Cybersecurity Engineer - Insider Risk and Forensic Analysis
Job Description
Join a cybersecurity engineering role within the Enterprise Information Security team, focused on insider risk, data loss prevention, and digital forensics. This hybrid position is based in Midvale, Utah, and fosters a collaborative culture that values practical impact, continuous learning, and cross functional teamwork. You will develop monitoring use cases, guide incident response, and lead digital forensic investigations while benefiting from a comprehensive benefits package, a modern sustainable campus, and opportunities to grow your expertise across SIEM, EDR, and forensics platforms.
Benefits
- Medical, dental and vision coverage starting day one
- Life and disability insurance, paid parental leave and adoption assistance
- Health Savings Account, Flexible Spending Account, and dependent care accounts
- Paid training, paid time off and 11 paid federal holidays
- 401(k) with company match and profit sharing
- Mental health benefits including coaching and therapy sessions
- Tuition reimbursement
- Employee ambassador preferred banking products
Responsibilities
- Act as a subject matter expert across enterprise cybersecurity tools and processes, including SIEM, EDR, and forensics platforms
- Design and implement monitoring use cases, insider risk procedures, playbooks, and supporting technical documentation
- Collaborate with Enterprise Cybersecurity Architecture and technology teams on monitoring, alerting infrastructure, processes, and tools
- Train, mentor, and guide other team members on incident response practices and tooling
- Respond to insider risk incidents, serving as an escalation point for high priority or highly complex cases
- Handle sensitive employee information and conduct internal investigations
- Carry out digital forensic collections and investigations for the organization
- Monitor and provide tuning feedback for the cybersecurity toolset
- Other duties as assigned
Requirements
- 2 plus years of progressive technical experience in one or more cybersecurity domains, with a preferred focus on digital forensics or an equivalent education
- Experience with digital forensic evidence collection and investigations
- Experience with insider risk investigations
- Experience resolving DLP incidents
- Hands-on technical experience with one or more industry-standard digital forensic products
- Hands-on technical experience with one or more commercial SIEM products, including defining and writing alert conditions and use cases, and daily incident investigation
- Working knowledge of common attack vectors, different classes of attacks, and typical attack stages
- Effective interpersonal and written communication skills, including the ability to produce technical documentation
- Bachelor’s degree in Information Technology, Computer Science, Business or a related technical field; a combination of education and experience may meet qualifications
Technologies
- SIEM
- EDR
- Digital forensics platforms
- Python
- JavaScript
- PowerShell
- Bash
Location
- Hybrid work from home schedule with a minimum of three days per week in the office at the new Zions Technology Center in Midvale, UT
- The Zions Technology Center is a 400,000-square-foot technology campus in Midvale, Utah
- Located on the former Sharon Steel Mill superfund site, the sustainably built campus serves as the company’s primary technology and operations center
- Electric vehicle charging stations and close proximity to Historic Gardner Village UTA TRAX station
- At least 75% of the building is powered by on-site renewable solar energy
- Access to outdoor recreation, parks, trails, shareable bikes and locker rooms
- Large modern cafe with a healthy and diverse menu
- Healthy indoor environment with ample natural light and fresh air
- LEED-certified sustainable building with low VOC-emitting construction materials
Plus
- Experience with financial institution processes, regulations and technologies is highly preferred
- Familiarity with networking concepts, architectures and tools, including traffic analysis, proxies, switches, load balancers, routers, and firewalls
- Knowledge of Windows and UNIX/Linux system administration concepts
- Development experience with scripting languages such as Python, JavaScript, PowerShell, Bash
- Experience with threat hunting methods and approaches
- Technical certifications such as GCFE, GCFA, CCCE, CFCE, or 13Cubed certifications are a plus
Similar Jobs
J