← Back to jobs

Sr. Investigator, Cyber Security

Skills

accessibilityaicloudcloud securitydlpedrgdprprogram managementrisk assessmentsiem

Description

This position is listed on behalf of a partner company, which manages all applications and next steps. Our partner is looking for a Sr. Investigator, Cyber Security based in the United States.

The Senior Cyber Security Investigator will lead and support complex investigations involving cyber incidents, insider threats, data loss, unauthorized disclosures, suspicious user activity, and other sensitive security concerns. This investigation-focused role combines technical analysis, evidence collection, threat assessment, and risk mitigation to help protect critical systems, sensitive information, and business operations. You will correlate technical and behavioral indicators, assess potential threats, and develop clear, defensible findings to guide security decisions. Working closely with Cyber Security, Legal, Human Resources, Compliance, IT, and business leadership, you will help ensure sensitive cases are handled with discretion, consistency, and sound judgment. This position offers the opportunity to strengthen insider-risk detection, improve investigative practices, and reduce human-driven security risks across a complex organization.

Accountabilities

  • Lead Cyber Security Investigations: Manage or support investigations into cyber incidents, insider-risk alerts, data misuse, policy violations, unauthorized disclosures, suspicious user activity, and other sensitive security matters.

  • Triage and Assess Security Alerts: Determine investigation priorities based on risk and business impact, identify affected users and systems, scope suspicious activity, and establish the potential exposure of sensitive data and business processes.

  • Analyze Threats and Incidents: Apply incident response methodologies to investigate suspicious behavior, determine root causes, validate impact, and recommend appropriate containment and remediation measures.

  • Correlate Technical and Behavioral Evidence: Analyze endpoint, network, identity, cloud, email, and user-behavior data to distinguish legitimate activity from security compromise, policy violations, or intentional misuse.

  • Manage Insider Risk: Investigate potential data exfiltration, unauthorized access, abnormal file transfers, misuse of sensitive information, and risky behavior involving employees, contractors, or privileged users.

  • Monitor High-Risk Scenarios: Assess security risks associated with employee departures, role changes, privileged access, high-risk travel, sensitive projects, and repeated policy violations.

  • Use Security and Threat Intelligence Tools: Leverage SIEM, SOAR, EDR, DLP, identity, endpoint, cloud, case management, and threat intelligence platforms to enrich investigations, validate indicators, improve detection, and support proactive risk reduction.

  • Maintain Investigation Records: Document cases from initial intake through closure, including timelines, evidence sources, investigative actions, findings, risk assessments, and mitigation decisions.

  • Preserve Evidence and Confidentiality: Maintain evidence integrity and chain of custody when required, ensuring investigations comply with applicable policies, privacy expectations, legal guidance, and HR direction.

  • Coordinate Cross-Functional Response: Partner with Cyber Security, Legal, HR, Compliance, IT, and business leaders to coordinate escalations, containment, access changes, monitoring, employee-related actions, clean-device workflows, post-travel reviews, and other mitigation measures.

  • Communicate Findings and Recommendations: Prepare clear investigation reports, executive-ready summaries, and actionable recommendations, translating technical findings into business risk language for technical and non-technical stakeholders.

  • Improve Investigation Effectiveness: Contribute to more consistent, defensible case handling, earlier identification of insider threats, stronger evidence collection, better stakeholder reporting, and improved coordination across security and business functions.

  • Requirements:

    • Relevant Professional Experience: Experience in incident response, Security Operations Center (SOC) functions, cyber investigations, threat intelligence, insider-risk investigations, or other sensitive security matters.

    • Advanced Threat Awareness: Experience assessing advanced persistent threat (APT) groups or related threat activity is relevant to the role.

    • Security Tool Proficiency: Hands-on familiarity with SIEM, SOAR, EDR, DLP, case management, identity and access management, endpoint security, cloud security, and threat intelligence platforms.

    • Incident Response Knowledge: Ability to investigate suspicious activity, correlate evidence across multiple data sources, assess root causes and business impact, and recommend proportionate containment or remediation actions.

    • Insider-Risk Investigation Skills: Understanding of indicators associated with data exfiltration, unauthorized access, sensitive information misuse, abnormal user behavior, and privileged-user risk.

    • Evidence Handling and Documentation: Strong skills in evidence collection, preservation, timeline development, case management, and producing accurate, complete, and defensible investigation records.

    • Stakeholder Communication: Demonstrated ability to brief technical and non-technical audiences, including Cyber Security leadership, Legal, HR, Compliance, executives, and business stakeholders.

    • Relevant Security Background: Experience in operational security, information security, personnel security, physical security, intelligence, compliance, or security program management is valuable.

    • Professional Judgment and Discretion: Strong analytical thinking, sound decision-making, confidentiality, attention to detail, and the ability to handle sensitive employee-related matters appropriately.

    • Collaboration and Organization: Excellent written communication, time management, prioritization, and cross-functional collaboration skills, including the ability to manage multiple investigations and competing deadlines.

    • Additional Advantages: Bilingual communication skills and experience working in cleared or highly controlled environments are beneficial.

    • Interview Availability: External candidates may be required to attend an in-person interview at one of the partner company's locations before a hiring decision is made.

    • Equal Opportunity and Accessibility: Qualified applicants are considered in accordance with applicable equal employment opportunity laws. Reasonable accommodations are available for candidates with disabilities who require support during the application or recruitment process.

    • Benefits:

      • Compensation: A good-faith salary range is established for the position in accordance with applicable pay transparency requirements. The specific range was not included in the provided description. Actual compensation may depend on skills, qualifications, experience, and location.

      • Potential Additional Compensation: Additional compensation and benefits may be available, including health insurance, retirement plans, and paid time off; specific eligibility and plan details were not provided.

      • Fair Hiring Practices: Candidates are evaluated in accordance with applicable employment laws and equal opportunity principles.

      • Reasonable Accommodations: Applicants who require disability-related support during recruitment may request reasonable accommodations.

      • Fair Chance Consideration: Where applicable, qualified applicants with criminal histories or arrest or conviction records will be considered in accordance with relevant local and state laws.

How Jobgether works:

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.

We appreciate your interest and wish you the best!

Why Apply Through Jobgether?

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

#LI-CL1

Get similar jobs in United States by email

We'll email you when new jobs similar to this one appear.

Similar jobs

Explore more remote Sr. Investigator, Cyber Security jobs in United States.

Finding similar jobs…