Insider Threat Analyst

Charles Schwab Inc.Omaha, NE
$64,000 - $70,000Hybrid

About The Position

Schwab is expanding its Insider Threat Operations Team. This role supports and analyzes threat detection for the Cybersecurity Defense Insider Threat program. The analyst will work with a team to identify and develop new processes and techniques for analyzing information to detect risks and gaps in people, processes, and technology. The role involves utilizing an understanding of Insider Threat principles to identify trends and patterns for developing new detection rules and models. The position offers a hybrid/flexible schedule, requiring 4 or more days in the office per week, with flexibility for one day outside the office.

Requirements

  • Discreet, thoughtful, and able to coordinate systemic, cross-functional solutions to mitigate risk.
  • Adept at translating complex problems into readily implemented (and preferably automated) solutions.
  • Familiarity with Insider Threat technologies (SIEM, UEBA, EDR, DLP).
  • Understanding of investigations and/or the intelligence cycle.
  • Understanding of computer networking concepts, communication protocols, primary threat actor attack methods and tools.
  • Competent in collecting, analyzing, and interpreting qualitative and quantitative data from multiple sources.
  • Ability to understand and learn technical specifications, system requirements and other application design information.
  • Detail-oriented with a passion for quality and enthusiasm for innovative technology offerings.
  • Strong verbal and written communication skills, comfortable composing briefs and assessments for leadership.
  • Familiar with analytical programming languages such as SQL.
  • Ability to thrive in ambiguity and rapid change.
  • Comfortable with process flow diagrams.
  • Familiar with applying Agile Methods.
  • Basic understanding of a variety of security and compliance policies and incident response processes.
  • Experience monitoring and analyzing Data Loss Prevention (DLP) and Database Activity Monitoring (DAM) incidents.
  • Ability to exercise sound judgment when determining which events require follow-up response or escalation.
  • Comfortable working with internal customers to respond to escalations.
  • Maintaining incident documentation, analyzing incident trends.
  • Experience maintaining and generating audit evidence for internal and external regulatory compliance.
  • Ability to function as a technical conduit between IT and the business.

Nice To Haves

  • 4 - 7 years related experience including developing requirements, designing, and executing test cases in insider threat and data loss prevention.

Responsibilities

  • Support and analyze threat detection for the Cybersecurity Defense Insider Threat program.
  • Identify and develop new processes and techniques to analyze information for detecting risks and gaps in people, processes, and technology.
  • Utilize understanding of Insider Threat principles to identify trends and patterns for developing new detection rules and models.
  • Collect, analyze, and interpret qualitative and quantitative data from multiple sources.
  • Document results and analyze findings to provide viable threat intelligence.
  • Monitor and analyze Data Loss Prevention (DLP) and Database Activity Monitoring (DAM) incidents to ensure compliance with company policies.
  • Exercise sound judgment when determining which events require follow-up response or escalation.
  • Respond to escalations from internal customers.
  • Maintain incident documentation and analyze incident trends.
  • Maintain and generate audit evidence for internal and external regulatory compliance.
  • Function as a technical conduit between IT and the business.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service