Basic Qualifications:Must possess and maintain at least one active certification: Security+ or ISC2 CISSP (or other comparable certification approved in advance by the SOC PM).Bachelor's degree in Computer Science, Information Security, or a related field, OR a minimum of two (2) years of dedicated experience in insider threat detection, APT mitigation, and User Activity Monitoring (e.g., Teramind).2+ years of experience with SPLUNK architecture (indexer, forwarder, search heads, etc.), including UI/GUI development and operational roles. Responsibilities:Independently run daily operations, proactively identifying and triaging indicators of malicious, negligent, or coerced insider risk across multiple telemetry sources (DLP, SIEM, EDR/NDR, UAM, IAM).Conduct end-to-end, self-directed risk scoring and categorization of user activity.