Full-Time Detection Engineering Lead (Insider Risk)
Guardant Health is hiring a remote Full-Time Detection Engineering Lead (Insider Risk). The career level for this job opening is Manager and is accepting Worldwide based applicants remotely. Read complete job description before applying.
Guardant Health
Job Title
Posted
Career Level
Career Level
Locations Accepted
Salary
Share
Job Details
This is an exciting opportunity for a technically strong cybersecurity professional to take the next step into a leadership role. As Detection Engineering Lead (Insider risk), you'll play a central role in building a scalable insider risk management program from the ground up. You'll use your hands-on experience in incident response, threat detection, and forensic analysis to lead investigations, develop processes for detecting and responding to insider threats. This role is for someone looking to expand from technical execution to owning strategy, process design, and stakeholder collaboration. You'll work closely with cross-functional teams (HR, Legal, Cybersecurity, and Technology) to assess insider risks, manage cases, and implement mitigation strategies.
Key Responsibilities Include:
- Building a resilient insider threat program aligning with business goals and security standards.
- Developing and maintaining automations, workflows, tools, and processes to detect and respond to high-risk insider activities.
- Working with cross-functional teams to classify, report, and resolve insider risks, enhancing incident response procedures.
- Serving as a reliable point of contact for insider risk matters, ensuring timely updates and alignment with senior leadership.
- Implementing and overseeing monitoring systems for behavioral anomalies, enabling early detection of suspicious insider activities.
- Collaborating with awareness teams to identify emerging threat tactics, promote risk-reducing behaviors, and prevent data loss/misuse.
- Breaking down complex security challenges into clear, understandable messages to empower leaders.
- Coordinating with Business Units, Security Operations, HR, Legal, and Compliance teams to address insider risks holistically and efficiently, maintaining strict confidentiality.
- Creating and maintaining meaningful use cases in UEBA and monitoring tools for early detection and prioritization of risky behaviors.
- Defining metrics and KPIs to clearly communicate program health and progress to senior leadership.
- Continuously refining rules, analytics, and detection logic to adapt to evolving threats and elevate detection capabilities.
- Aligning the insider risk program roadmap with organizational priorities for long-term relevance and impact.
- Identifying and scoping insider risks through detailed analysis, evidence collection, and sound judgment.
- Monitoring unauthorized activities while adhering to legal and privacy guidelines.
- Evaluating and refining behavioral detection models to stay ahead of insider threat patterns and false positives.
- Producing intelligence reports synthesizing diverse data points into actionable insights.
- Aligning team projects and goals with broader organizational strategy.
- Mentoring junior analysts to build a strong team culture.