Cybersecurity Insider Threat Analyst
M&T BankAbout the role
The Bank sponsors individuals for TN and H-1B transfers on a case by case basis. Please note that this position is not open to anyone on an F-1 student visa including those eligible for CPT/OPT or the Stem OPT extension.
This role offers a hybrid work schedule; offering the flexibility to work remotely two days a week, while providing the opportunity for in-person collaboration at our Buffalo, NY Tech Hub.
Overview:
We are seeking a skilled and proactive Cybersecurity Insider Threat Analyst to join our team. In this role, you will focus on detecting, analyzing, and mitigating risks posed by insider threats, whether malicious or accidental, to safeguard the organization’s sensitive information and systems. You will work closely with various departments, including IT, HR, legal, and compliance, to monitor user behavior, identify potential insider threats, and respond to incidents swiftly and effectively.
The ideal candidate has experience in cybersecurity, strong communication skills, experience with threat detection tools, the ability to analyze behavioral data to identify anomalous activities and is comfortable facilitating investigations across key stakeholders.
Primary Responsibilities:
- Continuously monitor user behavior across networks, systems, and applications using User and Entity Behavior Analytics (UEBA) and Security Information and Event Management (SIEM) tools to identify suspicious activities.
- Develop and refine use cases and rules for detecting potential insider threats based on patterns of behavior, unusual access, and data exfiltration.
- Analyze logs, alerts, and security data to detect insider threats in real-time and escalate as necessary.
- Perform detailed investigations into potential insider threats, including the collection and analysis of security logs, employee actions, and access controls.
- Collaborate with Employee Relations, Legal, Digital Forensics, Incident Response, Data Loss Prevention, and other key partners to support insider threat investigations, providing detailed findings and recommendations for remediation.
- Analyze the root cause of insider threat incidents and develop strategies to prevent future occurrences.
- Conduct forensic analysis on systems and data to investigate incidents and build reports on malicious, accidental, or negligent insider activities.
- Participate in risk assessments to identify and prioritize insider threat risks within the organization, developing strategies to mitigate those risks.
- Assist in the development of insider threat risk profiles for employees, contractors, and third-party vendors based on access levels and risk factors.
- Recommend improvements to policies and procedures to reduce the likelihood of insider threats, such as privileged access management and stricter controls on sensitive data access.
- Respond to insider threat incidents by working with cross-functional teams to contain the threat, mitigate damage, and execute recovery efforts.
- Maintain thorough documentation of incident investigations, findings, and remediation actions for future reference and regulatory compliance.
- Provide regular reports to senior management and the Insider Threat Program Manager, outlining trends, threat metrics, and the overall risk posture of the organization.
- Collaborate with other security analysts and engineers to align insider threat monitoring with broader cybersecurity efforts and ensure a holistic security approach.
- Communicate potential insider threat risks and incidents to leadership, ensuring transparency and timely action.
- Help develop and deliver security awareness training focused on insider threats, ensuring employees understand the risks and their role in preventing insider attacks.
- Promote a security-first culture by raising awareness of insider threat behaviors and best practices for data and system security across the organization.
- Stay updated on the latest trends, techniques, and tools related to insider threats and cybersecurity.
- Continuously refine and improve insider threat detection methodologies and tools to enhance the organization's ability to detect, respond to, and prevent threats.
- Conduct post-incident reviews to assess the effectiveness of detection and response processes, recommending improvements for future incidents.
- Understand and adhere to the Company’s risk and regulatory standards, policies and controls in accordance with the Company’s Risk Appetite. Identify risk-related issues needing escalation to management.
- Promote an environment that supports diversity and reflects the M&T Bank brand.
- Maintain M&T internal control standards, including timely implementation of internal and external audit points together with any issues
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s