内部威胁工程师
查看雇主原标题
Insider Threat EngineerCloudflare · Hybrid
职位信息来自雇主公开的招聘页面。申请前请务必在雇主官网核实详情。
为什么值得关注?
发现指数 52/100,仅依据与该职位一起存储的证据计算。
- 新的雇主官方职位
- 远程职位
分数构成
- 时效性 (随职位发布时间变化)+18
- 雇主官方来源+15
- 远程职位+8
- 稀有职位+3
- 公司来源健康度+8
该职位未包含:已披露薪资、提及签证担保、提及搬迁、未出现在监控的职位板上。
这些理由来自雇主自己的职位描述与我们核实过的来源检查结果。除了已存储的信号之外,我们不做任何推测。
职位描述
机器翻译关于我们
在 Cloudflare,我们的使命是帮助构建更好的互联网。如今,公司运营着全球最大的网络之一,为从个人博主到中小企业再到《财富》500 强企业的客户提供支持,驱动着数百万个网站和其他互联网资产。Cloudflare 无需添加硬件、安装软件或更改一行代码,即可保护和加速任何在线互联网应用。由 Cloudflare 驱动的互联网资产,其网络流量都会通过其智能全球网络进行路由,而该网络会随着每一次请求变得更加智能。因此,它们的性能显著提升,垃圾邮件和其他攻击也减少了。Cloudflare 曾入选《Entrepreneur》杂志的顶级公司文化榜单,并被《Fast Company》评为全球最具创新力公司之一。
在 Cloudflare,我们寻找的不是等待一份完美路线图的人;我们寻找的是那些看到互联网裂缝、而其他人却只是学会与之共处的建设者。我们看重那些有直觉发现“被正常化”的问题,并具备 AI 原生好奇心、能够利用最新工具创造解决方案的候选人。我们的文化建立在迭代之上,利用 AI 在今天更快交付,让明天更好,同时确保每一项改进,无论多小,都在团队中共享,以提升每个人。如果你是那种重视好奇心而非官僚作风,并且认为 AI 是解决棘手问题、推动互联网前进的伙伴的人,你会非常适合这里。
可选工作地点:Austin
关于该职位
我们正在寻找一位技术精湛、经验丰富的内部威胁技术负责人,加入我们充满活力且不断壮大的安全威胁检测、响应与模拟团队。这是一个关键职位,将站在保护公司免受恶意和疏忽内部人员活动的最前沿。你将负责领导我们内部威胁计划的技术方面,包括调查、威胁狩猎,以及开发前沿的检测和响应能力。
该职位需要技术专长、监管和法律知识、调查技能以及强大的人际沟通能力的独特结合。你将成为我们隐私、法律、GRC 和 HR 团队的关键联系人和协作者,确保所有活动都以最高谨慎进行,符合公司政策,并遵守法律和道德标准。
你将做什么
• 领导内部威胁数字调查: • • 独立并与我们的事件响应团队合作,对潜在的内部威胁事件进行全面技术调查,包括数据外泄、知识产权盗窃、未经授权访问和其他恶意活动。
• 具备从各种来源(例如端点、网络日志、云服务、电子邮件等)收集、保存和分析数字证据的知识和执行经验。
• 以清晰、简洁且可辩护的方式记录所有调查步骤和发现。
• 以专业和客观的方式向高级领导层和跨职能合作伙伴(法律、HR、隐私)展示调查结果。
• 确保在所有环节满足监管、法律和隐私要求
• 内部威胁狩猎: • 使用各种安全工具和数据源(例如 SIEM、DLP、EDR、UEBA)主动狩猎内部威胁。
• 基于新兴威胁、攻击技术以及对我们公司独特环境的理解,制定并执行威胁狩猎假设。
• 关联分散的数据点,以识别异常或可疑的用户行为
岗位职责
我们正在寻找一位技术精湛、经验丰富的内部威胁技术负责人,加入我们充满活力且不断壮大的安全威胁检测、响应与模拟团队。这是一个关键职位,将站在保护公司免受恶意和疏忽内部人员活动的最前沿。你将负责领导我们内部威胁计划的技术方面,包括调查、威胁狩猎,以及开发前沿的检测和响应能力。
该职位需要技术专长、监管和法律知识、调查技能以及强大的人际沟通能力的独特结合。你将成为我们隐私、法律、GRC 和 HR 团队的关键联系人和协作者,确保所有活动都以最高谨慎进行,符合公司政策,并遵守法律和道德标准。
• 领导内部威胁数字调查: • • 独立并与我们的事件响应团队合作,对潜在的内部威胁事件进行全面技术调查,包括数据外泄、知识产权盗窃、未经授权访问和其他恶意活动。
• 具备从各种来源(例如端点、网络日志、云服务、电子邮件等)收集、保存和分析数字证据的知识和执行经验。
• 以清晰、简洁且可辩护的方式记录所有调查步骤和发现。
• 以专业和客观的方式向高级领导层和跨职能合作伙伴(法律、HR、隐私)展示调查结果。
• 确保在所有环节满足监管、法律和隐私要求
• 内部威胁狩猎: • 使用各种安全工具和数据源(例如 SIEM、DLP、EDR、UEBA)主动狩猎内部威胁。
• 基于新兴威胁、攻击技术以及对我们公司独特环境的理解,制定并执行威胁狩猎假设。
• 关联分散的数据点,以识别异常或可疑的用户行为。
• 检测与响应改进: • 与安全事件响应团队(SIRT)和威胁检测团队紧密合作,持续增强我们的内部威胁检测能力。
• 在我们的安全工具中设计、开发并实施新的规则、警报和用例,以识别内部威胁指标。
• 评估并推荐新技术和流程,以成熟化我们的内部威胁计划。
• 为各种内部威胁场景制定并完善响应手册。
• 跨职能协作: • 作为内部威胁计划的主要技术联络人,与法律、HR 和隐私团队建立牢固、可信的关系。
• 与这些团队步调一致地合作,确保调查以敏感、尊重员工隐私并在法律和道德准则范围内进行。
• 在政策制定和事件响应规划期间提供技术专长和指导。
必备资格:
• 5 年以上技术安全岗位经验,其中至少 2 年以上专注于内部威胁、数字取证或安全调查。
• 具备开展和领导复杂技术调查的成熟经验,包括使用取证工具(例如 EnCase、FTK、X-Ways 或开源替代方案)。
• 深入理解安全技术,如 SIEM(例如 Splunk、Elastic)、EDR(例如 CrowdStrike、SentinelOne)以及 UEBA 类数据源。
• 强大的脚本和编程技能(例如 Python、PowerShell),以自动化任务并分析大型数据集。
• 出色的书面和口头沟通能力,能够向非技术受众解释复杂的技术概念。
• 具备与法律和 HR 团队合作处理敏感员工相关事务的经验。
任职要求
• 持有 GCIH、GCFA、GCTI 或类似认证。
• 具备云安全和云调查经验(例如 AWS、GCP、Azure)。
• 有技术产品或快节奏初创企业环境的先前经验。
• 了解与数据隐私和数字证据相关的法律和监管框架(例如 GDPR、CCPA)。
• 法律/法庭证据处理、展示和程序实施
Cloudflare 有何特别之处?
我们不仅仅是一家雄心勃勃的大型科技公司。我们是一家雄心勃勃、规模庞大且拥有灵魂的科技公司。我们帮助构建更好互联网使命的根本,是保护自由开放的互联网。
Project Galileo :自 2014 年以来,我们已为 111 个国家的 2,400 多个新闻和公民社会组织配备了强大的工具,以抵御那些否则会审查其工作的攻击,这些技术已被 Cloudflare 的企业客户使用——而且是免费提供。
Athenian Project :2017 年,我们创建了 Athenian Project,以确保州和地方政府免费获得最高级别的保护和可靠性,使其选民能够获取选举信息和选民登记。自该项目以来,我们已为 33 个州的 425 多个地方政府选举网站提供服务。
1.1.1.1 :我们发布了 1.1.1.1,通过构建更快、更安全且以隐私为中心的公共 DNS 解析器,帮助修复互联网的基础。这公开供所有人使用——这是 Cloudflare 发布的首个面向消费者的服务。事情是这样的——我们永远不会存储客户端 IP 地址。我们将继续遵守我们的隐私承诺,并确保不会将任何用户数据出售给广告商或用于定向消费者。
听起来像是你想参与的事情?我们很乐意听到你的消息!
请注意,进入面试流程录用阶段的申请人可能会被要求参加 Cloudflare 办公室或 Cloudflare Hub 之一的现场面试。有关此事的更多细节将在面试流程的该阶段提供。
该职位可能需要访问受美国出口管制法律保护的信息,包括美国出口管理条例。请注意,任何录用通知都可能以你在无需申请出口许可证赞助的情况下获准接收受这些美国出口法律管制的软件或技术为条件。
Cloudflare 自豪地成为提供平等机会的雇主。我们致力于为所有人提供平等的就业机会,并高度重视多样性和包容性。所有合格申请人都会获得就业考虑,不因其或任何其他人的感知或实际种族、肤色、宗教、性别、性别认同、性别表达、性取向、国籍、血统、公民身份、年龄、身体或精神残疾、医疗状况、家庭照护状况或任何其他受法律保护的基础而受到歧视。我们是 AA/退伍军人/残障人士雇主。
Cloudflare 为符合条件的残障人士提供合理便利。如果你在申请工作时需要合理便利,请告诉我们。合理便利的示例包括但不限于更改申请流程、以替代格式提供文件、使用手语翻译或使用专业设备。如果你在申请工作时需要合理便利,请通过电子邮件 hr@cloudflare.com 联系我们,或通过邮寄至 101 Townsend St. San Francisco, CA 94107 联系我们。
以上内容由机器翻译自动生成,可能存在错误;投递前请以雇主原文为准。
查看雇主原文
职位描述
About Us
At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world’s largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to SMBs to Fortune 500 companies. Cloudflare protects and accelerates any Internet application online without adding hardware, installing software, or changing a line of code. Internet properties powered by Cloudflare all have web traffic routed through its intelligent global network, which gets smarter with every request. As a result, they see significant improvement in performance and a decrease in spam and other attacks. Cloudflare was named to Entrepreneur Magazine’s Top Company Cultures list and ranked among the World’s Most Innovative Companies by Fast Company.
At Cloudflare, we’re not looking for people who wait for a polished roadmap; we’re looking for the builders who see the cracks in the Internet that everyone else has simply learned to live with. We value candidates who have the instinct to spot a "normalized" problem and the AI-native curiosity to create a solution using the latest tools. Our culture is built on iteration, leveraging AI to ship faster today to make it better tomorrow, while ensuring that every improvement, no matter how small, is shared across the team to lift everyone up. If you’re the type of person who values curiosity over bureaucracy, and that AI is a partner in solving tough problems to keep the Internet moving forward, you’ll fit right in.
Available Locations: Austin
About the role
We are seeking a highly skilled and experienced Insider Threat Tech Lead to join our dynamic and growing Security Threat Detection, Response and Emulation team. This is a critical role that will be at the forefront of protecting our company from malicious and negligent insider activities. You will be responsible for leading the technical aspects of our Insider Threat program, including investigations, threat hunting, and the development of cutting-edge detections and responses.
This role requires a unique blend of technical expertise, regulatory and legal knowledge, investigative skills, and strong interpersonal communication. You will be a key point of contact and collaborator with our Privacy, Legal, GRC and HR teams, ensuring that all activities are conducted with the utmost care, in accordance with company policy, and in compliance with legal and ethical standards.
What you'll do
• Lead Insider Threat Digital Investigations: • • Conduct comprehensive technical investigations individually and partnering with our incident response teams into potential insider threat incidents, including data exfiltration, intellectual property theft, unauthorized access, and other malicious activities.
• Knowledge and execution experience in collecting, preserving , and analyzing digital evidence from a variety of sources (e.g., endpoints, network logs, cloud services, email, etc.).
• Document all investigative steps and findings in a clear, concise, and defensible manner.
• Present findings to senior leadership and cross-functional partners (Legal, HR, Privacy) in a professional and objective manner.
• Ensuring regulatory, legal and privacy requirements are met through all
• Insider Threat Hunting: • Proactively hunt for insider threats using a variety of security tools and data sources (e.g., SIEM, DLP, EDR, UEBA).
• Develop and execute threat hunting hypotheses based on emerging threats, attack techniques, and an understanding of our company's unique environment.
• Correlate disparate data points to identify anomalous or suspicious user behavior
岗位职责
We are seeking a highly skilled and experienced Insider Threat Tech Lead to join our dynamic and growing Security Threat Detection, Response and Emulation team. This is a critical role that will be at the forefront of protecting our company from malicious and negligent insider activities. You will be responsible for leading the technical aspects of our Insider Threat program, including investigations, threat hunting, and the development of cutting-edge detections and responses.
This role requires a unique blend of technical expertise, regulatory and legal knowledge, investigative skills, and strong interpersonal communication. You will be a key point of contact and collaborator with our Privacy, Legal, GRC and HR teams, ensuring that all activities are conducted with the utmost care, in accordance with company policy, and in compliance with legal and ethical standards.
• Lead Insider Threat Digital Investigations: • • Conduct comprehensive technical investigations individually and partnering with our incident response teams into potential insider threat incidents, including data exfiltration, intellectual property theft, unauthorized access, and other malicious activities.
• Knowledge and execution experience in collecting, preserving , and analyzing digital evidence from a variety of sources (e.g., endpoints, network logs, cloud services, email, etc.).
• Document all investigative steps and findings in a clear, concise, and defensible manner.
• Present findings to senior leadership and cross-functional partners (Legal, HR, Privacy) in a professional and objective manner.
• Ensuring regulatory, legal and privacy requirements are met through all
• Insider Threat Hunting: • Proactively hunt for insider threats using a variety of security tools and data sources (e.g., SIEM, DLP, EDR, UEBA).
• Develop and execute threat hunting hypotheses based on emerging threats, attack techniques, and an understanding of our company's unique environment.
• Correlate disparate data points to identify anomalous or suspicious user behaviors.
• Detection & Response Improvement: • Collaborate closely with the Security Incident Response Team (SIRT) and Threat Detection teams to continuously enhance our insider threat detection capabilities.
• Design, develop, and implement new rules, alerts, and use cases in our security tools to identify insider threat indicators.
• Evaluate and recommend new technologies and processes to mature our Insider Threat program.
• Develop and refine response playbooks for various insider threat scenarios.
• Cross-Functional Collaboration: • Serve as the primary technical liaison for the Insider Threat program, building strong, trusted relationships with Legal, HR, and Privacy teams.
• Work in lockstep with these teams to ensure that investigations are conducted with sensitivity, respect for employee privacy, and within legal and ethical guidelines.
• Provide technical expertise and guidance during policy development and incident response planning.
Required Qualifications:
• 5+ years of experience in a technical security role, with at least 2+ years focused on insider threat, digital forensics, or security investigations.
• Proven experience in conducting and leading complex technical investigations, including the use of forensic tools (e.g., EnCase, FTK, X-Ways, or open-source alternatives).
• Deep understanding of security technologies such as SIEM (e.g., Splunk, Elastic), EDR (e.g., CrowdStrike, SentinelOne), and UEBA like data sources.
• Strong scripting and programming skills (e.g., Python, PowerShell) to automate tasks and analyze large datasets.
• Excellent communication skills, both written and verbal, with the ability to explain complex technical concepts to non-technical audiences.
• Experience working with legal and HR teams on sensitive employee-related matters.
任职要求
• Certifications such as GCIH, GCFA, GCTI, or similar.
• Experience with cloud-based security and investigations (e.g., AWS, GCP, Azure).
• Prior experience in a tech product or fast-paced startup environment.
• Knowledge of legal and regulatory frameworks related to data privacy and digital evidence (e.g., GDPR, CCPA).
• Legal/Court evidence handling, presentation and implementation of procedures
What Makes Cloudflare Special?
We’re not just a highly ambitious, large-scale technology company. We’re a highly ambitious, large-scale technology company with a soul. Fundamental to our mission to help build a better Internet is protecting the free and open Internet.
Project Galileo : Since 2014, we've equipped more than 2,400 journalism and civil society organizations in 111 countries with powerful tools to defend themselves against attacks that would otherwise censor their work, technology already used by Cloudflare’s enterprise customers--at no cost.
Athenian Project : In 2017, we created the Athenian Project to ensure that state and local governments have the highest level of protection and reliability for free, so that their constituents have access to election information and voter registration. Since the project, we've provided services to more than 425 local government election websites in 33 states.
1.1.1.1 : We released 1.1.1.1 to help fix the foundation of the Internet by building a faster, more secure and privacy-centric public DNS resolver. This is available publicly for everyone to use - it is the first consumer-focused service Cloudflare has ever released. Here’s the deal - we don’t store client IP addresses never, ever. We will continue to abide by our privacy commitment and ensure that no user data is sold to advertisers or used to target consumers.
Sound like something you’d like to be a part of? We’d love to hear from you!
Please note that applicants who progress to the offer stage of the interview process may be asked to attend an in-person interview within one of the Cloudflare Offices or Cloudflare Hubs. More details about this will be available at that stage of the interview process.
This position may require access to information protected under U.S. export control laws, including the U.S. Export Administration Regulations. Please note that any offer of employment may be conditioned on your authorization to receive software or technology controlled under these U.S. export laws without sponsorship for an export license.
Cloudflare is proud to be an equal opportunity employer. We are committed to providing equal employment opportunity for all people and place great value in both diversity and inclusiveness. All qualified applicants will be considered for employment without regard to their, or any other person's, perceived or actual race, color, religion, sex, gender, gender identity, gender expression, sexual orientation, national origin, ancestry, citizenship, age, physical or mental disability, medical condition, family care status, or any other basis protected by law. We are an AA/Veterans/Disabled Employer.
Cloudflare provides reasonable accommodations to qualified individuals with disabilities. Please tell us if you require a reasonable accommodation to apply for a job. Examples of reasonable accommodations include, but are not limited to, changing the application process, providing documents in an alternate format, using a sign language interpreter, or using specialized equipment. If you require a reasonable accommodation to apply for a job, please contact us via e-mail at hr@cloudflare.com or via mail at 101 Townsend St. San Francisco, CA 94107.