> Markdown version of [/jobs/ext/3224542-insider-threat-data-loss-prevention-dlp-technical-investigator](https://www.wearedevelopers.com/jobs/ext/3224542-insider-threat-data-loss-prevention-dlp-technical-investigator). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Insider Threat / Data Loss Prevention (DLP) technical investigator - **Company:** State Street - **Location:** United States - **Experience:** Expert - **Salary:** $110,000.0 - $185,000.0 - **Contract:** Permanent contract - **Skills:** Data Analysis, Antivirus Softwares, Cyber Security, Computer Forensics, Information Leak Prevention, Data Loss, Factor Analysis, Forensics Tools (Digital Forensics Software), Issue Tracking Systems, Network Forensics, Security Information and Event Management, Cloud Platform System, Data Classification - **Published:** September 4, 2026 - **Apply:** https://www.dice.com/job-detail/edaab973-31ad-42c1-af3f-27a77978be5c ## About the Role * Strong understanding of endpoint, network, and system logs * Strong understanding of cloud forensic tools and technologies * Strong understanding of SIEM tools and how to use them to retrive and analyze data * Exceptional problem solving and analytical skills * Exceptional report writing skills * Knowledge of Endpoint Detection and Response and Anti Virus tools * Knowlegde of Data Loss Prevention tools * Knowledge and understanding of data organizing or structuring complex data across varied data sources * Strong organizational, multi-tasking, and prioritizing skills, * 5+ years of experience performing computer and network forensics demonstrated through work, military, or education * 5+ years of experience in production supporting, including problem identification, ticket documentation, and customer/vendor relations, demonstrated through work, military, or education * 5+ years of experience using ticket tracking tools for change management, problem and incident management, and availability management, demonstrated through work, military, or education * Certified Computer Forensic Examiner * Certified Computer Examiner * GIAC Network Forensic Analyst ## Description State Street seeks to recruit an Insider Threat / Data Loss Prevention (DLP) technical investigator responsible for the technical investigative function of responding to DLP incidents and insider threats at State Street. This team will work with the core Global Cyber Security teams, Global Security, Enterprise Continuity Services, and infrastructure teams to investigate, resolve, and recover from insider threat and DLP incidents. This position requires strong technical knowledge of forensics tools, SIEMs, system logs, analytic skills, creativity, quick reaction, interview experience, and technical expertise to protect the bank's assets. Join us in evolving our insider threat and DLP response capabilities to shape a pro-active, threat intelligence driven fusion model to protect State Street, its customers and partners from sophisticated global threat actors. What you will be responsible for As Data Loss Prevention Technical Investigator you will * Review data loss prevention, insider threat, and other cyber events to ascertain policy violations * Determine data classification of sensitive documents flagged by the Data Loss Prevention tools * Build and maintain operating procedures for data loss events and cyber security events * Perform forensic analysis of endpoints as required * Conduct analysis of endpoint logs, network logs, cloud platform logs, and other relevant information in order to investigate suspected policy violations * Provide training, informational and educational materials to impacted employees * Conduct root cause and contributing factor analysis in order to understand why an incident occurred * Document interviews, write investigative reports, and handle evidence in accordance with organizational processes and procedures * Identify gaps in technical controls and develop strategies to remediate the gaps * Ensure that security plans, controls, processes, standards, policies and procedures are aligned with overall information security standards * Identify security risks and exposures, determine the causes of standard security violations and implement changes to halt future incidents and improve security. * Monitor and analyze system access logs to ensure ability to provide audit trails and incident investigation