Zscaler
Insider Risk Security Engineer
About this role
Zscaler is seeking an Insider Risk Security Engineer to lead detection engineering, investigation playbook development, and case management for their enterprise insider threat program. You'll refine detection rules, conduct forensic investigations using EDR/XDR and SIEM tools, and collaborate with HR, Legal, and executive stakeholders on sensitive cases.
What you'll do
- Refine detection rules and reduce alert noise to improve insider risk program coverage and fidelity
- Investigate endpoint and user activity using EDR/XDR, UEBA, and SIEM tools with end-to-end case management
- Develop and iterate insider risk investigation playbooks based on case patterns and lessons learned
- Serve as primary contact for HR, Legal, and business leaders, preparing evidentiary case documentation
- Mentor junior analysts and drive operational improvements to insider risk processes
- Apply automation to investigative workflows using Python or JavaScript
What they're looking for
- Insider risk and data protection investigation
- EDR/XDR and SIEM platform expertise
- UEBA (User and Entity Behavior Analytics)
- Python or JavaScript automation
- Forensic analysis and digital investigation
- Cross-functional stakeholder communication and discretion
- AI/ML technologies understanding
- Detection engineering and rule development
Opens the application — the Jobs AI extension fills it for you. Set up autofill
Opens the official application on the employer’s site. No login required.
Zscaler
Zscaler builds Zero Trust security platforms and managed detection and response (MDR) services that protect endpoints and cloud infrastructure while processing massive transaction volumes. The company is hiring threat response engineers for security operations, sales engineers to support enterprise customers, and production/reliability engineers to maintain their scalable cloud infrastructure.
- Website
- zscaler.com
Likely interview questions
- Walk us through your most complex insider risk investigation—how did you build the timeline and what evidence was critical?
- Describe your experience refining detection rules. How do you balance catching threats while minimizing false positives?