Jobs and Careers
AI

Cybersecurity Insider Threat Analyst

Airbus
Spainfull_timeVerifiedPosted 13 Mar 2024

About the role

Job Description:

Summary

A vacancy for a Cyber Insider Threat Analyst in Airbus Detection and Response Department has arisen within Airbus Commercial Aircraft. You will join the Cyber Security Department.

You will be part of an innovation project that has been proven its value to the company and now is in production in a mature team of more than 15 people with different roles and skills, with a solid expertise in the field. 

The project is dedicated to investigate different indicators to build an Insider Threat detection product using Machine Learning algorithms by computing the model in a Cloud platform, from a Cybersecurity perspective. 

Along with the development of an Insider Threat detection product, detection of this type of threat is also performed. 

Job Description

Analyze the results of the Artificial Intelligence algorithms to identify Insiders in the organization, perform searches in the security systems and document the investigated cases.

Design and assist in the development with Cybersecurity expertise, of new and innovative detection capabilities through Artificial Intelligence to detect Insiders (malicious or negligent profiles) within the company.

Assessment of how the detection models behave, evaluate if results are as desired to detect Insiders in pre-production and identify different methods to better evaluate the model. Assess their quality and behavior once put into production in order to detect possible points of improvement. Collect this feedback and be able to deliver it to the development team.

Coordinate the RUN detection team of Insider Protection, attending to the question that the operations have, monitoring its detection quality and creating KPIs for the management. Create procedures, define escalation scenarios, and perform dashboards and reports for investigations. 

Analyze data for its value, verbosity and utility in order to identify Insiders to enhance the product's detection capabilities.

Support in the definition of the product strategy, technical road maps of the future developments, and identify of new different stakeholders. 

Perform Threat Intelligence of Insiders cases to be able to identify actionable Intel to improve the detection capabilities or identify new and innovative ways of detecting this type of threats. 

Analyze the results of the Artificial Intelligence algorithms to identify trends and risky general activities.

Your role

Your role as an Cybersecurity Insider Threat Analyst will be building the followings:

  • Threat Hunting of Insiders with the help of Artificial Intelligence outcomes. 

  • Documentation of the cases and investigations made a Insiders

  • Communicate results of cases and investigations to different profiles: technical, managers, non-security technical personal 

  • Identification of Tactics and Techniques(MITRE TTPs) used by Insiders

  • Definition of detection rules used to identify Insider Risk

  • Assist the Data Scientists in the development of new Machine Learning algorithms

  • Evaluate how the models perform in the detection capabilities in pre-production, and assess the models that are already into production

  • Collect this feedback and delivery it to the Data Scientist to do an action plan for improvements

  • Coordination of the RUN team operators

  • Creation of KPI that are valuable for the management to evaluate the RUN team capabilities

  • Creation of Dashboard and Reports for the operators to investigate, and for the management to monitor the quality

  • Identification and analysis of new data that can add detection quality to the product 

  • Creation and support of a actionable strategy for the product

  • Development of a Technical Roadmap

  • Threat Intelligence to build actionable indicators to identify Insiders

  • Identify threats to deliver a newsletter to other security departments 

Task & accountabilities

As the successful candidate your main tasks & accountabilities are:

# Develop AI detection rules that will allow us to reveal insider threat anomaly 

# You will need to participate in the investigation of the detected suspicious behaviors related to insider threat.

# Ensure the delivery of analysis project end to end from the anomaly case study to the final result analysis restitution into the dashboard and visualization tools.

# Contribute to the evolution and improvement of the Insider Protection product framework. This role will involve regular travel to Toulouse and as such you must be able to travel accordingly. 

Required skills

We are looking for candidates

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Airbus

View company profile →