OPEN POSITIONS
Cybersecurity

Insider Risk Security Engineer

APPLY FOR THIS JOB
Remote
Full time - Remote
Remote

We're hiring a hands-on Insider Risk Security Engineer to build, tune, and operate our insider threat program. This is not a ticket-triage or compliance-report role. You'll be in the trenches analyzing user behavior, tuning detection engines, reconstructing timelines across our entire stack, and writing the automation that makes investigations faster, deeper, and more consistent.

 

You'll act as the technical engine of our team, bridging security operations, detection engineering, and automation — while partnering discreetly with Legal, People, and IT to protect our most critical data from accidental exposure and malicious exfiltration. One day you're reconstructing a user's timeline across five platforms to determine if a data exfiltration happened. Next, you're writing a detection rule in YARA-L to catch that class of behavior going forward, or shipping a tool that automates the triage you just did manually.

What You'll Do

  • Build & Tune Detections: Design, implement, and fine-tune rules across Chronicle (YARA-L), Wiz, and SentinelOne, plus our DLP and UEBA surfaces. Move beyond out-of-the-box alerts, actively cut false positives, and own the detection lifecycle from rule creation to retirement.
  • Investigate & Triage: Act as the primary technical investigator for insider risk alerts. Analyze logs, reconstruct user timelines across our entire stack, and determine what happened, why, and what to do about it — including intent behind data movement.
  • Reduce the Noise: Continuously tune alerts and detection logic to drive down false positives and keep the signal high.
  • Automate Workflows: Write code (TypeScript) to automate repetitive triage tasks and integrate our insider risk tools with our SIEM and SOAR platforms. If you repeat a triage step twice, automate it.
  • Weaponize AI for Investigations: Build and tune LLM-powered agents that triage alerts, enrich them with cross-platform context, and reconstruct investigation timelines automatically. Turn repetitive forensic work into autonomous workflows.
  • Cross-Functional Operations: Partner directly with Legal, People, and other Security teams to safely and discreetly conduct forensic investigations and coordinate remediation efforts.
  • Threat Hunting: Proactively hunt for undetected anomalous behavior, unauthorized shadow IT usage, or risky data handling practices across endpoints and cloud environments.

What You Need to Succeed

  • Hands-on Experience in a Security Operations Center (SOC), Cyber Threat Intelligence, Incident Response, Security Engineering, or dedicated Insider Threat role.
  • Investigative & Analytical Mindset: You know how to differentiate between a malicious data exfiltration event and an engineer who just doesn't understand the company's cloud storage policy.
  • Technical Chops: Deep, practical experience querying raw logs, writing detection rules, and understanding the data pipeline behind them — you don't just read dashboards, you go to the source.
  • Stack Familiarity (or ability to ramp fast): Google Workspace (Admin SDK, Reports API), Chronicle / Google SecOps (UDM Search, YARA-L), Wiz, SentinelOne (Deep Visibility), Jumpcloud, Tailscale, GCP Audit Logs and IAM. DLP/UEBA tools (e.g., Microsoft Purview, Proofpoint, Forcepoint, Varonis, Exabeam) and SIEM platforms (e.g., Splunk, Sentinel, CrowdStrike LogScale).
  • Scripting Skills: Proficiency in TypeScript (Python/bash a plus). You write tools and services others can rely on, not just one-off scripts.
  • Discretion & Ethics: Unwavering integrity and the ability to handle highly sensitive, confidential personnel investigations with strict adherence to privacy laws and company guidelines.
  • Communication: The ability to translate complex technical forensic findings into clear, non-technical summaries for People and Legal teams.

Nice to Have

  • Experience with insider threat detection, User and Entity Behavior Analytics, or building insider risk workflows.
  • Familiarity with fintech / payment industry security (PCI DSS, card data, Pix, acquiring flows).
  • Experience with LLM-powered security agents or AI-driven detection / triage automation.
  • Kubernetes / Istio service mesh context.

The Future We See:

At CloudWalk, we envision a future where AI empowers every field to reach new heights:
• People teams leveraging AI to transform talent acquisition and employee development.
• Marketing professionals creating data-driven, AI-powered campaign strategies.
• Customer Success teams enhancing client experiences with intelligent solutions.
• Risk analysts combining human expertise with AI to navigate complexities.
• Designers collaborating with AI to push creative boundaries.

Join us at CloudWalk, where we're not just engineering solutions; we're building a smarter, AI-driven future for payments—together.

By applying for this position, your data will be processed as per CloudWalk's Privacy Policy that you can read here in Portuguese and here in English.

We use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, assessing responses, and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

submit your application

Links

Cloudwalk | Introductory Questions 01

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.