RGA Careers logo
RGA CareersPosted 1 week ago

Staff Insider Risk Engineer

On-siteKuala Lumpur, Kuala Lumpur, Malaysia

Full TimeSenior LevelBachelors DegreeLarge

Job Summary

Participate in a 24/7 on-call rotation, alert triage, and incident investigations to manage and mitigate risks posed by malicious insiders, negligent users, and compromised accounts. Drive Security Operations functions including threat detection, offensive security, and insider risk management by designing monitoring capabilities and developing automation using scripting, APIs, and SOAR technologies. Lead complex investigations across endpoint, identity, email, cloud, and network environments while partnering with Legal, Human Resources, Privacy, and Compliance teams on risk assessments and initiatives. Perform advanced security analysis, threat emulation, and detection validation to strengthen monitoring capabilities, delivering projects, dashboards, and metrics that reduce cyber risk. Provide technical leadership and mentoring to junior team members within a global, purpose-driven reinsurance organization focused on life- and health-related solutions.

Required Qualifications

  • Bachelor's Degree in Arts/Sciences (BA/BS) or equivalent experience
  • 6+ years of experience in cybersecurity, security engineering, security operations, incident response, threat detection, threat hunting, offensive security, or insider threat/risk management
  • 3+ years of experience developing automation, orchestration, and workflows to scale security operations
  • Experience leading complex investigations, incident response activities, forensic analysis, and threat detection initiatives
  • Experience developing security monitoring capabilities, behavioral analytics, metrics, reporting, and addressing telemetry gaps
  • Strong knowledge of insider threat methodologies, security operations, threat detection engineering, identity security, data protection, and cloud security
  • Experience with SIEM, EDR, UEBA, and threat intelligence platforms such as Splunk, Microsoft Sentinel, CrowdStrike, Microsoft Defender, Exabeam, or similar technologies
  • Working knowledge of Windows, Mac, Linux, networking, cloud platforms (AWS, Azure, GCP), identity technologies (Active Directory, Okta, SAML, OAuth, OpenID Connect), email security, and DNS security
  • Proficiency in PowerShell, Python, or similar scripting languages, including API integrations and security automation
  • Strong analytical, investigative, problem-solving, and communication skills, with the ability to work independently in a globally distributed environment

Desired Qualifications

  • Experience leading purple team exercises, threat emulation, or detection validation activities preferred
  • Experience with Microsoft 365 security technologies, including Defender, Entra ID, Purview Insider Risk Management, and Data Loss Prevention (DLP), preferred
  • Understanding of legal, privacy, compliance, and regulatory considerations related to insider risk investigations preferred
  • Professional cybersecurity certifications and industry contributions through conferences, publications, or technical communities preferred

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce