Phoenix, AZ, USA
4 days ago
Insider Risk Engineer

Job Title:

Insider Risk Engineer

Location:

CityScape

What you'll do:

Western Alliance Bank’s (WAB) Business Information Security Office is responsible for analyzing and conducting assessments of insider related risks and vulnerabilities identified by the WAB Insider Risk Program, including policy violations, system alerts, and other reported threats to the confidentiality, integrity, and availability of information assets. The role will coordinate investigations involving a variety of highly technical and/or business functional stakeholders across the WAB enterprise. This is key to ensuring the proactive management of insider-related risk services in compliance with Western Alliance Bank policies, standards, and frameworks.

This individual will work as part of a matrixed team of cybersecurity professionals in a structure designed to help them succeed in delivering best-in-class security to this stakeholder group.Facilitate/conduct investigations by analyzing and verifying information through various investigative techniques, internal resources, forensics, and Insider Risk tools such as Data Loss Prevention, Endpoint Detection and Response, Network Traffic Analysis & Deceptive Technology to detect malicious lateral movement & privilege escalation in On-prem and Cloud environment.Identify the technical requirements for accessing data for insider risk analysis.Provide actionable Insider risk analysis for remediation on all escalations.Facilitate Triage of potential Insider Risk events with cross-functional partners.Collaborate with internal teams to drive Insider Risk program continuous improvement.Assess and make recommendations for improvement and refinement of use cases, software tools, and other risk reduction methods used to improve the Insider Risk Program.Create analytical and data visualization tools to automate the analysis of large dataset and correlate with other sources and apply advanced analytics to identify insider anomalies.Develop insider risk indicators that fuse data from multiple sources.Design, Build, and Maintain operational data store for insider risk and security program data in secure manner and according to industry best practices and regulatory requirements.Develop and implement software and data applications in both our existing stack (SQL Server on Azure VM, Python on Azure Linux VM) and coding for our planned future state (Azure SQL, Azure Linux VM, Master Data Management, etc.).Stay current with the latest cyber threats, attacks, and vulnerabilities, and updated with evolving and emerging attack techniques and methods.Maintain and update related insider risk documentations such as IT Standards and Standard Operation Procedures and carry out activities specified in these artifacts.Participate in various cybersecurity exercises such as cyber tabletop and BCP.

What you'll need:

Bachelor’s degree from a four-year college or university and ten (10) or more years of related experience and/or training; or a combination of experience and education.Work related experience must include security experience as an insider risk/threat analyst, or security engineer, or a similar role in a Financial Institution environment.Hands on experience with investigative and/or insider risk tools, such as UEBA, DLP, EDR, Computer Forensics, Monitoring, Elastic SIEM, Incident Response, Databases, or data visualization tools in On-prem and Cloud environment.Proven experience using analytical and data visualization tools to automate the analysis of large dataset and correlate with other sources of information.Understanding and/or working knowledge of insider risks in the Dark and Deep Web underground forums.Working knowledge of Azure, Azure SQL and serverless compute environments.Experience developing Restful APIs, SQL data warehouses or data marts involving the extraction, transformation, and loading of data in financial services environment.Proficiency in Power BI development to and creation of business intelligence data visualizations.Experience with SQL for data manipulation and extraction.Knowledge of Data Analysis Expressions (DAX) for creating calculations.Strong practical experience in cybersecurity: CMU Insider Threat Framework, MITRE ATT&CK Framework, Cyber kill chain, TTP, threat intelligence, malware triage.Strong understanding of Different Attacks on system, network, applications.Possess strong analytical skills, self-motivated, detail oriented and team player.Willing to learn and work in a collaborative manner with peers and team.Good interpersonal and communication skills.Able to work under pressure during critical situations.A passion for cybersecurity and data security.

Benefits you’ll love:
We offer all the important things you'd want — like competitive salaries, an ownership stake in the company, medical and dental insurance, time off, a great 401k matching program, tuition assistance program, an employee volunteer program, and a wellness program. In addition, you’ll have the opportunity to bolster your business knowledge, learning the ins and outs of how successful companies operate and manage their finances, giving you invaluable hands-on experience to help grow your career!

About the company:

Western Alliance Bank is a wholly owned subsidiary of Western Alliance Bancorporation. Alliance Bank of Arizona, Alliance Association Bank, Bank of Nevada, Bridge Bank, First Independent Bank, and Torrey Pines Bank are divisions of Western Alliance Bank; Member FDIC.  AmeriHome Mortgage is a Western Alliance Bank company.

Western Alliance Bancorporation is committed to equal employment and will consider all qualified applicants without regard to race, sex, color, religion, age, nation origin, marital status, disability, protected veteran status, sexual orientation, gender identity or genetic information. Western Alliance Bancorporation is committed to working with and providing reasonable accommodations for individuals with disabilities. If you are an individual with a disability and require a reasonable accommodation to complete any part of the application process and/or need an alternative method of applying, please email HR@westernalliancebank.com or call 602-386-2488.  When contacting us, please provide your contact information and state the nature of your accessibility issue.  We will only respond to inquiries concerning requests that involve a reasonable accommodation in the application process.

© Western Alliance Bancorporation

Confirm your E-mail: Send Email