Insider Threat Engineering Support Lead

Citi

Confirmed live yesterday High trust
Hybrid

Quick summary

Work type
Hybrid
Location
Irving, TX
Salary
$125,760–$188,640 / yr
Employment
Full-time
Posted
3 days ago
Freshness
Confirmed live yesterday
Closes
Oct 25, 2026

Market check

Salary context

Below market

How this pay compares to similar roles

Similar $185k
This role $157k
$114k most similar roles pay here $237k

This role pays less than 71% of similar roles. Most pay $152,875–$216,271 — the shaded band above. At the midpoint, this role pays about $157k versus about $185k for comparable roles.

Based on 240 similar postings.

Employer

About Citi

Citi is one of the world’s most trusted financial institutions, proudly serving millions of customers across the United States.

Citi currently has 271 open roles on FindRole.

Listed pay typically runs $125,760–$188,640 across 255 roles with salary data.

Most-posted roles

View all roles at Citi

At a glance

TL;DR · Insider Threat Engineering Support Lead

The Insider Threat Engineering Support Lead joins the Cybersecurity Operations & Engineering team to focus on identifying, mitigating, and engineering detection controls around internal human-risk factors, anomalous behavioral patterns, and unauthorized data movement. This role involves developing, testing, and tuning behavioral analytics, hunt-based queries, and SIEM or data platform detection rules to address risks like privilege abuse and data exfiltration. The individual will conduct hypothesis-driven threat hunting across multi-source log repositories and troubleshoot complex datasets to establish baseline activities. Key technical requirements include experience with Splunk, KQL/Sentinel, Elastic, SQL, and Snowflake. The role requires a blend of investigative mindset and engineering acumen to manage the detection lifecycle using SDLC best practices and version control. This position addresses the specific challenge of distinguishing internal human-centric risks from external attacks through advanced data analysis.

What you'll do

  • Develop, test, and tune behavioral analytics and SIEM detection rules to identify insider threat vectors.
  • Translate investigative insights into automated, resilient detection logic for data exfiltration and privilege abuse.
  • Conduct hypothesis-driven threat hunting across multi-source log repositories and telemetry data.
  • Analyze large, complex datasets to establish baseline activity and isolate anomalies.
  • Partner with incident response teams to turn hunt findings into long-term defensive safeguards.
  • Manage the end-to-end detection engineering lifecycle using SDLC best practices and version control.
  • Create comprehensive technical documentation for all detection artifacts and engineering designs.

What we're looking for

  • Bachelor's degree or equivalent experience required; Master's degree preferred.
  • 6+ years of experience constructing, tuning, and executing complex queries within SIEM, data lake, or log analytics platforms (preferred).
  • Strong understanding of core Cybersecurity and Insider Threat concepts, including behavioral and human-centric risk models (preferred).
  • Demonstrated ability to perform proactive, hypothesis-based threat hunting across enterprise log sources (preferred).
  • Ability to navigate, sanitize, query, and troubleshoot high-volume, heterogeneous datasets.
  • Ability to articulate complex data findings and engineering designs to both technical and non-technical stakeholders.
  • Capability to manage priorities autonomously and deliver results in a fast-paced environment.
  • Ability to combine an investigative analytical lens with a software/security engineer's systems-building perspective.

More like this

Similar roles

Insider Threat Engineer

Cloudflare, Inc

Austin, TX 79 days ago
SIEM EDR UEBA DLP Python PowerShell Splunk Elastic CrowdStrike SentinelOne EnCase FTK X-Ways AWS GCP Azure Digital Forensics Incident Response Threat Hunting
5+ yrs exp Hybrid

Insider Risk Security Engineer

Lam Research

Tualatin, OR 39 days ago
Insider Risk Management DLP UEBA Microsoft E5 KQL YARA Regex JSON Lucene Query Syntax Cloud Security Security Engineering Behavioral Analysis Information Security Cybersecurity
5+ yrs exp

Insider Risk Security Engineer

Lam Research

Phoenix, AZ 39 days ago
Insider Risk Management DLP UEBA Microsoft E5 KQL YARA Regex JSON Lucene Query Syntax Cloud Security Cybersecurity Engineering Behavioral Analysis Counterintelligence
5+ yrs exp

Insider Risk Security Engineer

Lam Research

Fremont, CA 39 days ago $114,000–$253,000
Insider Risk Management DLP UEBA Microsoft E5 KQL YARA Regex JSON Lucene Query Syntax Cloud Security Cybersecurity Engineering Information Security Counterintelligence
5+ yrs exp Hybrid

Information Security Risk Analyst

Lam Research

Tualatin, OR 79 days ago
SIEM Microsoft Sentinel Splunk KQL SPL SQL Python PowerShell MITRE ATT&CK UEBA Azure AWS Cloud Platform Entra ID Logic Apps MISP STIX/TAXII Threat Hunting Incident Response

Information Security Risk Analyst

Lam Research

Tualatin, OR 88 days ago
SIEM KQL SPL SQL Python PowerShell Microsoft Sentinel Splunk Exabeam Securonix Microsoft Defender XDR Entra ID Azure AWS Cloud Platform MITRE ATT&CK UEBA STIX/TAXII MISP Logic Apps