- Company Name
- NorthMark Strategies
- Job Title
- Cyber Defense Engineer - Inside Threat
- Job Description
-
**Job title:** Cyber Defense Engineer – Inside Threat
**Role Summary:**
Design, implement, and maintain enterprise-grade insider threat defenses for a global investment firm. Lead the architecture of Microsoft Purview Insider Risk Management, Data Loss Prevention, and User & Entity Behavior Analytics solutions to protect sensitive information across Microsoft 365 tenants. Collaborate cross‑functionally with HR, Legal, Compliance, and IT to align security policies with business and regulatory requirements.
**Expectations:**
- Deliver scalable insider threat solutions within a multi‑tenant environment.
- Reduce false positive rates while maintaining high detection coverage.
- Provide technical guidance and expertise in threat hunting, incident response, and policy tuning.
- Serve as a subject‑matter expert on insider risk management for internal stakeholders.
**Key Responsibilities:**
1. Architect and optimize Microsoft Purview Insider Risk Management for detection, triage, and response.
2. Build and tune enterprise DLP policies across endpoints, cloud services, and collaboration platforms.
3. Develop insider‑threat use cases using telemetry, behavioral analytics, and UEBA models.
4. Deploy monitoring systems for user behavior, data access patterns, and abnormal workflows.
5. Lead forensic investigations of insider alerts, correlating SIEM, EDR, and DLP data.
6. Configure sensitivity labeling, auto‑labeling, and classification across SharePoint, OneDrive, Teams, and email.
7. Maintain multi‑tenant policy consistency while adhering to regional regulations.
8. Work with Cyber Defense Operations analysts to reduce false positives.
9. Partner with HR, Legal, Compliance, and Business teams to define protected data types and use cases.
**Required Skills:**
- 6+ years cybersecurity engineering or SOC experience.
- Deep expertise with Microsoft Purview Insider Risk Management and DLP policy design.
- Strong knowledge of sensitivity labels, auto‑labeling, and classification.
- Experience managing solutions across multiple Microsoft 365 tenants.
- Familiarity with threat hunting, MITRE ATT&CK framework, and incident response.
- Analytical, problem‑solving, and communication proficiency.
- Ability to translate business requirements into technical security controls.
**Required Education & Certifications:**
- Bachelor’s degree in Cybersecurity, Information Technology, or related field (or equivalent experience).
- Relevant certifications such as Microsoft Certified: Security, Compliance & Identity Fundamentals, or Microsoft 365 Certified: Security Administrator Associate, are preferred.
New york city, United states
Hybrid
Mid level
04-11-2025