Insider Risk Management Lead
Listed on 2026-01-16
-
IT/Tech
Cybersecurity, Data Security
Overview Who we are
Collaborative. Respectful. A place to dream and do. These are just a few words that describe what life is like one of the world’s most admired brands, Toyota is growing and leading the future of mobility through innovative, high-quality solutions designed to enhance lives and delight those we serve. We’re looking for talented team members who want to Dream. Do. Grow.
with us.
An important part of the Toyota family is Toyota Financial Services (TFS), the finance and insurance brand for Toyota and Lexus in North America. While TFS is a separate business entity, it is an essential part of this world-changing company- delivering on Toyota's vision to move people beyond what's possible. At TFS, you will help create best-in-class customer experience in an innovative, collaborative environment.
To save time applying, Toyota does not offer sponsorship of job applicants for employment-based visas or any other work authorization for this position at this time.
Who We’re Looking ForToyota Financial Services (TFS) Technology team is looking for a highly motivated person to filla roleas
Inside
r
Risk Management Lead
.
Your primary responsibility is to proactively identify, assess, mitigate, and deter risks arising from employee and contractor activity. Operating under the Information Security mandate, you will lead complex insider risk investigations and drive cross-functional remediation with Legal, HR, and Security to reduce organizational risk.
We’relooking for someone who thrives in a high-growth environment and brings deep technicalexpertisealongside strong awareness of the cyber threat landscape – enabling you to detect, investigate, andcontaininsider threats with precision and discretion.
Whatyou’llbe doing- Threat Detection & Analysis: Continuously monitor and assess security alerts generated by insider threat detection systems across on-prem, cloud, and endpoint environments. Analyze system logs, network traffic, authentication records, and application data to identify potential threats.
- Detection Engineering: Design and implement detection rules, scripts, and algorithms to identify anomalous user behaviors indicative of insider threats. Apply advanced correlation techniques to link suspicious activities across multiple data sources and build comprehensive threat narratives.
- Investigation Leadership & Response: Serve as senior analyst during insider threat investigations, coordinating containment and remediation efforts with Legal, HR, and cyber defense teams. Ensure timely and effective resolution of complex cases.
- Process Development & Standardization: Assist in the development and maintenance of standard operating procedures (SOPs) and playbooks that streamline alert triage, investigation, and escalation processes. Continuously refine workflows to improve efficiency and consistency.
- 5+ years of experience in cyber security: anomaly detection, Security Operations Center (SOC) detection and engineering, Data Loss Prevention (DLP), threat hunting and analytics, security incident and event management (SIEM), and incident response.
- Subject matterexpertiseinone or more IRM technologies (e.g.,EUBA,EDR,Email DLP, Cloud DLP, etc.)
- Strong understanding of the insider threat landscape, investigation and risk assessment methodologies, chain of custody requirements, and data protection regulations.
- Excellent communication skillswiththeability to influence stakeholders at all levels.
- A bachelor’s degree in a relevant field (e.g., Cybersecurity,Computer Science, Engineering,Risk Management) or equivalent work experience.
- Experience in a regulated industry (e.g.,finance, healthcare, government)
- Proficiency in programing and query languages (e.g.,Power Shell,Python,SQL,Yara, FQL,KQL,EQL, SPL)
- Familiarity with data loss prevention (DLP) and user behavior analytics (UBA)
- Proficiency in AWS and Azure cloud environments, with a strong understanding of data flows and access management
- Experience in threat detection, incident response, and root-cause analysis in cloud environments.
- Familiarity with eDiscovery and litigation processes.
During your interview process, our…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).