Engineer IV - Sr. Insider Risk Investigator
Listed on 2026-01-14
-
IT/Tech
Cybersecurity, Data Security
This job posting is anticipated to remain open for 30 days, from 09-Jan-2026. The posting may close early due to the volume of applicants.
Join a financial services firm where your contributions are valued. Edward Jones is a Fortune 500¹ company where people come first. With over 9 million clients and 20,000 financial advisors across the U.S. and Canada, we’re proud to be privately‑owned, placing the focus on our clients rather than shareholder returns.
Behind everything we do is our purpose:
We partner for positive impact to improve the lives of our clients and colleagues, and together, better our communities and society. We are an innovative, flexible, and inclusive organization that attracts, develops, and inspires performance excellence and a sense of belonging.
People are at the center of our partnership. Edward Jones associates are seen, heard, respected, and supported. This is what we believe makes us the best place to start or build your career.
View our Purpose, Inclusion and Citizenship Report.
¹Fortune 500, published June 2024, data as of December 2023. Compensation provided for using, not obtaining, the rating.
Team OverviewThe Digital Insider Risk (DInR) Department protects The Jones Financial Companies, and its subsidiaries (collectively, “the Firm”) against risk stemming from user digital activity. The Digital Insider Risk and Data Loss Prevention (DLP) Analyst will be responsible for monitoring, analyzing, investigating and reporting of User Behavior Analytics and Data Loss Prevention alerts across various tools, ensuring the protection of client and Firm data.
You will work closely with security analysts, engineers, and other IT professionals to enhance our security posture through the development and refinement of detection and enforcement rules.
- Monitor, triage, investigate, and escape UEBA and DLP alerts from multiple systems (e.g., Gurucul, XSOAR, Microsoft Purview, Proofpoint, Zscaler).
- Quickly and accurately determine the level of urgency and escalate or investigate as necessary.
- Lead high‑priority incident response activities related to insider risk and critical data exfiltration events.
- Assist in performing activities necessary for immediate containment and long‑term resolution of events and incidents.
- Perform initial analysis of data from a variety of sources (to include but not limited to host, network, cloud, messaging, application), correlating it to meaningful DLP and Insider Risk events.
- Support confidential and complex digital investigations.
- Generate informed reporting around security events and metrics.
- Document investigations in adherence to all audit and legal requirements.
- Support the development of documentation in support of response processes and/or procedures.
- Analyze incidents for patterns of data misuse or exfiltration across email, endpoints, cloud, and web.
- Assist in rule development, tuning, and testing of DLP policies to reduce false positives and improve detection efficacy.
- Provide mentorship and guidance to junior analysts, fostering a culture of continuous learning and professional development.
- Develop threat models and use cases to proactively identify emerging insider risks.
- Minimum of 5 years in Information Systems Security or Information Technology with a focus on security controls and processes.
- Possession of a recognized, advanced security certification.
- Proven experience enhancing an enterprise level Data Loss Prevention program (e.g., Microsoft Purview, Symantec, Trellix, Proofpoint).
- Demonstrated expertise in conducting digital forensic analysis and evidence collection across various operating systems and cloud platforms.
- Proven ability to define and utilize UEBA models to detect complex, non‑signature based risks.
- Experience triaging, investigating and assisting remediation of security alerts.
- Familiarity with various cybersecurity tools and how to leverage them effectively (e.g., SIEM, SOAR, UEBA, DLP).
- Familiarity with enterprise data types and sensitivity levels: PII, PHI, PCI, IP, financial data, insider risk indicators.
- Strong technical understanding of security controls and data protection mechanisms within…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).