Position - Security Engineer Location - Fort Worth, TX (Hybrid) Job ID - 178604 Position Overview We are seeking a Directory Services Engineer to support critical cybersecurity initiatives focused on identity infrastructure security, Tier 0 protection, and resiliency. This role is hands-on and execution-focused, working across Active Directory, Microsoft Entra ID (Azure AD), and hybrid identity environments. The engineer will play a key role in hardening identity systems, identifying attack paths, and implementing remediation actions to reduce enterprise risk. Key Responsibilities Identity Engineering & Operations • Administer and support Active Directory (AD) and Microsoft Entra ID (Azure AD) environments. • Implement and manage Azure AD Connect / Entra Connect for hybrid identity synchronization. • Support domain controllers, forests, trusts, and authentication services. • Execute identity-related changes, configurations, and deployments. Security Hardening & Tier 0 Protection • Implement security controls for Tier 0 assets (AD, Entra ID, domain controllers). • Perform system hardening in alignment with cybersecurity standards. • Support initiatives for privileged access restrictions and identity protection. • Remediate identified security gaps and misconfigurations. Attack Path Identification & Remediation • Analyze and identify identity-based attack paths across on-prem and cloud environments. • Support remediation efforts to eliminate: o Privilege escalation paths o Excessive permissions o Identity misconfigurations • Partner with cybersecurity teams to reduce identity attack surface. Resiliency & Recovery Support • Implement and validate Active Directory forest recovery procedures. • Support backup, restore, and testing activities for identity systems. • Assist in improving resiliency and recoverability of Tier 0 infrastructure. Integration Support • Assist in integration and configuration of identity with: o MFA / Conditional Access o PAM (e.g., CyberArk) o IGA (e.g., Saviynt) o Secrets and certificate platforms (e.g., HashiCorp, Keyfactor) • Support identity governance and access control initiatives. Automation & Execution • Use PowerShell and scripting to automate identity tasks and remediation. • Execute predefined engineering tasks, runbooks, and operational procedures. • Document configurations, changes, and implementation steps. Job Description: Operationalize automated data discovery, classification, and inventory; apply sensitivity labels and consistent taxonomy across data stores, pipelines, and collaboration systems. Engineer DSPM capabilities with tools (e.g., Securiti, BigID) to surface data posture risks (overexposure, shadow data, stale sensitive data) and drive remediation workflows. Implement and support encryption, tokenization, masking, anonymization/pseudonymization for data at rest and in transit; integrate with cloud key management systems and enforce approved cryptographic standards; define crypto baselines and policy-as-code guardrails. Configure and govern access controls with RBAC/ABAC and purpose-based authorization; perform least-privilege and fine-grained access reviews across data platforms. Deploy, tune, and operate DLP and DAM solutions (e.g., Microsoft Purview DLP, Imperva/Guardium); build detections for PII/PCI/PHI and reduce false positives with policy and context improvements. Integrate and tune UEBA and Insider Risk signals to detect anomalous data access and exfiltration, partner on response workflows and preventive control changes. Integrate data protection telemetry with SIEM/SOAR; build detections, correlation rules, and automated response playbooks for data-related threats and policy violations. Implement data minimization and retention/ROT enforcement patterns; automate monitoring of lifecycle actions (archive, delete, redact) aligned to policy and legal holds. Implement DSAR (data subject access request) orchestration and fulfillment with SLA monitoring; automate data collection, redaction, and secure delivery with audit trails. Contribute to cookie/tag governance and catalog assurance; validate consent signals, storage durations, and vendor script behavior against policy. Support privacy platform capabilities and integrate with identity, ticketing, data catalogs/lineage, and evidence repositories. Embed data protection and privacy-by-design controls into services and CI/CD (pre-commit/CI privacy code scanning, secret scanning, schema checks for sensitive fields, data egress policies). Produce compliance evidence and reports for GDPR/CCPA/CPRA, PCI DSS, HIPAA, and internal audits; maintain controls health dashboards, regulatory tracking, and program KPIs. Investigate data-related incidents and privacy events in partnership with IR/SOC/Privacy Office. Collect artifacts, support forensics, document findings, and drive preventive engineering fixes. Conduct platform hardening and vulnerability remediation for data control tooling (misconfigurations, exposed buckets, weak crypto, excessive permissions). Participate in red teaming/tabletop exercises for data scenarios (insider misuse, public link exposures, unintended AI training data); translate findings into control improvements. Partner with Cybersecurity, Privacy Office, Enterprise Data, Legal, and product/platform teams to align designs and deliver privacy- and data protection-by-design outcomes. Document engineering patterns, runbooks, and reference architectures; create training and technical guidance that strengthen secure data handling practices across teams. Communicate clearly and concisely with technical and non?technical audiences - summarize incidents, risks, and recommended actions with accurate, complete context. Required Skills & Experience 3-7 years of hands-on experience in: Active Directory administration/engineering Microsoft Entra ID (Azure AD) Azure AD Connect / hybrid identity environments Experience with: AD security hardening Identity-related attack techniques (privilege escalation, lateral movement) Attack path analysis or remediation activities Strong working knowledge of: Tier 0 concepts and identity as a control plane Authentication protocols (Kerberos, NTLM, SAML, OAuth) Preferred Experience Exposure to: CyberArk or other PAM tools Saviynt or similar IGA platforms Ping Identity or federation solutions HashiCorp Vault, Keyfactor, or PKI environments Experience supporting AD forest recovery exercises Familiarity with Zero Trust principles Key Traits for Success Strong execution and delivery focus Security and resiliency mindset Ability to quickly identify and remediate risks Works effectively in a cross-functional cybersecurity environment Comfortable working in fast-paced, project-driven (contract) engagements Pay Range: $65 - $70/Hr The specific compensation for this position will be determined by a number of factors, including the scope, complexity and location of the role as well as the cost of labor in the market; the skills, education, training, credentials and experience of the candidate; and other conditions of employment. Our full-time consultants have access to benefits including medical, dental, vision and 401K contributions as well as any other PTO, sick leave, and other benefits mandated by appliable state or localities where you reside or work.
08/05/2026
Full time
Position - Security Engineer Location - Fort Worth, TX (Hybrid) Job ID - 178604 Position Overview We are seeking a Directory Services Engineer to support critical cybersecurity initiatives focused on identity infrastructure security, Tier 0 protection, and resiliency. This role is hands-on and execution-focused, working across Active Directory, Microsoft Entra ID (Azure AD), and hybrid identity environments. The engineer will play a key role in hardening identity systems, identifying attack paths, and implementing remediation actions to reduce enterprise risk. Key Responsibilities Identity Engineering & Operations • Administer and support Active Directory (AD) and Microsoft Entra ID (Azure AD) environments. • Implement and manage Azure AD Connect / Entra Connect for hybrid identity synchronization. • Support domain controllers, forests, trusts, and authentication services. • Execute identity-related changes, configurations, and deployments. Security Hardening & Tier 0 Protection • Implement security controls for Tier 0 assets (AD, Entra ID, domain controllers). • Perform system hardening in alignment with cybersecurity standards. • Support initiatives for privileged access restrictions and identity protection. • Remediate identified security gaps and misconfigurations. Attack Path Identification & Remediation • Analyze and identify identity-based attack paths across on-prem and cloud environments. • Support remediation efforts to eliminate: o Privilege escalation paths o Excessive permissions o Identity misconfigurations • Partner with cybersecurity teams to reduce identity attack surface. Resiliency & Recovery Support • Implement and validate Active Directory forest recovery procedures. • Support backup, restore, and testing activities for identity systems. • Assist in improving resiliency and recoverability of Tier 0 infrastructure. Integration Support • Assist in integration and configuration of identity with: o MFA / Conditional Access o PAM (e.g., CyberArk) o IGA (e.g., Saviynt) o Secrets and certificate platforms (e.g., HashiCorp, Keyfactor) • Support identity governance and access control initiatives. Automation & Execution • Use PowerShell and scripting to automate identity tasks and remediation. • Execute predefined engineering tasks, runbooks, and operational procedures. • Document configurations, changes, and implementation steps. Job Description: Operationalize automated data discovery, classification, and inventory; apply sensitivity labels and consistent taxonomy across data stores, pipelines, and collaboration systems. Engineer DSPM capabilities with tools (e.g., Securiti, BigID) to surface data posture risks (overexposure, shadow data, stale sensitive data) and drive remediation workflows. Implement and support encryption, tokenization, masking, anonymization/pseudonymization for data at rest and in transit; integrate with cloud key management systems and enforce approved cryptographic standards; define crypto baselines and policy-as-code guardrails. Configure and govern access controls with RBAC/ABAC and purpose-based authorization; perform least-privilege and fine-grained access reviews across data platforms. Deploy, tune, and operate DLP and DAM solutions (e.g., Microsoft Purview DLP, Imperva/Guardium); build detections for PII/PCI/PHI and reduce false positives with policy and context improvements. Integrate and tune UEBA and Insider Risk signals to detect anomalous data access and exfiltration, partner on response workflows and preventive control changes. Integrate data protection telemetry with SIEM/SOAR; build detections, correlation rules, and automated response playbooks for data-related threats and policy violations. Implement data minimization and retention/ROT enforcement patterns; automate monitoring of lifecycle actions (archive, delete, redact) aligned to policy and legal holds. Implement DSAR (data subject access request) orchestration and fulfillment with SLA monitoring; automate data collection, redaction, and secure delivery with audit trails. Contribute to cookie/tag governance and catalog assurance; validate consent signals, storage durations, and vendor script behavior against policy. Support privacy platform capabilities and integrate with identity, ticketing, data catalogs/lineage, and evidence repositories. Embed data protection and privacy-by-design controls into services and CI/CD (pre-commit/CI privacy code scanning, secret scanning, schema checks for sensitive fields, data egress policies). Produce compliance evidence and reports for GDPR/CCPA/CPRA, PCI DSS, HIPAA, and internal audits; maintain controls health dashboards, regulatory tracking, and program KPIs. Investigate data-related incidents and privacy events in partnership with IR/SOC/Privacy Office. Collect artifacts, support forensics, document findings, and drive preventive engineering fixes. Conduct platform hardening and vulnerability remediation for data control tooling (misconfigurations, exposed buckets, weak crypto, excessive permissions). Participate in red teaming/tabletop exercises for data scenarios (insider misuse, public link exposures, unintended AI training data); translate findings into control improvements. Partner with Cybersecurity, Privacy Office, Enterprise Data, Legal, and product/platform teams to align designs and deliver privacy- and data protection-by-design outcomes. Document engineering patterns, runbooks, and reference architectures; create training and technical guidance that strengthen secure data handling practices across teams. Communicate clearly and concisely with technical and non?technical audiences - summarize incidents, risks, and recommended actions with accurate, complete context. Required Skills & Experience 3-7 years of hands-on experience in: Active Directory administration/engineering Microsoft Entra ID (Azure AD) Azure AD Connect / hybrid identity environments Experience with: AD security hardening Identity-related attack techniques (privilege escalation, lateral movement) Attack path analysis or remediation activities Strong working knowledge of: Tier 0 concepts and identity as a control plane Authentication protocols (Kerberos, NTLM, SAML, OAuth) Preferred Experience Exposure to: CyberArk or other PAM tools Saviynt or similar IGA platforms Ping Identity or federation solutions HashiCorp Vault, Keyfactor, or PKI environments Experience supporting AD forest recovery exercises Familiarity with Zero Trust principles Key Traits for Success Strong execution and delivery focus Security and resiliency mindset Ability to quickly identify and remediate risks Works effectively in a cross-functional cybersecurity environment Comfortable working in fast-paced, project-driven (contract) engagements Pay Range: $65 - $70/Hr The specific compensation for this position will be determined by a number of factors, including the scope, complexity and location of the role as well as the cost of labor in the market; the skills, education, training, credentials and experience of the candidate; and other conditions of employment. Our full-time consultants have access to benefits including medical, dental, vision and 401K contributions as well as any other PTO, sick leave, and other benefits mandated by appliable state or localities where you reside or work.
Consultant, Insider Threat Enterprise Cyber Security Full Time, Springfield MA (Hybrid) The Opportunity MassMutual is advancing an enterprise Insider Threat program focused on identifying and managing human-driven cyber risk. The Insider Threat Consultant will play a key role in developing the asset intelligence, monitoring strategies, detection capabilities, and investigative processes necessary to identify and manage insider-driven risk. This role combines deep technical expertise, critical asset analysis, behavioral risk assessment, and investigative discipline to understand how people interact with sensitive assets and to identify patterns of activity that may indicate elevated risk. The consultant will partner with cybersecurity operations, detection engineering, HR, Legal, Privacy, and business stakeholders to align monitoring and investigative capabilities with asset sensitivity and business impact. This position is suited for an experienced practitioner who can operate across technical, analytical, and investigative domains while helping build and mature an enterprise-scale insider threat program. The Team The Insider Threat team is a specialized cybersecurity function responsible for understanding and managing the risks that trusted individuals may pose to MassMutual's critical assets, systems, information, and operations. The team operates at the intersection of critical asset protection, identity and access management, behavioral analytics, cyber defense, investigations, and workforce risk. Team members develop the intelligence, monitoring strategies, detection capabilities, investigative processes, and analytical frameworks necessary to identify and reduce insider-driven risk. The team partners closely with Cyber Operations, Detection Engineering, Human Resources, Legal, Privacy, Compliance, Fraud Operations, and business stakeholders to ensure insider risk is identified, assessed, and managed in a consistent, defensible, and risk-informed manner. The Impact The Insider Threat Consultant will: Identify and prioritize critical assets requiring enhanced monitoring and protection. Analyze how critical assets are accessed, used, and shared across the enterprise. Map relationships between identities, access privileges, business processes, and critical assets. Analyze behavioral and technical indicators associated with insider risk. Identify patterns of activity that may indicate misuse or mishandling of critical assets. Conduct and support complex insider threat investigations. Correlate identity, access, asset, and behavioral signals across multiple data sources. Monitor and analyze deception environments and adversary interaction signals. Partner with detection engineering and security operations to develop and refine insider threat detection logic. Contribute to tuning enterprise security tooling to improve identification of insider-driven risk. Support development of early-warning frameworks and proactive risk identification. Produce clear, defensible analytical findings and case documentation. Support executive reporting and enterprise risk visibility. The consultant's work will improve visibility into critical assets, strengthen understanding of user-to-asset trust relationships, increase the fidelity of insider threat detections, and help prevent compromise of the confidentiality, integrity, and availability of MassMutual's most important information and systems. The Minimum Qualifications 8+ years of experience in cybersecurity, insider threat, investigations, intelligence analysis, data protection, enterprise architecture, or related disciplines. 2+ years of experience working cross-functionally with security, HR, Legal, Privacy, business, or investigative stakeholders. Preferred Qualifications Experience supporting or building an Insider Threat Program. Experience supporting Critical Asset Protection, Information Protection, Data Protection, or Human Risk Management initiatives. Experience conducting cyber, digital, fraud, employee misconduct, or insider threat investigations. Experience analyzing logs, endpoint telemetry, identity activity, access patterns, and behavioral signals. Hands-on experience contributing to detection use cases, monitoring strategies, investigative workflows, or security content development. Experience identifying, classifying, mapping, or protecting sensitive information or critical assets. Strong understanding of identity and access management concepts, privileged access, trust relationships, and access governance. Experience with SIEM, EDR, UEBA, DLP, insider risk management, identity security, and security analytics platforms. Experience developing, tuning, or validating detection logic across endpoint, identity, network, and data protection technologies. Experience analyzing user behavior and identifying anomalous or high-risk activity through the correlation of multiple data sources. Familiarity with deception technologies, cyber deception strategies, or adversary engagement techniques. Experience supporting highly regulated environments such as financial services. Professional certifications such as CISSP, CISM, GIAC, CDLP, GCFA, GCIH, or equivalent. Degree in cybersecurity, intelligence studies, psychology, criminal justice, information systems, or related field. What You Can Expect at MassMutual MassMutual offers the opportunity to do meaningful work within a purpose-driven organization that values long-term impact over short-term outcomes. In this role, you can expect: Clear areas of ownership and accountability, with work that connects directly to company and customer outcomes A collaborative environment where perspectives are welcomed Access to learning, development, and internal networks that support continuous growth and skill-building over time Employee-led communities and forums that foster connection, learning, and inclusion across the organization A culture grounded in integrity, responsibility, and stewardship-supported by a company with a strong legacy and a future-focused mindset MassMutual is an equal employment opportunity employer. We welcome all persons to apply. If you need an accommodation to complete the application process, please contact us and share the specifics of the assistance you need. California residents: For detailed information about your rights under the California Consumer Privacy Act (CCPA), please visit our California Consumer Privacy Act Disclosures page.
08/04/2026
Full time
Consultant, Insider Threat Enterprise Cyber Security Full Time, Springfield MA (Hybrid) The Opportunity MassMutual is advancing an enterprise Insider Threat program focused on identifying and managing human-driven cyber risk. The Insider Threat Consultant will play a key role in developing the asset intelligence, monitoring strategies, detection capabilities, and investigative processes necessary to identify and manage insider-driven risk. This role combines deep technical expertise, critical asset analysis, behavioral risk assessment, and investigative discipline to understand how people interact with sensitive assets and to identify patterns of activity that may indicate elevated risk. The consultant will partner with cybersecurity operations, detection engineering, HR, Legal, Privacy, and business stakeholders to align monitoring and investigative capabilities with asset sensitivity and business impact. This position is suited for an experienced practitioner who can operate across technical, analytical, and investigative domains while helping build and mature an enterprise-scale insider threat program. The Team The Insider Threat team is a specialized cybersecurity function responsible for understanding and managing the risks that trusted individuals may pose to MassMutual's critical assets, systems, information, and operations. The team operates at the intersection of critical asset protection, identity and access management, behavioral analytics, cyber defense, investigations, and workforce risk. Team members develop the intelligence, monitoring strategies, detection capabilities, investigative processes, and analytical frameworks necessary to identify and reduce insider-driven risk. The team partners closely with Cyber Operations, Detection Engineering, Human Resources, Legal, Privacy, Compliance, Fraud Operations, and business stakeholders to ensure insider risk is identified, assessed, and managed in a consistent, defensible, and risk-informed manner. The Impact The Insider Threat Consultant will: Identify and prioritize critical assets requiring enhanced monitoring and protection. Analyze how critical assets are accessed, used, and shared across the enterprise. Map relationships between identities, access privileges, business processes, and critical assets. Analyze behavioral and technical indicators associated with insider risk. Identify patterns of activity that may indicate misuse or mishandling of critical assets. Conduct and support complex insider threat investigations. Correlate identity, access, asset, and behavioral signals across multiple data sources. Monitor and analyze deception environments and adversary interaction signals. Partner with detection engineering and security operations to develop and refine insider threat detection logic. Contribute to tuning enterprise security tooling to improve identification of insider-driven risk. Support development of early-warning frameworks and proactive risk identification. Produce clear, defensible analytical findings and case documentation. Support executive reporting and enterprise risk visibility. The consultant's work will improve visibility into critical assets, strengthen understanding of user-to-asset trust relationships, increase the fidelity of insider threat detections, and help prevent compromise of the confidentiality, integrity, and availability of MassMutual's most important information and systems. The Minimum Qualifications 8+ years of experience in cybersecurity, insider threat, investigations, intelligence analysis, data protection, enterprise architecture, or related disciplines. 2+ years of experience working cross-functionally with security, HR, Legal, Privacy, business, or investigative stakeholders. Preferred Qualifications Experience supporting or building an Insider Threat Program. Experience supporting Critical Asset Protection, Information Protection, Data Protection, or Human Risk Management initiatives. Experience conducting cyber, digital, fraud, employee misconduct, or insider threat investigations. Experience analyzing logs, endpoint telemetry, identity activity, access patterns, and behavioral signals. Hands-on experience contributing to detection use cases, monitoring strategies, investigative workflows, or security content development. Experience identifying, classifying, mapping, or protecting sensitive information or critical assets. Strong understanding of identity and access management concepts, privileged access, trust relationships, and access governance. Experience with SIEM, EDR, UEBA, DLP, insider risk management, identity security, and security analytics platforms. Experience developing, tuning, or validating detection logic across endpoint, identity, network, and data protection technologies. Experience analyzing user behavior and identifying anomalous or high-risk activity through the correlation of multiple data sources. Familiarity with deception technologies, cyber deception strategies, or adversary engagement techniques. Experience supporting highly regulated environments such as financial services. Professional certifications such as CISSP, CISM, GIAC, CDLP, GCFA, GCIH, or equivalent. Degree in cybersecurity, intelligence studies, psychology, criminal justice, information systems, or related field. What You Can Expect at MassMutual MassMutual offers the opportunity to do meaningful work within a purpose-driven organization that values long-term impact over short-term outcomes. In this role, you can expect: Clear areas of ownership and accountability, with work that connects directly to company and customer outcomes A collaborative environment where perspectives are welcomed Access to learning, development, and internal networks that support continuous growth and skill-building over time Employee-led communities and forums that foster connection, learning, and inclusion across the organization A culture grounded in integrity, responsibility, and stewardship-supported by a company with a strong legacy and a future-focused mindset MassMutual is an equal employment opportunity employer. We welcome all persons to apply. If you need an accommodation to complete the application process, please contact us and share the specifics of the assistance you need. California residents: For detailed information about your rights under the California Consumer Privacy Act (CCPA), please visit our California Consumer Privacy Act Disclosures page.
Consultant, Insider Threat Enterprise Cyber Security Full Time, Springfield MA (Hybrid) The Opportunity MassMutual is advancing an enterprise Insider Threat program focused on identifying and managing human-driven cyber risk. The Insider Threat Consultant will play a key role in developing the asset intelligence, monitoring strategies, detection capabilities, and investigative processes necessary to identify and manage insider-driven risk. This role combines deep technical expertise, critical asset analysis, behavioral risk assessment, and investigative discipline to understand how people interact with sensitive assets and to identify patterns of activity that may indicate elevated risk. The consultant will partner with cybersecurity operations, detection engineering, HR, Legal, Privacy, and business stakeholders to align monitoring and investigative capabilities with asset sensitivity and business impact. This position is suited for an experienced practitioner who can operate across technical, analytical, and investigative domains while helping build and mature an enterprise-scale insider threat program. The Team The Insider Threat team is a specialized cybersecurity function responsible for understanding and managing the risks that trusted individuals may pose to MassMutual's critical assets, systems, information, and operations. The team operates at the intersection of critical asset protection, identity and access management, behavioral analytics, cyber defense, investigations, and workforce risk. Team members develop the intelligence, monitoring strategies, detection capabilities, investigative processes, and analytical frameworks necessary to identify and reduce insider-driven risk. The team partners closely with Cyber Operations, Detection Engineering, Human Resources, Legal, Privacy, Compliance, Fraud Operations, and business stakeholders to ensure insider risk is identified, assessed, and managed in a consistent, defensible, and risk-informed manner. The Impact The Insider Threat Consultant will: Identify and prioritize critical assets requiring enhanced monitoring and protection. Analyze how critical assets are accessed, used, and shared across the enterprise. Map relationships between identities, access privileges, business processes, and critical assets. Analyze behavioral and technical indicators associated with insider risk. Identify patterns of activity that may indicate misuse or mishandling of critical assets. Conduct and support complex insider threat investigations. Correlate identity, access, asset, and behavioral signals across multiple data sources. Monitor and analyze deception environments and adversary interaction signals. Partner with detection engineering and security operations to develop and refine insider threat detection logic. Contribute to tuning enterprise security tooling to improve identification of insider-driven risk. Support development of early-warning frameworks and proactive risk identification. Produce clear, defensible analytical findings and case documentation. Support executive reporting and enterprise risk visibility. The consultant's work will improve visibility into critical assets, strengthen understanding of user-to-asset trust relationships, increase the fidelity of insider threat detections, and help prevent compromise of the confidentiality, integrity, and availability of MassMutual's most important information and systems. The Minimum Qualifications 8+ years of experience in cybersecurity, insider threat, investigations, intelligence analysis, data protection, enterprise architecture, or related disciplines. 2+ years of experience working cross-functionally with security, HR, Legal, Privacy, business, or investigative stakeholders. Preferred Qualifications Experience supporting or building an Insider Threat Program. Experience supporting Critical Asset Protection, Information Protection, Data Protection, or Human Risk Management initiatives. Experience conducting cyber, digital, fraud, employee misconduct, or insider threat investigations. Experience analyzing logs, endpoint telemetry, identity activity, access patterns, and behavioral signals. Hands-on experience contributing to detection use cases, monitoring strategies, investigative workflows, or security content development. Experience identifying, classifying, mapping, or protecting sensitive information or critical assets. Strong understanding of identity and access management concepts, privileged access, trust relationships, and access governance. Experience with SIEM, EDR, UEBA, DLP, insider risk management, identity security, and security analytics platforms. Experience developing, tuning, or validating detection logic across endpoint, identity, network, and data protection technologies. Experience analyzing user behavior and identifying anomalous or high-risk activity through the correlation of multiple data sources. Familiarity with deception technologies, cyber deception strategies, or adversary engagement techniques. Experience supporting highly regulated environments such as financial services. Professional certifications such as CISSP, CISM, GIAC, CDLP, GCFA, GCIH, or equivalent. Degree in cybersecurity, intelligence studies, psychology, criminal justice, information systems, or related field. What You Can Expect at MassMutual MassMutual offers the opportunity to do meaningful work within a purpose-driven organization that values long-term impact over short-term outcomes. In this role, you can expect: Clear areas of ownership and accountability, with work that connects directly to company and customer outcomes A collaborative environment where perspectives are welcomed Access to learning, development, and internal networks that support continuous growth and skill-building over time Employee-led communities and forums that foster connection, learning, and inclusion across the organization A culture grounded in integrity, responsibility, and stewardship-supported by a company with a strong legacy and a future-focused mindset MassMutual is an equal employment opportunity employer. We welcome all persons to apply. If you need an accommodation to complete the application process, please contact us and share the specifics of the assistance you need. California residents: For detailed information about your rights under the California Consumer Privacy Act (CCPA), please visit our California Consumer Privacy Act Disclosures page.
08/04/2026
Full time
Consultant, Insider Threat Enterprise Cyber Security Full Time, Springfield MA (Hybrid) The Opportunity MassMutual is advancing an enterprise Insider Threat program focused on identifying and managing human-driven cyber risk. The Insider Threat Consultant will play a key role in developing the asset intelligence, monitoring strategies, detection capabilities, and investigative processes necessary to identify and manage insider-driven risk. This role combines deep technical expertise, critical asset analysis, behavioral risk assessment, and investigative discipline to understand how people interact with sensitive assets and to identify patterns of activity that may indicate elevated risk. The consultant will partner with cybersecurity operations, detection engineering, HR, Legal, Privacy, and business stakeholders to align monitoring and investigative capabilities with asset sensitivity and business impact. This position is suited for an experienced practitioner who can operate across technical, analytical, and investigative domains while helping build and mature an enterprise-scale insider threat program. The Team The Insider Threat team is a specialized cybersecurity function responsible for understanding and managing the risks that trusted individuals may pose to MassMutual's critical assets, systems, information, and operations. The team operates at the intersection of critical asset protection, identity and access management, behavioral analytics, cyber defense, investigations, and workforce risk. Team members develop the intelligence, monitoring strategies, detection capabilities, investigative processes, and analytical frameworks necessary to identify and reduce insider-driven risk. The team partners closely with Cyber Operations, Detection Engineering, Human Resources, Legal, Privacy, Compliance, Fraud Operations, and business stakeholders to ensure insider risk is identified, assessed, and managed in a consistent, defensible, and risk-informed manner. The Impact The Insider Threat Consultant will: Identify and prioritize critical assets requiring enhanced monitoring and protection. Analyze how critical assets are accessed, used, and shared across the enterprise. Map relationships between identities, access privileges, business processes, and critical assets. Analyze behavioral and technical indicators associated with insider risk. Identify patterns of activity that may indicate misuse or mishandling of critical assets. Conduct and support complex insider threat investigations. Correlate identity, access, asset, and behavioral signals across multiple data sources. Monitor and analyze deception environments and adversary interaction signals. Partner with detection engineering and security operations to develop and refine insider threat detection logic. Contribute to tuning enterprise security tooling to improve identification of insider-driven risk. Support development of early-warning frameworks and proactive risk identification. Produce clear, defensible analytical findings and case documentation. Support executive reporting and enterprise risk visibility. The consultant's work will improve visibility into critical assets, strengthen understanding of user-to-asset trust relationships, increase the fidelity of insider threat detections, and help prevent compromise of the confidentiality, integrity, and availability of MassMutual's most important information and systems. The Minimum Qualifications 8+ years of experience in cybersecurity, insider threat, investigations, intelligence analysis, data protection, enterprise architecture, or related disciplines. 2+ years of experience working cross-functionally with security, HR, Legal, Privacy, business, or investigative stakeholders. Preferred Qualifications Experience supporting or building an Insider Threat Program. Experience supporting Critical Asset Protection, Information Protection, Data Protection, or Human Risk Management initiatives. Experience conducting cyber, digital, fraud, employee misconduct, or insider threat investigations. Experience analyzing logs, endpoint telemetry, identity activity, access patterns, and behavioral signals. Hands-on experience contributing to detection use cases, monitoring strategies, investigative workflows, or security content development. Experience identifying, classifying, mapping, or protecting sensitive information or critical assets. Strong understanding of identity and access management concepts, privileged access, trust relationships, and access governance. Experience with SIEM, EDR, UEBA, DLP, insider risk management, identity security, and security analytics platforms. Experience developing, tuning, or validating detection logic across endpoint, identity, network, and data protection technologies. Experience analyzing user behavior and identifying anomalous or high-risk activity through the correlation of multiple data sources. Familiarity with deception technologies, cyber deception strategies, or adversary engagement techniques. Experience supporting highly regulated environments such as financial services. Professional certifications such as CISSP, CISM, GIAC, CDLP, GCFA, GCIH, or equivalent. Degree in cybersecurity, intelligence studies, psychology, criminal justice, information systems, or related field. What You Can Expect at MassMutual MassMutual offers the opportunity to do meaningful work within a purpose-driven organization that values long-term impact over short-term outcomes. In this role, you can expect: Clear areas of ownership and accountability, with work that connects directly to company and customer outcomes A collaborative environment where perspectives are welcomed Access to learning, development, and internal networks that support continuous growth and skill-building over time Employee-led communities and forums that foster connection, learning, and inclusion across the organization A culture grounded in integrity, responsibility, and stewardship-supported by a company with a strong legacy and a future-focused mindset MassMutual is an equal employment opportunity employer. We welcome all persons to apply. If you need an accommodation to complete the application process, please contact us and share the specifics of the assistance you need. California residents: For detailed information about your rights under the California Consumer Privacy Act (CCPA), please visit our California Consumer Privacy Act Disclosures page.