Citigroup logo

Insider Threat Engineering Support Lead

Citigroup

Irving, TXFull-time$126–189K/yrSeen 2 days agoSeen in employer's feed 2 days ago

Most applications go out cold — see where you stand first. No sign-up to start.

Watch jobs like this.

At a glance

Compensation
$126–189K/yr
Location
Irving, TX
Schedule
Full-time
Work Authorization
Not specified

Olive lists jobs from US employers, including remote roles you can work from the United States.

Job overview

The Insider Threat Engineering Support Lead will design, tune, and operationalize high‑fidelity detection controls, conduct hypothesis‑driven threat hunting, and support the detection engineering lifecycle within Citi’s Cybersecurity Operations & Engineering team.

Skills & qualifications

RequiredNice to have

Skills

CybersecurityInsider ThreatBehavioral AnalyticsSIEMSplunkKQL/SentinelElasticSQLSnowflakeData AnalysisTroubleshootingInquisitive MindsetEffective CommunicationSelf‑Directed ExecutionSecure Software Development LifecycleVersion ControlTechnical Documentation

Qualifications

Bachelor’s DegreeMaster’s Degree6+ Years Query & Detection Engineering Experience

Benefits

Medical Insurance
Dental Insurance
Vision Insurance
401(k) Match
Paid Time Off

Full job description

Role Overview

Seeking an inquisitive, analytical, and hands-on Insider Threat Engineering Support Lead to join our Cybersecurity Operations & Engineering team. This role sits at the intersection of security engineering, data analytics, and behavioral threat hunting. Unlike traditional perimeter-focused cybersecurity roles, this position focuses on identifying, mitigating, and engineering detection controls around internal human-risk factors, anomalous behavioral patterns, and unauthorized data movement.

The ideal candidate blends an investigative mindset with engineering acumen to design, tune, and operationalize high-fidelity detections, proactively hunt across massive enterprise telemetry datasets, and continuously enhance our insider threat mitigation posture.

Key Responsibilities

Detection Engineering & Rule Optimization

  • Develop, test, tune, and maintain behavioral analytics, hunt-based queries, and SIEM/data platform detection rules to identify insider threat vectors (e.g., data exfiltration, privilege abuse, unauthorized access).

  • Translate investigative insights and newly identified threat patterns into automated, resilient detection logic.

  • Monitor detection effectiveness, minimizing false positives while maximizing coverage against known insider attack methodologies.

Proactive Threat Hunting & Analytics

  • Conduct hypothesis-driven threat hunting across multi-source log repositories, behavioral baselines, and disparate telemetry data to uncover undetected threats.

  • Analyze and troubleshoot large, complex datasets to establish normal baseline activity and isolate anomalies.

  • Partner with incident response and insider threat analysts to operationalize hunt findings into long-term defensive safeguards.

Engineering Support & Process Improvement

  • Support the end-to-end detection engineering lifecycle, incorporating Secure Software Development Lifecycle (SDLC) best practices, version control, and comprehensive technical documentation.

  • Participate in testing, validation, and continuous delivery of detection artifacts.

  • Manage priorities autonomously in a fast-paced environment, driving deliverables from concept through deployment.

Candidate Qualifications & Requirements

Desired Skills & Experience

  • Domain Knowledge: Strong understanding of core Cybersecurity and Insider Threat concepts, specifically the behavioral, access, and human-centric risk models that distinguish insider threats from external attacks.

  • Query & Detection Engineering: 6+ years of experience constructing, tuning, and executing complex queries within SIEM, data lake, or log analytics platforms (e.g., Splunk, KQL/Sentinel, Elastic, SQL, Snowflake).

  • Threat Hunting: Demonstrated ability to perform proactive, hypothesis-based threat hunting to identify stealthy, anomalous, or policy-violating activity across enterprise log sources.

  • Data Analysis & Troubleshooting: Exceptional attention to detail with the ability to navigate, sanitize, query, and troubleshoot high-volume, heterogeneous datasets.

  • Self-Directed Execution: Demonstrated capability to independently manage workload, prioritize high-impact initiatives, and deliver results with minimal supervision.

Behavioral Attributes & Core Competencies

  • Inquisitive & Investigative Mindset : High natural curiosity and an "outside-the-box" analytical approach to solving ambiguous problems and tracing subtle anomalies.

  • Hybrid Engineering & Investigation Focus : Ability to view telemetry through both an investigator's analytical lens and a software/security engineer’s systems-building perspective.

  • Effective Communication : Ability to articulate complex data findings and engineering designs clearly to technical peers and non-technical stakeholders alike.

Education:

  • Bachelor’s degree/University degree or equivalent experience

  • Master’s degree preferred

This job description provides a high-level review of the types of work performed. Other job-related duties may be assigned as required.


Job Family Group:

Technology


Job Family:

Information Security


Time Type:

Full time


Primary Location:

Irving Texas United States


Primary Location Full Time Salary Range:

$125,760.00 - $188,640.00

In addition to salary, Citi’s offerings may also include, for eligible employees, discretionary and formulaic incentive and retention awards. Citi offers competitive employee benefits, including: medical, dental & vision coverage; 401(k); life, accident, and disability insurance; and wellness programs. Citi also offers paid time off packages, including planned time off (vacation), unplanned time off (sick leave), and paid holidays. For additional information regarding Citi employee benefits, please visit citibenefits.com. Available offerings may vary by jurisdiction, job level, and date of hire.


Most Relevant Skills

Please see the requirements listed above.


Other Relevant Skills

For complementary skills, please see above and/or contact the recruiter.


Anticipated Posting Close Date:

Oct 25, 2026


Automated Processing and AI

We use automated processing, including artificial intelligence, for our legitimate business interests (or our reasonable and appropriate business purposes) to identify and align the candidate's skills and abilities with a specific job opening. Additionally, if you so choose, or consent, we can match your skills and abilities to other suitable roles at Citi.

Importantly, all our hiring processes and decisions, including determining your suitability for a role, are conducted, checked, and decided by individuals. Our automated processing and AI do not involve relying on automatic or autonomous decision-making. Please refer to any Jurisdictional Considerations, with specific provisions for your country (where relevant) for further details.

Illinois residents – AI Notice and Right (https://tbcdn.talentbrew.com/company/287/cms/v3/docs/policies/Illinois\_Career\_Supplement\_a11y.pdf)


Citi is an equal opportunity employer, and qualified candidates will receive consideration without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other characteristic protected by law.

If you are a person with a disability and need a reasonable accommodation to use our search tools and/or apply for a career opportunity review Accessibility at Citi (https://www.citigroup.com/citi/accessibility/application-accessibility.htm) .

View Citi’s EEO Policy Statement (https://www.citigroup.com/global/eeo-aa-policy) and the Know Your Rights (https://www.eeoc.gov/sites/default/files/2023-06/22-088\_EEOC\_KnowYourRights6.12ScreenRdr.pdf) poster.

Citi is an equal opportunity and affirmative action employer.

Minority/Female/Veteran/Individuals with Disabilities/Sexual Orientation/Gender Identity.

Similar jobs, posted recently

Open roles like this one, listed in the last 30 days.

You've read the whole posting — now see how you match it.