Security Engineer, Insider Risk
Role details
Job location
Tech stack
Job description
- DLP Policy Engineering: Design, develop, and deploy advanced detection logic and use cases within the Insider Risk platforms to identify unauthorized data movement, anomalous system activity, and policy violations. Independently identify gaps in detection coverage and propose, implement, and tune new DLP use cases to address emerging insider risk scenarios.
- Cloud & SaaS Telemetry Analysis: Work with Security Engineering department to ingest and normalize high-fidelity telemetry from cloud environments, SaaS services, and endpoint agents into the Insider Risk security stack/tooling.
- Behavioral Detection Development: Design and implement technical "tripwires" and behavioral models that identify patterns associated with data exfiltration, such as unusual download volumes, unauthorized file sharing, or anomalous access to sensitive repositories.
- Data Pipeline Oversight: Define telemetry requirements and partner with Security Engineering to build and maintain high-fidelity data pipelines from DLP agents and cloud providers into our monitoring platforms.
- Technical Incident Support: Serve as the technical subject matter expert during complex investigations, providing deep-dive forensic analysis, log reconstruction and evidence gathering and preservation. Drive improvements to investigative tooling, detection feedback loops, and post-incident telemetry requirements.
- Infrastructure Maintenance: Manage the health, configuration, and continuous optimization of the Insider Risk technology stack.
Requirements
- 7+ years experience in Security Engineering or Security Operation and 4+ years of DLP or user-centric monitoring experience.
- Demonstrated expertise in configuring and/or managing enterprise-grade DLP solutions (e.g. Proofpoint ITM, Netskope, Digital Guardian, Forcepoint or Symantec) and cloud-native security tools.
- Deep proficiency in analyzing and querying cloud audit logs to reconstruct user activity.
- Strong command of data analysis languages to parse large datasets and identify behavioral trends.
- Experience identifying gaps in telemetry or detection coverage and driving improvements.
Wondering if you're a good fit? We believe in investing in our people, and value candidates who can bring their own diversified experiences to our teams - even if you aren't a 100% skill or experience match. Here are a few qualities we've found compatible with our team. If some of this describes you, we'd love to talk.
- Experience building or maintaining User and Entity Behavior Analytics (UEBA) logic.
- Experience with Cloud Security Posture Management (CSPM) and managing visibility in multi-cloud environments.
- Knowledge of data classification frameworks and the technical implementation of data labeling/tagging.
- Familiarity with global privacy regulations (e.g.GDPR, CCPA) and the technical requirements for compliant data monitoring.
- Experience operating in high-sensitivity environments requiring strong judgment around privacy, ethics, and employee trust.
Benefits & conditions
The base salary range for this role is $165,000 to $242,000. The starting salary will be determined based on job-related knowledge, skills, experience, and market location. We strive for both market alignment and internal equity when determining compensation. In addition to base salary, our total rewards package includes a discretionary bonus, equity awards, and a comprehensive benefits program (all based on eligibility)., In addition to a competitive salary, we offer a variety of benefits to support your needs, including:
- Medical, dental, and vision insurance - 100% paid for by CoreWeave
- Company-paid Life Insurance
- Voluntary supplemental life insurance
- Short and long-term disability insurance
- Flexible Spending Account
- Health Savings Account
- Tuition Reimbursement
- Ability to Participate in Employee Stock Purchase Program (ESPP)
- Mental Wellness Benefits through Spring Health
- Family-Forming support provided by Carrot
- Paid Parental Leave
- Flexible, full-service childcare support with Kinside
- 401(k) with a generous employer match
- Flexible PTO
- Catered lunch each day in our office and data center locations
- A casual work environment
- A work culture focused on innovative disruption
Our Workplace
While we prioritize a hybrid work environment, remote work may be considered for candidates located more than 30 miles from an office, based on role requirements for specialized skill sets. New hires will be invited to attend onboarding at one of our hubs within their first month. Teams also gather quarterly to support collaboration.
California Consumer Privacy Act - California applicants only