Security Engineer - Insider Threat Detection
Confirmed live in the last 24 hours
Godaddy
Job Description
Location Details: India, Remote
At GoDaddy the future of work looks different for each team. Some teams work in the office full-time; others have a hybrid arrangement (they work remotely some days and in the office some days) and some work entirely remotely.
This is a remote position, so you’ll be working remotely from your home. You may occasionally visit a GoDaddy office to meet with your team for events or meetings.
Join Our Team...
GoDaddy is looking for an Insider Threat Security Engineer to join our growing security team. This role focuses on technical investigation, behavioral detection development, and proactive monitoring to identify and mitigate insider risk across the enterprise. You will be part of a dynamic and collaborative environment where innovation and continuous learning are encouraged. You will have the opportunity to work alongside highly skilled professionals across Security Operations, Legal, HR, and Privacy teams — engaging in knowledge sharing that will further enhance your professional growth and development.
Your expertise in security investigations and behavioral analytics will enable us to protect our organization's most sensitive assets and ensure the integrity of our information systems!
What you'll get to do...
- Develop and refine insider threat detections using log analytics and behavioral data to build a flawless security environment
- Monitor for data exfiltration, privilege misuse, policy violations, and unusual user behavior to keep our systems highly secure
- Use SIEM (Splunk preferred), endpoint telemetry (SentinelOne preferred), and data governance platforms (Microsoft Purview preferred) to detect suspicious activity
- Build detection logic for USB transfers, cloud uploads, mass file access, and identity misuse scenarios
- Support the development of risk scoring models and behavioral analytics refinements
- Conduct structured insider threat investigations using endpoint, identity, cloud, and collaboration platform telemetry
- Correlate evidence across multiple data sources to establish timelines and assess risk
- Produce investigation summaries suitable for Legal, HR, and executive collaborators
- Support chain-of-custody documentation and evidence preservation guidelines
- Advance high-risk findings in accordance with detailed procedures
- Partner with SOC, Detection Engineering, CTI, HR, Legal, and Privacy teams during active security incidents
- Assist in identifying control gaps and recommending improvements to monitoring capabilities
- Contribute to development and refinement of insider threat playbooks and SOPs
- Support monitoring of sensitive data activity using Microsoft Purview and related tooling
- Assist in tuning DLP policies and reviewing alert efficiency
Your experience should include...
- 2+ years of direct and detailed experience in information security investigations, incident response, SOC operations, or related cybersecurity roles
- Experience working with SIEM platforms (Splunk preferred)
- Experience interpreting endpoint telemetry (SentinelOne preferred or a comparable EDR)
- Experience working with data governance or data loss prevention tools (Microsoft Purview preferred)
- Strong understanding of Windows, macOS, and enterprise authentication systems
- Experience examining data exfiltration, privilege misuse, or account compromise
- Ability to write and tune log queries for investigation and detection use cases
- Strong analytical and documentation skills
Similar Jobs
Booz Allen Hamilton
Satellite Communications System Security Engineer, Senior
Comcast
Security Engineer 4
CrowdStrike
Sr. Data Engineer - Cloud Security
Coalition
Data Engineer, Security
Coalition
Data Engineer, Security
Orca Security