About your role:
As a Cyber Security Operations Insider Threat Investigator, you will play a critical role in protecting Fiserv and our clients from cyber threats. You will be responsible for investigating suspicious activities, anomalous events, and behaviors that may pose a security risk to the company. Your contributions will be vital in ensuring our systems are secure and our clients’ data is protected, making a direct impact on Fiserv’s overall security strategy.
What you'll do:
- Investigate potential insider threat, sabotage, data exfiltration, misuse, and misrepresentation cases
- Analyze and interpret SIEM, DLP, EUBA, proxy, system logs, email, DLP, CASB, endpoint, network, database, application logs and other potential case related artifacts
- Execute complex investigations, conduct interviews, write objective reports
- Advise on root cause analysis, preventative controls, and new detections and aid in maturing the Enterprise Insider Threat Program
- Perform threat hunts and new alert triage to determine efficacy of UEBA alert program feeding investigations
- Perform deep analysis of large data sets to identify trends, tuning opportunities, and control creation
- Through analysis, identify root cause themes including bad business practices and work with control owners to reduce risk & enhance overall security posture
- Perform security reviews, cyber defense trend analysis and open-source research, partnering with Threat Intelligence on emerging risks
Experience you'll need to have:
- 7+ years of experience in insider threat investigations, cybersecurity, incident response, law enforcement, or financial crimes with deep knowledge of Insider Threat UEBA platforms, User Activity Monitoring (UAM) or other similar Machine Learning /Risk Score methodologies/concepts
- Experience conducting complex technical investigations including deep log analysis of systems, network, applications and tools, managing chain of custody and evidence preservation
- Experience conducting interviews and deep understanding of Insider Threat anatomy of attack and nation-state sponsored espionage / cyber espionage activities
- Strong written communication skills with experience writing fact-based objective reports for legal, HR, and other business partners.
- Maintain thorough documentation for each case and meticulously curate artifacts and evidence.
- Recommend risk mitigation and root cause analysis for cases and develop case scoping queries on the fly while working cases
- Understanding and experience of investigative procedures including preservation, analysis, reporting, and presentation.
- Experience with OSINT, public records, and link analysis
- Experienced with SIEM/SOAR technologies such as Splunk, Google SecOps, log sourcing, forwarders, parsing, data pipeline and management, data architecture
- Working knowledge of EDR, NDR, DLP, CASB solutions
- Working knowledge of information security operations frameworks and standards – MITRE, NIST, Cyber Kill Chain, etc.
- Familiar with best practice security principles on identity & access management, network security, endpoint security, vulnerability management, and application security
- Ability to obtain security clearance and/or active C6 security clearance (or higher) preferred with computer networking concepts, protocols, and network security methodologies, cyber-attack stages and techniques used by malicious insiders.
- Working knowledge of global data protection privacy regulations
Experience that would be great to have:
- (Preferred) Experience in technical investigations, law enforcement, HUMINT, and/or Counterintelligence,
- (Preferred) Training and/or experience with financial crimes
- Certifications such as CMU CERT ITPM/ ITVA, CCITP, CISM, CDPSE or similar
- Experience in data science and analytics solutions applicable to the insider threat detection space.
- Exposure to programming, scripting and query languages such as Python, bash, SQL, Lucene, YARA-L, and SPL.
- Experience working in financial services or financial technology desired.
Sponsorship: - In order to be considered, you must be legally authorized to work in the U.S. without need for visa sponsorship now or in the future.
R-10370114