Insider Threat Engineering Support Lead

Citi•Irving, TX
•$125,760 - $188,640•Onsite

About The Position

Seeking an inquisitive, analytical, and hands-on Insider Threat Engineering Support Lead to join our Cybersecurity Operations & Engineering team. This role sits at the intersection of security engineering, data analytics, and behavioral threat hunting. Unlike traditional perimeter-focused cybersecurity roles, this position focuses on identifying, mitigating, and engineering detection controls around internal human-risk factors, anomalous behavioral patterns, and unauthorized data movement. The ideal candidate blends an investigative mindset with engineering acumen to design, tune, and operationalize high-fidelity detections, proactively hunt across massive enterprise telemetry datasets, and continuously enhance our insider threat mitigation posture.

Requirements

  • Strong understanding of core Cybersecurity and Insider Threat concepts, specifically the behavioral, access, and human-centric risk models that distinguish insider threats from external attacks.
  • 6+ years of experience constructing, tuning, and executing complex queries within SIEM, data lake, or log analytics platforms (e.g., Splunk, KQL/Sentinel, Elastic, SQL, Snowflake).
  • Demonstrated ability to perform proactive, hypothesis-based threat hunting to identify stealthy, anomalous, or policy-violating activity across enterprise log sources.
  • Exceptional attention to detail with the ability to navigate, sanitize, query, and troubleshoot high-volume, heterogeneous datasets.
  • Demonstrated capability to independently manage workload, prioritize high-impact initiatives, and deliver results with minimal supervision.
  • High natural curiosity and an "outside-the-box" analytical approach to solving ambiguous problems and tracing subtle anomalies.
  • Ability to view telemetry through both an investigator's analytical lens and a software/security engineer’s systems-building perspective.
  • Ability to articulate complex data findings and engineering designs clearly to technical peers and non-technical stakeholders alike.
  • Bachelor’s degree/University degree or equivalent experience

Nice To Haves

  • Master’s degree preferred

Responsibilities

  • Develop, test, tune, and maintain behavioral analytics, hunt-based queries, and SIEM/data platform detection rules to identify insider threat vectors (e.g., data exfiltration, privilege abuse, unauthorized access).
  • Translate investigative insights and newly identified threat patterns into automated, resilient detection logic.
  • Monitor detection effectiveness, minimizing false positives while maximizing coverage against known insider attack methodologies.
  • Conduct hypothesis-driven threat hunting across multi-source log repositories, behavioral baselines, and disparate telemetry data to uncover undetected threats.
  • Analyze and troubleshoot large, complex datasets to establish normal baseline activity and isolate anomalies.
  • Partner with incident response and insider threat analysts to operationalize hunt findings into long-term defensive safeguards.
  • Support the end-to-end detection engineering lifecycle, incorporating Secure Software Development Lifecycle (SDLC) best practices, version control, and comprehensive technical documentation.
  • Participate in testing, validation, and continuous delivery of detection artifacts.
  • Manage priorities autonomously in a fast-paced environment, driving deliverables from concept through deployment.

Benefits

  • medical, dental & vision coverage
  • 401(k)
  • life, accident, and disability insurance
  • wellness programs
  • paid time off packages, including planned time off (vacation), unplanned time off (sick leave), and paid holidays
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service