Insider Threat Engineer

Cloudflare, Inc

Confirmed live 2 days ago High trust
Hybrid

Quick summary

Work type
Hybrid
Location
Austin, TX
Posted
58 days ago
Freshness
Confirmed live 2 days ago

Market check

Salary context

How this pay compares to similar roles

Similar $177k
$118k most similar roles pay here $227k

This listing doesn't post a salary. Most similar roles pay $150,000–$203,750.

Based on 240 similar postings.

Employer

About Cloudflare, Inc

Cloudflare is a prominent cloud services and security company that provides content delivery network (CDN), DDoS mitigation, and Zero Trust security services to millions of internet properties.

Cloudflare, Inc currently has 190 open roles on FindRole.

Listed pay typically runs $215,000–$278,000 across 59 roles with salary data.

Most-posted roles

View all roles at Cloudflare, Inc

At a glance

TL;DR · Insider Threat Engineer

Insider Threat Engineer The Insider Threat Engineer joins the Security Threat Detection, Response and Emulation team to protect the company from malicious or negligent insider activities. This role involves leading technical aspects of the insider threat program, including conducting digital investigations into data exfiltration and intellectual property theft, performing proactive threat hunting, and improving detection capabilities by developing new rules and response playbooks. The successful candidate will collaborate with Legal, HR, and Privacy teams to ensure all actions meet regulatory and ethical standards. Key technical requirements include experience with forensic tools like EnCase or FTK, security technologies such as SIEM (Splunk, Elastic), EDR (CrowdStrike, SentinelOne), and UEBA. Additionally, the role requires proficiency in Python or PowerShell for automation and analysis of large datasets to identify anomalous user behaviors within a complex corporate environment.

What you'll do

  • Conduct technical investigations into insider threats including data exfiltration and intellectual property theft.
  • Collect, preserve, and analyze digital evidence from endpoints, network logs, cloud services, and email.
  • Proactively hunt for insider threats using SIEM, DLP, EDR, and UEBA tools.
  • Develop and execute threat hunting hypotheses based on emerging techniques and internal data.
  • Design and implement new rules, alerts, and use cases to improve detection capabilities.
  • Create and refine response playbooks for various insider threat scenarios.
  • Serve as the primary technical liaison for Legal, HR, and Privacy teams during investigations.
  • Provide technical guidance during policy development and incident response planning.

What we're looking for

  • Must have 5+ years of experience in a technical security role.
  • Must have at least 2+ years of experience focused on insider threat, digital forensics, or security investigations.
  • Proven experience leading complex technical investigations using forensic tools like EnCase, FTK, X-Ways, or open-source alternatives.
  • Deep understanding of security technologies including SIEM (Splunk, Elastic), EDR (CrowdStrike, SentinelOne), and UEBA data sources.
  • Strong scripting and programming skills in languages such as Python or PowerShell to automate tasks and analyze large datasets.
  • Experience working with legal and HR teams on sensitive employee-related matters.
  • Ability to communicate complex technical concepts clearly to non-technical audiences.
  • Authorization to receive software or technology controlled under U.S. export control laws.

More like this

Similar roles

Insider Threat Investigator III

Global Payments (TSYS)

Atlanta, GA +1 7 days ago
UEBA DLP Digital Forensics Incident Response MITRE ATT&CK EDR SIEM CASB PAM AWS Microsoft Azure Google Cloud Platform Python PowerShell Bash JavaScript Cybersecurity
3+ yrs exp

Insider Risk Security Engineer

Lam Research

Phoenix, AZ 18 days ago
Insider Risk Management DLP UEBA Microsoft E5 KQL YARA Regex JSON Lucene Query Syntax Cloud Security Cybersecurity Engineering Behavioral Analysis Counterintelligence
5+ yrs exp

Insider Risk Security Engineer

Lam Research

Fremont, CA 18 days ago $114,000$253,000
Insider Risk Management DLP UEBA Microsoft E5 KQL YARA Regex JSON Lucene Query Syntax Cloud Security Cybersecurity Engineering Information Security Counterintelligence
5+ yrs exp Hybrid

Insider Risk Security Engineer

Lam Research

Tualatin, OR 18 days ago
Insider Risk Management DLP UEBA Microsoft E5 KQL YARA Regex JSON Lucene Query Syntax Cloud Security Security Engineering Behavioral Analysis Information Security Cybersecurity
5+ yrs exp

Lead Engineer, Insider Risk

Target

Remote (Brooklyn Park, MN) 11 days ago $132,000$238,000
DLP UEBA SIEM SOAR EDR CASB Python PowerShell ZScaler ForcePoint Symantec Incident Response Cyber Threat Intelligence Security Architecture Cloud Security Automation Endpoint Detection
7+ yrs exp Remote Hybrid