Consultant, Insider Threat Enterprise Cyber Security Full Time, Springfield MA (Hybrid) The Opportunity MassMutual is advancing an enterprise Insider Threat program focused on identifying and managing human-driven cyber risk. The Insider Threat Consultant will play a key role in developing the asset intelligence, monitoring strategies, detection capabilities, and investigative processes necessary to identify and manage insider-driven risk. This role combines deep technical expertise, critical asset analysis, behavioral risk assessment, and investigative discipline to understand how people interact with sensitive assets and to identify patterns of activity that may indicate elevated risk. The consultant will partner with cybersecurity operations, detection engineering, HR, Legal, Privacy, and business stakeholders to align monitoring and investigative capabilities with asset sensitivity and business impact. This position is suited for an experienced practitioner who can operate across technical, analytical, and investigative domains while helping build and mature an enterprise-scale insider threat program. The Team The Insider Threat team is a specialized cybersecurity function responsible for understanding and managing the risks that trusted individuals may pose to MassMutual's critical assets, systems, information, and operations. The team operates at the intersection of critical asset protection, identity and access management, behavioral analytics, cyber defense, investigations, and workforce risk. Team members develop the intelligence, monitoring strategies, detection capabilities, investigative processes, and analytical frameworks necessary to identify and reduce insider-driven risk. The team partners closely with Cyber Operations, Detection Engineering, Human Resources, Legal, Privacy, Compliance, Fraud Operations, and business stakeholders to ensure insider risk is identified, assessed, and managed in a consistent, defensible, and risk-informed manner. The Impact The Insider Threat Consultant will: Identify and prioritize critical assets requiring enhanced monitoring and protection. Analyze how critical assets are accessed, used, and shared across the enterprise. Map relationships between identities, access privileges, business processes, and critical assets. Analyze behavioral and technical indicators associated with insider risk. Identify patterns of activity that may indicate misuse or mishandling of critical assets. Conduct and support complex insider threat investigations. Correlate identity, access, asset, and behavioral signals across multiple data sources. Monitor and analyze deception environments and adversary interaction signals. Partner with detection engineering and security operations to develop and refine insider threat detection logic. Contribute to tuning enterprise security tooling to improve identification of insider-driven risk. Support development of early-warning frameworks and proactive risk identification. Produce clear, defensible analytical findings and case documentation. Support executive reporting and enterprise risk visibility. The consultant's work will improve visibility into critical assets, strengthen understanding of user-to-asset trust relationships, increase the fidelity of insider threat detections, and help prevent compromise of the confidentiality, integrity, and availability of MassMutual's most important information and systems. The Minimum Qualifications 8+ years of experience in cybersecurity, insider threat, investigations, intelligence analysis, data protection, enterprise architecture, or related disciplines. 2+ years of experience working cross-functionally with security, HR, Legal, Privacy, business, or investigative stakeholders. Preferred Qualifications Experience supporting or building an Insider Threat Program. Experience supporting Critical Asset Protection, Information Protection, Data Protection, or Human Risk Management initiatives. Experience conducting cyber, digital, fraud, employee misconduct, or insider threat investigations. Experience analyzing logs, endpoint telemetry, identity activity, access patterns, and behavioral signals. Hands-on experience contributing to detection use cases, monitoring strategies, investigative workflows, or security content development. Experience identifying, classifying, mapping, or protecting sensitive information or critical assets. Strong understanding of identity and access management concepts, privileged access, trust relationships, and access governance. Experience with SIEM, EDR, UEBA, DLP, insider risk management, identity security, and security analytics platforms. Experience developing, tuning, or validating detection logic across endpoint, identity, network, and data protection technologies. Experience analyzing user behavior and identifying anomalous or high-risk activity through the correlation of multiple data sources. Familiarity with deception technologies, cyber deception strategies, or adversary engagement techniques. Experience supporting highly regulated environments such as financial services. Professional certifications such as CISSP, CISM, GIAC, CDLP, GCFA, GCIH, or equivalent. Degree in cybersecurity, intelligence studies, psychology, criminal justice, information systems, or related field. What You Can Expect at MassMutual MassMutual offers the opportunity to do meaningful work within a purpose-driven organization that values long-term impact over short-term outcomes. In this role, you can expect: Clear areas of ownership and accountability, with work that connects directly to company and customer outcomes A collaborative environment where perspectives are welcomed Access to learning, development, and internal networks that support continuous growth and skill-building over time Employee-led communities and forums that foster connection, learning, and inclusion across the organization A culture grounded in integrity, responsibility, and stewardship-supported by a company with a strong legacy and a future-focused mindset MassMutual is an equal employment opportunity employer. We welcome all persons to apply. If you need an accommodation to complete the application process, please contact us and share the specifics of the assistance you need. California residents: For detailed information about your rights under the California Consumer Privacy Act (CCPA), please visit our California Consumer Privacy Act Disclosures page.
09/07/2026
Full time
Consultant, Insider Threat Enterprise Cyber Security Full Time, Springfield MA (Hybrid) The Opportunity MassMutual is advancing an enterprise Insider Threat program focused on identifying and managing human-driven cyber risk. The Insider Threat Consultant will play a key role in developing the asset intelligence, monitoring strategies, detection capabilities, and investigative processes necessary to identify and manage insider-driven risk. This role combines deep technical expertise, critical asset analysis, behavioral risk assessment, and investigative discipline to understand how people interact with sensitive assets and to identify patterns of activity that may indicate elevated risk. The consultant will partner with cybersecurity operations, detection engineering, HR, Legal, Privacy, and business stakeholders to align monitoring and investigative capabilities with asset sensitivity and business impact. This position is suited for an experienced practitioner who can operate across technical, analytical, and investigative domains while helping build and mature an enterprise-scale insider threat program. The Team The Insider Threat team is a specialized cybersecurity function responsible for understanding and managing the risks that trusted individuals may pose to MassMutual's critical assets, systems, information, and operations. The team operates at the intersection of critical asset protection, identity and access management, behavioral analytics, cyber defense, investigations, and workforce risk. Team members develop the intelligence, monitoring strategies, detection capabilities, investigative processes, and analytical frameworks necessary to identify and reduce insider-driven risk. The team partners closely with Cyber Operations, Detection Engineering, Human Resources, Legal, Privacy, Compliance, Fraud Operations, and business stakeholders to ensure insider risk is identified, assessed, and managed in a consistent, defensible, and risk-informed manner. The Impact The Insider Threat Consultant will: Identify and prioritize critical assets requiring enhanced monitoring and protection. Analyze how critical assets are accessed, used, and shared across the enterprise. Map relationships between identities, access privileges, business processes, and critical assets. Analyze behavioral and technical indicators associated with insider risk. Identify patterns of activity that may indicate misuse or mishandling of critical assets. Conduct and support complex insider threat investigations. Correlate identity, access, asset, and behavioral signals across multiple data sources. Monitor and analyze deception environments and adversary interaction signals. Partner with detection engineering and security operations to develop and refine insider threat detection logic. Contribute to tuning enterprise security tooling to improve identification of insider-driven risk. Support development of early-warning frameworks and proactive risk identification. Produce clear, defensible analytical findings and case documentation. Support executive reporting and enterprise risk visibility. The consultant's work will improve visibility into critical assets, strengthen understanding of user-to-asset trust relationships, increase the fidelity of insider threat detections, and help prevent compromise of the confidentiality, integrity, and availability of MassMutual's most important information and systems. The Minimum Qualifications 8+ years of experience in cybersecurity, insider threat, investigations, intelligence analysis, data protection, enterprise architecture, or related disciplines. 2+ years of experience working cross-functionally with security, HR, Legal, Privacy, business, or investigative stakeholders. Preferred Qualifications Experience supporting or building an Insider Threat Program. Experience supporting Critical Asset Protection, Information Protection, Data Protection, or Human Risk Management initiatives. Experience conducting cyber, digital, fraud, employee misconduct, or insider threat investigations. Experience analyzing logs, endpoint telemetry, identity activity, access patterns, and behavioral signals. Hands-on experience contributing to detection use cases, monitoring strategies, investigative workflows, or security content development. Experience identifying, classifying, mapping, or protecting sensitive information or critical assets. Strong understanding of identity and access management concepts, privileged access, trust relationships, and access governance. Experience with SIEM, EDR, UEBA, DLP, insider risk management, identity security, and security analytics platforms. Experience developing, tuning, or validating detection logic across endpoint, identity, network, and data protection technologies. Experience analyzing user behavior and identifying anomalous or high-risk activity through the correlation of multiple data sources. Familiarity with deception technologies, cyber deception strategies, or adversary engagement techniques. Experience supporting highly regulated environments such as financial services. Professional certifications such as CISSP, CISM, GIAC, CDLP, GCFA, GCIH, or equivalent. Degree in cybersecurity, intelligence studies, psychology, criminal justice, information systems, or related field. What You Can Expect at MassMutual MassMutual offers the opportunity to do meaningful work within a purpose-driven organization that values long-term impact over short-term outcomes. In this role, you can expect: Clear areas of ownership and accountability, with work that connects directly to company and customer outcomes A collaborative environment where perspectives are welcomed Access to learning, development, and internal networks that support continuous growth and skill-building over time Employee-led communities and forums that foster connection, learning, and inclusion across the organization A culture grounded in integrity, responsibility, and stewardship-supported by a company with a strong legacy and a future-focused mindset MassMutual is an equal employment opportunity employer. We welcome all persons to apply. If you need an accommodation to complete the application process, please contact us and share the specifics of the assistance you need. California residents: For detailed information about your rights under the California Consumer Privacy Act (CCPA), please visit our California Consumer Privacy Act Disclosures page.
Consultant, Insider Threat Enterprise Cyber Security Full Time, Springfield MA (Hybrid) The Opportunity MassMutual is advancing an enterprise Insider Threat program focused on identifying and managing human-driven cyber risk. The Insider Threat Consultant will play a key role in developing the asset intelligence, monitoring strategies, detection capabilities, and investigative processes necessary to identify and manage insider-driven risk. This role combines deep technical expertise, critical asset analysis, behavioral risk assessment, and investigative discipline to understand how people interact with sensitive assets and to identify patterns of activity that may indicate elevated risk. The consultant will partner with cybersecurity operations, detection engineering, HR, Legal, Privacy, and business stakeholders to align monitoring and investigative capabilities with asset sensitivity and business impact. This position is suited for an experienced practitioner who can operate across technical, analytical, and investigative domains while helping build and mature an enterprise-scale insider threat program. The Team The Insider Threat team is a specialized cybersecurity function responsible for understanding and managing the risks that trusted individuals may pose to MassMutual's critical assets, systems, information, and operations. The team operates at the intersection of critical asset protection, identity and access management, behavioral analytics, cyber defense, investigations, and workforce risk. Team members develop the intelligence, monitoring strategies, detection capabilities, investigative processes, and analytical frameworks necessary to identify and reduce insider-driven risk. The team partners closely with Cyber Operations, Detection Engineering, Human Resources, Legal, Privacy, Compliance, Fraud Operations, and business stakeholders to ensure insider risk is identified, assessed, and managed in a consistent, defensible, and risk-informed manner. The Impact The Insider Threat Consultant will: Identify and prioritize critical assets requiring enhanced monitoring and protection. Analyze how critical assets are accessed, used, and shared across the enterprise. Map relationships between identities, access privileges, business processes, and critical assets. Analyze behavioral and technical indicators associated with insider risk. Identify patterns of activity that may indicate misuse or mishandling of critical assets. Conduct and support complex insider threat investigations. Correlate identity, access, asset, and behavioral signals across multiple data sources. Monitor and analyze deception environments and adversary interaction signals. Partner with detection engineering and security operations to develop and refine insider threat detection logic. Contribute to tuning enterprise security tooling to improve identification of insider-driven risk. Support development of early-warning frameworks and proactive risk identification. Produce clear, defensible analytical findings and case documentation. Support executive reporting and enterprise risk visibility. The consultant's work will improve visibility into critical assets, strengthen understanding of user-to-asset trust relationships, increase the fidelity of insider threat detections, and help prevent compromise of the confidentiality, integrity, and availability of MassMutual's most important information and systems. The Minimum Qualifications 8+ years of experience in cybersecurity, insider threat, investigations, intelligence analysis, data protection, enterprise architecture, or related disciplines. 2+ years of experience working cross-functionally with security, HR, Legal, Privacy, business, or investigative stakeholders. Preferred Qualifications Experience supporting or building an Insider Threat Program. Experience supporting Critical Asset Protection, Information Protection, Data Protection, or Human Risk Management initiatives. Experience conducting cyber, digital, fraud, employee misconduct, or insider threat investigations. Experience analyzing logs, endpoint telemetry, identity activity, access patterns, and behavioral signals. Hands-on experience contributing to detection use cases, monitoring strategies, investigative workflows, or security content development. Experience identifying, classifying, mapping, or protecting sensitive information or critical assets. Strong understanding of identity and access management concepts, privileged access, trust relationships, and access governance. Experience with SIEM, EDR, UEBA, DLP, insider risk management, identity security, and security analytics platforms. Experience developing, tuning, or validating detection logic across endpoint, identity, network, and data protection technologies. Experience analyzing user behavior and identifying anomalous or high-risk activity through the correlation of multiple data sources. Familiarity with deception technologies, cyber deception strategies, or adversary engagement techniques. Experience supporting highly regulated environments such as financial services. Professional certifications such as CISSP, CISM, GIAC, CDLP, GCFA, GCIH, or equivalent. Degree in cybersecurity, intelligence studies, psychology, criminal justice, information systems, or related field. What You Can Expect at MassMutual MassMutual offers the opportunity to do meaningful work within a purpose-driven organization that values long-term impact over short-term outcomes. In this role, you can expect: Clear areas of ownership and accountability, with work that connects directly to company and customer outcomes A collaborative environment where perspectives are welcomed Access to learning, development, and internal networks that support continuous growth and skill-building over time Employee-led communities and forums that foster connection, learning, and inclusion across the organization A culture grounded in integrity, responsibility, and stewardship-supported by a company with a strong legacy and a future-focused mindset MassMutual is an equal employment opportunity employer. We welcome all persons to apply. If you need an accommodation to complete the application process, please contact us and share the specifics of the assistance you need. California residents: For detailed information about your rights under the California Consumer Privacy Act (CCPA), please visit our California Consumer Privacy Act Disclosures page.
09/07/2026
Full time
Consultant, Insider Threat Enterprise Cyber Security Full Time, Springfield MA (Hybrid) The Opportunity MassMutual is advancing an enterprise Insider Threat program focused on identifying and managing human-driven cyber risk. The Insider Threat Consultant will play a key role in developing the asset intelligence, monitoring strategies, detection capabilities, and investigative processes necessary to identify and manage insider-driven risk. This role combines deep technical expertise, critical asset analysis, behavioral risk assessment, and investigative discipline to understand how people interact with sensitive assets and to identify patterns of activity that may indicate elevated risk. The consultant will partner with cybersecurity operations, detection engineering, HR, Legal, Privacy, and business stakeholders to align monitoring and investigative capabilities with asset sensitivity and business impact. This position is suited for an experienced practitioner who can operate across technical, analytical, and investigative domains while helping build and mature an enterprise-scale insider threat program. The Team The Insider Threat team is a specialized cybersecurity function responsible for understanding and managing the risks that trusted individuals may pose to MassMutual's critical assets, systems, information, and operations. The team operates at the intersection of critical asset protection, identity and access management, behavioral analytics, cyber defense, investigations, and workforce risk. Team members develop the intelligence, monitoring strategies, detection capabilities, investigative processes, and analytical frameworks necessary to identify and reduce insider-driven risk. The team partners closely with Cyber Operations, Detection Engineering, Human Resources, Legal, Privacy, Compliance, Fraud Operations, and business stakeholders to ensure insider risk is identified, assessed, and managed in a consistent, defensible, and risk-informed manner. The Impact The Insider Threat Consultant will: Identify and prioritize critical assets requiring enhanced monitoring and protection. Analyze how critical assets are accessed, used, and shared across the enterprise. Map relationships between identities, access privileges, business processes, and critical assets. Analyze behavioral and technical indicators associated with insider risk. Identify patterns of activity that may indicate misuse or mishandling of critical assets. Conduct and support complex insider threat investigations. Correlate identity, access, asset, and behavioral signals across multiple data sources. Monitor and analyze deception environments and adversary interaction signals. Partner with detection engineering and security operations to develop and refine insider threat detection logic. Contribute to tuning enterprise security tooling to improve identification of insider-driven risk. Support development of early-warning frameworks and proactive risk identification. Produce clear, defensible analytical findings and case documentation. Support executive reporting and enterprise risk visibility. The consultant's work will improve visibility into critical assets, strengthen understanding of user-to-asset trust relationships, increase the fidelity of insider threat detections, and help prevent compromise of the confidentiality, integrity, and availability of MassMutual's most important information and systems. The Minimum Qualifications 8+ years of experience in cybersecurity, insider threat, investigations, intelligence analysis, data protection, enterprise architecture, or related disciplines. 2+ years of experience working cross-functionally with security, HR, Legal, Privacy, business, or investigative stakeholders. Preferred Qualifications Experience supporting or building an Insider Threat Program. Experience supporting Critical Asset Protection, Information Protection, Data Protection, or Human Risk Management initiatives. Experience conducting cyber, digital, fraud, employee misconduct, or insider threat investigations. Experience analyzing logs, endpoint telemetry, identity activity, access patterns, and behavioral signals. Hands-on experience contributing to detection use cases, monitoring strategies, investigative workflows, or security content development. Experience identifying, classifying, mapping, or protecting sensitive information or critical assets. Strong understanding of identity and access management concepts, privileged access, trust relationships, and access governance. Experience with SIEM, EDR, UEBA, DLP, insider risk management, identity security, and security analytics platforms. Experience developing, tuning, or validating detection logic across endpoint, identity, network, and data protection technologies. Experience analyzing user behavior and identifying anomalous or high-risk activity through the correlation of multiple data sources. Familiarity with deception technologies, cyber deception strategies, or adversary engagement techniques. Experience supporting highly regulated environments such as financial services. Professional certifications such as CISSP, CISM, GIAC, CDLP, GCFA, GCIH, or equivalent. Degree in cybersecurity, intelligence studies, psychology, criminal justice, information systems, or related field. What You Can Expect at MassMutual MassMutual offers the opportunity to do meaningful work within a purpose-driven organization that values long-term impact over short-term outcomes. In this role, you can expect: Clear areas of ownership and accountability, with work that connects directly to company and customer outcomes A collaborative environment where perspectives are welcomed Access to learning, development, and internal networks that support continuous growth and skill-building over time Employee-led communities and forums that foster connection, learning, and inclusion across the organization A culture grounded in integrity, responsibility, and stewardship-supported by a company with a strong legacy and a future-focused mindset MassMutual is an equal employment opportunity employer. We welcome all persons to apply. If you need an accommodation to complete the application process, please contact us and share the specifics of the assistance you need. California residents: For detailed information about your rights under the California Consumer Privacy Act (CCPA), please visit our California Consumer Privacy Act Disclosures page.
Kaiser Permanente seeks a Cyber Risk Defense Consultant to lead security strategy for Systeme.io, an all-in-one marketing platform. You will assess cyber risk across cloud applications, design and implement security controls, and guide incident response. Partner with engineering to embed secure-by-design practices, perform threat modeling, and manage vulnerability remediation. You will develop policies, mentor teams on best practices, and collaborate cross-functionally, helping maintain resilient, user-focused software while supporting a culture of innovation, learning, and continual improvement. Responsibilities Lead cyber risk assessments for cloud-based and web applications supporting Systeme.io Design and implement security architectures, controls, and standards across platforms Collaborate with engineering and product teams to embed secure-by-design practices Manage vulnerability assessment, prioritization, and remediation tracking Oversee incident response planning, playbooks, and post-incident reviews Develop and maintain security policies, standards, and technical guidelines Perform threat modeling and security reviews for new features and integrations Monitor security posture using SIEM and logging tools, recommending improvements Advise leadership on cyber risk, emerging threats, and mitigation strategies Provide security training and mentorship to technical and non-technical teams Required Skills Cybersecurity Risk assessment Cloud security (AWS/Azure/GCP) Network security Security architecture Vulnerability management Incident response SIEM and log analysis Threat modeling Security compliance and governance
09/06/2026
Full time
Kaiser Permanente seeks a Cyber Risk Defense Consultant to lead security strategy for Systeme.io, an all-in-one marketing platform. You will assess cyber risk across cloud applications, design and implement security controls, and guide incident response. Partner with engineering to embed secure-by-design practices, perform threat modeling, and manage vulnerability remediation. You will develop policies, mentor teams on best practices, and collaborate cross-functionally, helping maintain resilient, user-focused software while supporting a culture of innovation, learning, and continual improvement. Responsibilities Lead cyber risk assessments for cloud-based and web applications supporting Systeme.io Design and implement security architectures, controls, and standards across platforms Collaborate with engineering and product teams to embed secure-by-design practices Manage vulnerability assessment, prioritization, and remediation tracking Oversee incident response planning, playbooks, and post-incident reviews Develop and maintain security policies, standards, and technical guidelines Perform threat modeling and security reviews for new features and integrations Monitor security posture using SIEM and logging tools, recommending improvements Advise leadership on cyber risk, emerging threats, and mitigation strategies Provide security training and mentorship to technical and non-technical teams Required Skills Cybersecurity Risk assessment Cloud security (AWS/Azure/GCP) Network security Security architecture Vulnerability management Incident response SIEM and log analysis Threat modeling Security compliance and governance
Kaiser Permanente is seeking a Cyber Risk Defense Consultant to strengthen security for its Systeme.io-based platforms. You will assess cyber threats, design and implement defense strategies, and lead incident response across cloud and on-prem environments. Partner with engineering and product teams to embed security by design, conduct risk assessments, and tune monitoring tools. You'll mentor teams on best practices, support compliance, and drive continuous improvement in a collaborative, innovation-focused culture that values learning and user-centric solutions. Responsibilities Conduct cyber risk assessments and threat modeling for cloud and on-prem systems supporting Systeme.io-based platforms. Design, implement, and optimize cyber defense controls, including network, endpoint, and cloud security measures. Lead and coordinate incident detection, response, and post-incident reviews with cross-functional teams. Configure and tune SIEM and monitoring tools to improve detection accuracy and reduce false positives. Collaborate with engineering, product, and IT teams to embed security by design into new and existing solutions. Manage vulnerability assessments, prioritize remediation, and track closure across environments. Ensure compliance with relevant regulations and frameworks (e.g., HIPAA, SOC 2) and support audits. Develop and deliver security training and guidance to technical and non-technical stakeholders. Create and maintain security documentation, runbooks, standards, and architectural diagrams. Continuously evaluate emerging threats and technologies to evolve Kaiser Permanente's cyber defense posture. Required Skills Cybersecurity risk assessment Threat modeling Cloud security (AWS/Azure/GCP) Network security SIEM configuration and tuning Incident detection and response Vulnerability management Security architecture and design Security compliance and governance (HIPAA, SOC 2) Scripting/automation (Python, Power Shell)
09/06/2026
Full time
Kaiser Permanente is seeking a Cyber Risk Defense Consultant to strengthen security for its Systeme.io-based platforms. You will assess cyber threats, design and implement defense strategies, and lead incident response across cloud and on-prem environments. Partner with engineering and product teams to embed security by design, conduct risk assessments, and tune monitoring tools. You'll mentor teams on best practices, support compliance, and drive continuous improvement in a collaborative, innovation-focused culture that values learning and user-centric solutions. Responsibilities Conduct cyber risk assessments and threat modeling for cloud and on-prem systems supporting Systeme.io-based platforms. Design, implement, and optimize cyber defense controls, including network, endpoint, and cloud security measures. Lead and coordinate incident detection, response, and post-incident reviews with cross-functional teams. Configure and tune SIEM and monitoring tools to improve detection accuracy and reduce false positives. Collaborate with engineering, product, and IT teams to embed security by design into new and existing solutions. Manage vulnerability assessments, prioritize remediation, and track closure across environments. Ensure compliance with relevant regulations and frameworks (e.g., HIPAA, SOC 2) and support audits. Develop and deliver security training and guidance to technical and non-technical stakeholders. Create and maintain security documentation, runbooks, standards, and architectural diagrams. Continuously evaluate emerging threats and technologies to evolve Kaiser Permanente's cyber defense posture. Required Skills Cybersecurity risk assessment Threat modeling Cloud security (AWS/Azure/GCP) Network security SIEM configuration and tuning Incident detection and response Vulnerability management Security architecture and design Security compliance and governance (HIPAA, SOC 2) Scripting/automation (Python, Power Shell)
Tech Summary The Threat Hunting Lead will serve as the technical lead for Kaiser Permanente's Threat Hunting function within the Threat Intelligence and Detection Engineering (TIDE) team. This role is responsible for proactively identifying advanced threats by leveraging threat intelligence and analyzing endpoint, network, cloud, identity, email, asset, and other security telemetry. The successful candidate will develop and execute threat hunts, translate intelligence into actionable detection and hunting strategies, identify gaps in defensive coverage, and drive improvements to the organization's security posture. Working closely with Threat Intelligence, Detection Engineering, Incident Response, and Cyber Defense teams, the Threat Hunting Lead will provide technical leadership, mentor analysts, communicate findings to both technical and executive audiences, and help ensure Kaiser Permanente remains protected against an evolving threat landscape. The ideal candidate is a collaborative, intellectually curious cybersecurity professional with a passion for emerging threats, data-driven analysis, and continuous improvement. Job Summary: This senior level employee is primarily responsible for overseeing the maintenance and protection of integrity and reliability of the security of data, systems and networks. Essential Responsibilities: Conducts or oversees business-specific projects by applying deep expertise in subject area; promoting adherence to all procedures and policies; developing work plans to meet business priorities and deadlines; determining and carrying out processes and methodologies; coordinating and delegating resources to accomplish organizational goals; partnering internally and externally to make effective business decisions; solving complex problems; escalating issues or risks, as appropriate; monitoring progress and results; recognizing and capitalizing on improvement opportunities; evaluating recommendations made; and influencing the completion of project tasks by others. Practices self-leadership and promotes learning in others by building relationships with cross-functional stakeholders; communicating information and providing advice to drive projects forward; influencing team members within assigned unit; listening and responding to, seeking, and addressing performance feedback; adapting to competing demands and new responsibilities; providing feedback to others, including upward feedback to leadership and mentoring junior team members; creating and executing plans to capitalize on strengths and improve opportunity areas; and adapting to and learning from change, difficulties, and feedback. Leads team in the proactive monitoring and/or response to known or emerging threats against the KP network. Effectively communicates investigative findings to non-technical audiences. Plans and facilitates regular operations meeting with Cyber Risk Defense Center (CRDC) teams. Supports closed loop processes on security efforts by providing feedback to the TDA leads and/or leadership. Participates in information fusion procedures across operations and engineering, including activities such as Use Case planning/development, Use Case quality assurance validation, and response procedure documentation. Serves as a liaison between stage teams and upper management by identifying issues, improvement areas, or security/architectural gaps and suggesting appropriate improvements. Drives the development of the CRDC intellectual capital by leading process or procedure improvements, consulting on brown bag training sessions, and leading the development of new training documents. Partners with the CRDC Policy Engineers and Remediation teams to contain identified issues and determine the best approach for improving security posture. Facilitates follow-up remediation design and review efforts. Leads the investigation and triage of security events across multiple domains. Leads complex data analyses in support of security event management processes, including root cause analysis. Coordinates the response and resolution of high impact or critical cyber security incidents. Leads the deployment of threat detection capabilities and/or incident response plans which may include after-hours support and coordination among responsible teams. Drives the execution of incident detection and/or handling processes which may include containment, protection, and remediation activities. Minimum Qualifications: Minimum two (2) years in an informal leadership role working with project or technical teams. Bachelors degree in Business Administration, Computer Science, Social Science, Mathematics, or related field and Minimum eight (8) years experience in IT or a related field, including Minimum two (2) years in information security or network engineering. Additional equivalent work experience may be substituted for the degree requirement. Additional Requirements:
09/06/2026
Full time
Tech Summary The Threat Hunting Lead will serve as the technical lead for Kaiser Permanente's Threat Hunting function within the Threat Intelligence and Detection Engineering (TIDE) team. This role is responsible for proactively identifying advanced threats by leveraging threat intelligence and analyzing endpoint, network, cloud, identity, email, asset, and other security telemetry. The successful candidate will develop and execute threat hunts, translate intelligence into actionable detection and hunting strategies, identify gaps in defensive coverage, and drive improvements to the organization's security posture. Working closely with Threat Intelligence, Detection Engineering, Incident Response, and Cyber Defense teams, the Threat Hunting Lead will provide technical leadership, mentor analysts, communicate findings to both technical and executive audiences, and help ensure Kaiser Permanente remains protected against an evolving threat landscape. The ideal candidate is a collaborative, intellectually curious cybersecurity professional with a passion for emerging threats, data-driven analysis, and continuous improvement. Job Summary: This senior level employee is primarily responsible for overseeing the maintenance and protection of integrity and reliability of the security of data, systems and networks. Essential Responsibilities: Conducts or oversees business-specific projects by applying deep expertise in subject area; promoting adherence to all procedures and policies; developing work plans to meet business priorities and deadlines; determining and carrying out processes and methodologies; coordinating and delegating resources to accomplish organizational goals; partnering internally and externally to make effective business decisions; solving complex problems; escalating issues or risks, as appropriate; monitoring progress and results; recognizing and capitalizing on improvement opportunities; evaluating recommendations made; and influencing the completion of project tasks by others. Practices self-leadership and promotes learning in others by building relationships with cross-functional stakeholders; communicating information and providing advice to drive projects forward; influencing team members within assigned unit; listening and responding to, seeking, and addressing performance feedback; adapting to competing demands and new responsibilities; providing feedback to others, including upward feedback to leadership and mentoring junior team members; creating and executing plans to capitalize on strengths and improve opportunity areas; and adapting to and learning from change, difficulties, and feedback. Leads team in the proactive monitoring and/or response to known or emerging threats against the KP network. Effectively communicates investigative findings to non-technical audiences. Plans and facilitates regular operations meeting with Cyber Risk Defense Center (CRDC) teams. Supports closed loop processes on security efforts by providing feedback to the TDA leads and/or leadership. Participates in information fusion procedures across operations and engineering, including activities such as Use Case planning/development, Use Case quality assurance validation, and response procedure documentation. Serves as a liaison between stage teams and upper management by identifying issues, improvement areas, or security/architectural gaps and suggesting appropriate improvements. Drives the development of the CRDC intellectual capital by leading process or procedure improvements, consulting on brown bag training sessions, and leading the development of new training documents. Partners with the CRDC Policy Engineers and Remediation teams to contain identified issues and determine the best approach for improving security posture. Facilitates follow-up remediation design and review efforts. Leads the investigation and triage of security events across multiple domains. Leads complex data analyses in support of security event management processes, including root cause analysis. Coordinates the response and resolution of high impact or critical cyber security incidents. Leads the deployment of threat detection capabilities and/or incident response plans which may include after-hours support and coordination among responsible teams. Drives the execution of incident detection and/or handling processes which may include containment, protection, and remediation activities. Minimum Qualifications: Minimum two (2) years in an informal leadership role working with project or technical teams. Bachelors degree in Business Administration, Computer Science, Social Science, Mathematics, or related field and Minimum eight (8) years experience in IT or a related field, including Minimum two (2) years in information security or network engineering. Additional equivalent work experience may be substituted for the degree requirement. Additional Requirements: