Chainlink Labs is the industry-standard oracle platform bringing the capital markets onchain and powering the majority of decentralized finance (DeFi). The Insider Trust Team (ITT) Senior Security Engineer will lead efforts in identifying, investigating, and mitigating security policy violations, focusing on automation and scalable infrastructure to enhance security measures.
Responsibilities:
- Own and lead building out the Insider Trust Team’s infrastructure to engineer and automate end-to-end detection and investigation workflows
- Develop, measure, and tune detection rules in Sigma to ensure effective and sustainable operations
- Drive projects with a focus on Insider Risks, ranging from access abuse and intellectual property theft, to novel risks emerging within the blockchain/Web3 space
- Work closely with cross-functional teams, including Threat Management, People, Legal, IT, and Engineering, and provide technical expertise and evidence to lead insider investigations
- Assist in conducting sensitive interviews during insider threat investigations, bringing your technical subject matter expertise to support fact finding
- Proactively identify and implement areas of improvement and modernization
Requirements:
- 7+ years of experience conducting technical investigations and working in an Insider Threat capacity. We are seeking senior candidates
- Deep experience in macOS focused environments, including log collection, log analysis, digital investigations, and forensics
- Knowledge of Insider Threat tactics and attack paths, data exfiltration techniques, and experience running and leading insider incidents independently and as part of a team
- Broad familiarity with Insider Threat investigations of modern cloud infrastructure
- Strong critical thinking skills, as well as integrity, objectivity, and maturity
- Prior success in remote-first environments as a self-starter Insider Threat security engineer
- Previous scripting experience (Python, Bash, or similar) to include scripting for data parsing/enrichment and automations
- Experience with detection‑as‑code development and workflows in Sigma
- Collaborative, straightforward communication skills with the ability to write clear incident updates and summaries. Ability to explain risk, impact, and trade‑offs to both technical and non‑technical stakeholders and have a proven record of building trust with partner teams during high‑pressure situations
- Domain experience with blockchain/Web3 threats
- Usage of AI technology to augment and enhance Insider Threat investigations
- Open-source contributions to security related projects, with a focus on Insider Threat