Senior Insider Threat Analyst

Salesforce Salesforce · Enterprise · McLean, VA +2

This role is for a Senior Insider Threat Analyst focused on investigations, threat hunting, and identifying indicators of malicious insider activity within Salesforce's enterprise environment. The role requires deep knowledge of cybersecurity, incident response, and counterintelligence procedures.

What you'd actually do

  1. Conduct investigations into the most complex and sensitive insider-threat matters across all of Salesforce. You will own the investigation from initial signal through evidence preservation, timeline reconstruction, interview support, documentation, and handoff to partner teams.
  2. Ensure investigative findings are documented in the case management system and investigative reports, as needed
  3. Identify, collect, and analyze technical and non-technical indicators from a variety of sources
  4. Conduct proactive threat hunting operations for insiders and translate the results of those hunts into investigations and high fidelity detections.
  5. Leverage your analytical and technical skills to identify patterns and trends, and make recommendations to enhance detective and preventive controls

Skills

Required

  • cybersecurity
  • incident response
  • intelligence
  • insider threat
  • counterintelligence
  • investigations
  • threat hunting
  • technical and non-technical indicator analysis
  • case management systems
  • risk assessments
  • M&A activity analysis
  • relationship building
  • technical degree

Nice to have

  • Prior experience identifying and investigating insider threats within a cloud-based software or platform organization
  • familiarity in the unique data access patterns, privileged user risks, and IP theft vectors common to SaaS/PaaS companies

What the JD emphasized

  • 6 years experience in cybersecurity, incident response, intelligence, insider threat or counterintelligence, with at least X-3 years involving insider threat and/or counterintelligence investigations
  • Deep knowledge of procedures and indicators of malicious insider threat activity such as fraud, theft, sabotage, espionage, etc.
  • Proficiency in identifying both cyber, insider, and intelligence threats using a multitude of sources.
  • Demonstrated experience creating and employing effective strategies at scale
  • A related technical degree required