technical Chops: Deep, practical experience querying raw logs, writing detection rules, and understanding the data pipeline behind them - you don't just read dashboards, you go to the source.
      • Stack Familiarity (or ability to ramp fast): Google Workspace (Admin SDK, Reports API), Chronicle / Google SecOps (UDM Search, YARA-L), Wiz, SentinelOne (Deep Visibility), Jumpcloud, Tailscale, GCP Audit Logs and IAM. DLP/UEBA tools (e.g., Microsoft Purview, Proofpoint, Forcepoint, Varonis, Exabeam) and SIEM platforms (e.g., Splunk, Sentinel, CrowdStrike LogScale).
      • Scripting Skills: Proficiency in TypeScript (Python/bash a plus). You write tools and services others can rely on, not just one-off scripts.
      • Discretion & Ethics: Unwavering integrity and the ability to handle highly sensitive, confidential personnel investigations with strict adherence to privacy laws and company guidelines.
      • Communication: The ability to translate complex technical forensic findings into clear, non-technical summaries for People and Legal teams.

      Nice to Have

      • Experience with insider threat detection, User and Entity Behavior Analytics, or building insider risk workflows.
      • Familiarity with fintech / payment industry security (PCI DSS, card data, Pix, acquiring flows).
      • Experience with LLM-powered security agents or AI-driven detection / triage automation.
      • Kubernetes / Istio service mesh context.

      The Future We See:

      At CloudWalk, we envision a future where AI empowers every field to reach new heights:

      • People teams leveraging AI to transform talent acquisition and employee development.
      • Marketing professionals creating data-driven, AI-powered campaign strategies.
      • Customer Success teams enhancing client experiences with intelligent solutions.
      • Risk analysts combining human expertise with AI to navigate complexities.
      • Designers collaborating with AI to push creative boundaries.

      Join us at CloudWalk, where we're not just engineering solutions; we're building a smarter, AI-driven future for payments-together.

      By applying for this position, your data will be processed as per CloudWalk's Privacy Policy that you can read here in Portuguese and here in English.

      We use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, assessing responses, and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

      submit your application

      Full name *

      Email *

      Phone *

      Current location *

      Current company

      Links

      LinkedIn URL *

      Resume/CV URL

      Portfolio URL (If you are Designer)

      GitHub URL

      Other URL

      Cloudwalk | Introductory Questions 01

      What exceptional work have you done? Tell us about a piece of work you are most proud of *

      What's the most exciting tech you've recently learned? *

      What AI tools have you used and how have they improved your productivity? *

      What level of English do you have? *

      Beginner

      Intermediate

      Advanced

      Fluent

      What level of Portuguese do you have? *

      Beginner

      Intermediate

      Advanced

      Fluent

      By applying for this position, your data will be processed as per CloudWalk's Privacy Policy that you can read here in Portuguese and here in English. *

      Cloudwalk is not responsible for visa issuance or legalization in the candidate's country of residence. It is the candidate's responsibility to comply with the legislation in their country. Please, confirm that you read it. *

      Thank you! Your submission has been received!

      Oops! Something went wrong while submitting the form.

      Numbers & Facts

      Location

      Skills

      • Analysis Skillsunmatched
      • Application Programming Interface (API)unmatched
      • Artificial Intelligence (AI)unmatched
      • Artificial Intelligence (AI) Agentsunmatched
      • Automationunmatched
      • Bash Scriptingunmatched
      • Campaignsunmatched
      • Cloud Computingunmatched
      • Cloud Storageunmatched
      • Computer Programmingunmatched
      • Computer Securityunmatched
      • Corporate Lawunmatched
      • Cross-Functionalunmatched
      • Customer Experienceunmatched
      • Customer/Consumer Behaviorunmatched
      • Data Managementunmatched
      • Editingunmatched
      • English Languageunmatched
      • GCP (Good Clinical Practices)unmatched
      • Huntingunmatched
      • Incident Responseunmatched
      • Internet Securityunmatched
      • Legalunmatched
      • Marketingunmatched
      • Microsoft FASTunmatched
      • Microsoft Product Familyunmatched
      • Multiplatform/Cross-Platformunmatched
      • PCI-DSSunmatched
      • Privacy Regulationsunmatched
      • Productivity Managementunmatched
      • Python Programming/Scripting Languageunmatched
      • Regulatory Complianceunmatched
      • Reporting Dashboardsunmatched
      • Riskunmatched
      • Risk Analysisunmatched
      • Security Attacksunmatched
      • Security Information and Event Management (SIEM)unmatched
      • Splunkunmatched
      • Staff Developmentunmatched

      Be found by employers

      5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

      Level up your application

      Professional resume templates

      Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

      Free resume templates

      Free resume builder

      Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

      Free resume builder