Director, Insider Threat
CLS GroupAbout the role
About CLS:
CLS is the trusted party at the centre of the global FX ecosystem. Utilized by thousands of counterparties, CLS makes FX safer, smoother and more cost effective. Trillions of dollars’ worth of currency flows through our systems each day.
Created by the market for the market, our unrivalled global settlement infrastructure reduces systemic risk and provides standardization for participants in many of the world’s most actively traded currencies. We deliver huge efficiencies and savings for our clients: in fact, our approach to multilateral netting shrinks funding requirements by over 96% on average, so clients can put their capital and resources to better use.
CLS products are designed to enable clients to manage risk most effectively across the full FX lifecycle – whether through more efficient processing tools or market intelligence derived from the largest single source of FX executed data available to the market.
Our ambition to make a positive difference starts with our people. Our values – Protect, Improve, Grow – underpin everything that we do at CLS and define and shape a supportive and inclusive working environment in which everyone is encouraged to be open and forward-thinking.
Job purpose
CLS is seeking a highly motivated, and skilled Director to lead our Insider Threat Team. The role will be located in New York City or Metropark NJ. The position will report to the Deputy CISO and will be responsible for leading the development, implementation, and continuous improvement of a new Insider Threat team. This role involves overseeing the identification, prevention, and response to risks posed by individuals with authorized access to organizational assets, including employees, contractors, and third-party vendors. The position will require collaboration with cross-functional teams to mitigate the risks of malicious, negligent, or unintentional insider actions that could lead to security breaches, data loss, or reputational damage. This role will also be responsible for mentoring others on the team.
This position requires someone with an analytical mind, a quick learner, and the ability to create and deliver briefings, propose, and execute program initiative’s/improvements, and collaborate with a wide range of key stakeholders.
Job Description
- Lead the insider threat program, including the development of standards, procedures, and processes to detect, prevent, and respond to insider threats
- Drive continuous improvement by integrating lessons learned, industry best practices, and emerging threat intelligence
- Utilize advanced detection tools, behavioral analytics, and security monitoring systems
- Collaborate with stakeholders across the firm to evaluate and address potential insider risks across systems, networks, and organizational processes
- Lead and manage investigations of suspected insider threat incidents, ensuring that investigations are thorough, timely, and conducted in accordance with legal and regulatory requirements
- Produce reports on insider threat risks, incidents, and mitigation efforts for executives to aid in their decision making
- Work with the intelligence team to develop threat modeling deliverables
Experience
- 6-10+ years of progressive experience in information security (cyber security) field, preferable in Security Operations, Incident Response, or Threat Intelligence roles
- 5+ years of experience in Insider Threat
- Experience with insider threat detection tools (UEBA, DLP, SIEM) and knowledge of advanced threat intelligence techniques
- Knowledge of fundamentals of threat actors’ TTPs and MITRE ATT&CK Framework
- Understanding of security frameworks, incident response, and risk management practice
- Knowledge of relevant legal and regulatory considerations, including privacy laws an data protection requirements
- Excellent interpersonal and relationship management skills
Qualifications/Certifications
- Bachelor’s Degree in Cybersecurity studies, Computer Science, Intelligence Studies, International Relations, or related discipline
- Security certification such as CERT Insider Threat Program Manager (ITPM) Certificate (or equivalent) ideally or working towards certification (or equivalent)
- Experience with threat intelligence and SOC/CIRT interaction
- Splunk experience is highly preferred
- Expertise in managing complex investigations, coordinating with multiple departments, and resolving security incidents efficiently
- Strong written and verbal communication skills
- Ability to work on-site at least twice a week in New York and/or participate in local intelligence sharing groups
Desired Sk
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s