Senior Insider Threat Analyst

WorkdayBoulder, CO
$144,400 - $258,000Hybrid

About The Position

Workday is seeking a skilled Insider Threat Analyst to support a dynamic environment. In this role, you will play a critical part in identifying, analyzing, and mitigating insider threats by leveraging advanced security tools, behavioral analytics, and investigative techniques. You will collaborate with cross-functional teams to assess risks, detect anomalies, and enhance the organization's overall insider threat posture.

Requirements

  • 8+ years of experience in Insider Threat, Security operations, Threat Hunting, Intelligence analysis, corporate investigations or counterintelligence.
  • Threat hunting experience in a corporate or government environment.
  • Hand On experience designing, tuning, and operationalizing detection logic and policies in tools such as Proofpoint, DTEX, Exabeam, Netskope, or similar UEBA and DLP tools.
  • Experience working with and analyzing data or related telemetry to identify and investigate insider risk activity in DLP UEBA, UAM, and SIEM solutions.
  • Experience developing program metrics and presenting finding to senior leadership.
  • Bachelor’s degree in a relevant discipline such as Computer Science, Cybersecurity, Information Security, or a related discipline, or equivalent practical experience.

Nice To Haves

  • Experience mapping detections to MITRE ATT&CK and other Insider threat TTP knowledge bases.
  • Strong experience with insider threat detection methodologies, behavioral analytics, and risk indicators.
  • Proven ability to design, tune, and operationalize detection logic to improve alert quality and reduce noise.
  • Analytical mindset with ability to translate investigation outcomes into detection improvements.
  • Understanding of data classification, data movement patterns, and exfiltration techniques.
  • Ability to measure and improve detection effectiveness (i.e., alert fidelity, actionable alert rate).
  • Strong collaboration and communication skills to influence cross-functional stakeholders.
  • Experience implementing automation or orchestration in security operations (SOAR, APIs, pipelines, scripted workflows) to accelerate response and improve consistency.
  • Experience applying AI-assisted analytics for alert enrichment, correlation/deduplication, prioritization, and operational reporting.
  • Experience contributing to training, playbooks, and tabletop exercise development.
  • Relevant industry certifications (e.g., GCIA, GCIH, GCFA, ITPM, SEC+).

Responsibilities

  • Design, build, and continuously refine insider threat detection logic, use cases, and analytics to improve signal quality. Focus on reducing false positives and increasing the percentage of actionable insider threat alerts.
  • Lead triage and investigation of insider threat alerts, applying structured methodologies to assess risk. Translate investigation outcomes into detection improvements, ensuring a continuous feedback loop between operations and engineering.
  • Develop and implement a scalable detection strategy aligned to key insider threat risks (i.e., data exfiltration, employee exit risk, misuse). Identify gaps and prioritize new detection use cases to expand coverage and effectiveness.
  • Conduct proactive threat hunting using behavioral, endpoint, and data activity signals to identify emerging insider risks. Translate findings into new detection use cases and improvements to existing detection logic.
  • Partner with Data Protection, Legal, HR, and Cyber teams to ensure detections are risk-aligned, context-aware, and operationally actionable. Incorporate business context and investigation requirements into detection design to improve alert fidelity and response effectiveness.

Benefits

  • Workday Bonus Plan or a role-specific commission/bonus
  • Annual refresh stock grants
  • Comprehensive benefits
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service