Insider Risk Analyst
As an Insider Risk Analyst at Lam Research, you will play a critical role in helping manage insider risk investigations and helping to build out our insider risk capabilities. Your responsibilities will include analyzing and investigating anomalous user activities, indicators, and providing support to active incidents alongside our most valuable stakeholders. You may be asked to support cross-functional opportunities across Lam Research to help identify security trends and metrics, develop innovative use cases designed to detect anomalous events, and support education and awareness campaigns for insider risks and threats. You will use sophisticated technology and robust partnerships to enhance our insider risk posture against nation-state actors, negligent and malicious employee activity, and support high-risk populations from potential compromise. You will play avital role in taking the Lam Research Insider Risk program to the next level by being both an analytical and technical expert on our team.
Job Responsibilities:
- Drive triage, investigation, and support management of insider risk cases.
- Identify, collect, and analyze technical and non-technical indicators from a variety of sources.
- Coordinate investigation and mitigation strategies with Insider Risk team’s management and colleagues, as well as additional internal stakeholders.
- Leverage your analytical and technical skills to identify patterns and trends and make recommendations to enhance detective and preventive controls.
- Perform log analysis and coordinate/perform event queries across enterprise systems.
- Operationalize and maintain the processes and playbooks required for insider risk analysis and support the development and execution of any new processes and playbooks.
- Leverage subject matter expertise to educate stakeholders on the importance of data and information sharing to protect and enable the business.
- Ensure investigative findings are documented, as needed.
- Support process improvement initiatives and provide project related support for the Insider Risk program.
- Respond to requests for ad-hoc support, reporting, and research topics from management and stakeholders, as required.
- Must be able to maintain confidentiality and always use sound discretion and judgment.
Minimum Qualifications
- Bachelor’s degree or Advanced Degree in Cybersecurity, Information Security, Counterintelligence, or related discipline.
- 4+ years of experience in an Insider Risk role.
- Korean fluency required (additional language abilities preferred).
- Experience working Insider Risk investigations directly and/or providing analysis to Insider Risk investigations beyond alert triage.
- Ability to read, interpret, and identify anomalies within system, network, and application logs.
- Proficiency in querying, analyzing, and parsing unstructured log data to identify complex behavioral patterns.
- Experience monitoring and responding to alerts and investigations.
- Basic knowledge of malicious insider risk indicators, such as those associated with theft of intellectual property, sabotage, and/or espionage.
- Proficiency utilizing security-related tools, to include UEBA, UAM, and DLP experience.
- Working knowledge of investigation processes and techniques, leveraging technical and non-technical indicators and ability to prescribe best practices with our stakeholders.
- Excellent written and verbal communication skills with the ability to communicate professionally with team members, stakeholders, and senior leadership, as needed.
- Strong aptitude for identifying and learning new technologies.
- Ability to adapt to a fast-paced and evolving environment.
- A self-motivated person that can use their creative and experience-driven analytical skills to solve problems.
Preferred Qualifications
- Formal education and training in insider risk and/or counterintelligence.
- Possession of investigative interviewing skills to gather context from employees, managers, and witnesses during internal investigations.
- Proficiency in identifying insider threats using a multitude of sources.
- Ability to break down and understand complex problems and the ability to develop a plan and innovative ways to address them.
- Strong people and team/relationship building skills in cross-functional global team settings.
- Demonstrated ability to collaborate with wider security, counterintelligence, and insider risk professional communities.