Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AI @ 3
API @ 5
Communication @ 3
Data Engineering @ 3
Data Pipelines @ 3
Go @ 5
Java @ 5
JavaScript @ 5
Mentoring @ 3
Python @ 5
SQL @ 3
Security @ 3
TypeScript @ 5
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
NVIDIA is hiring an Insider Threat Engineer to help protect its people, intellectual property, engineering systems, and data, including source code, hardware and software designs, AI models and artifacts, research, build systems, and computing environments. The role combines security engineering with insider-threat investigations across identity, endpoint, cloud, collaboration, source-code, and data-protection systems. The successful candidate will write code, analyze complex activity, handle sensitive information carefully, and distinguish facts from assumptions while working with Security, Legal, HR, Privacy, IT, and engineering teams.
Responsibilities
- Build, test, deploy, and tune detections across identity, endpoint, cloud, SaaS, collaboration platforms, source-code repositories, build systems, removable media, data movement, and employee-lifecycle signals.
- Lead and support investigations involving unusual data movement, unapproved application use, external sharing, access anomalies, compromised accounts, employee transitions, and other defined insider-risk scenarios.
- Collect and correlate information from endpoint, identity, cloud, source-code, collaboration, data-protection, and approved business sources to reconstruct activity and establish timelines.
- Develop automation, data pipelines, integrations, dashboards, and investigation tools that reduce manual work and improve investigation consistency and efficiency.
- Operate and improve insider-risk and data loss prevention capabilities by assessing policy performance, detection coverage, alert quality, false positives, and connections to case-management workflows.
- Use documented hypotheses, threat models, test cases, version control, peer review, and performance measures to improve detections; work with system owners to address gaps in telemetry or controls.
- Present findings that distinguish facts from inferences and explain confidence levels, data limitations, alternative explanations, and unanswered questions to Security, Incident Response, Legal, HR, Privacy, and business partners.
- Work with authorized partners on evidence preservation, containment, escalation, and remediation while following requirements for investigative scope, access, confidentiality, auditing, and retention.
Requirements
- Bachelor’s degree in Computer Science, Cybersecurity, Information Security, Data Engineering, or a related field, or equivalent experience.
- At least 7 years of experience in insider threat, detection engineering, security operations, incident response, digital forensics, data protection, threat hunting, or a related security field.
- Experience conducting security investigations, including defining scope, collecting evidence, developing timelines, analyzing activity, documenting findings, escalating concerns, and applying lessons learned.
- Experience with security technologies such as SIEM, DLP, UEBA, EDR, insider-risk management, identity security, case management, or security orchestration.
- Proficiency in at least one programming or scripting language, such as Python, Go, Java, JavaScript, or TypeScript, with experience building automation using APIs, structured data, source control, and testing.
- SQL, security-query, and data-analysis skills, including experience correlating incomplete or inconsistent data from multiple sources.
- Knowledge of identity and access management, endpoints, cloud services, collaboration platforms, SaaS integrations, data classification, source-code environments, and data-exfiltration methods.
- Experience translating insider-risk scenarios into telemetry requirements, detection logic, investigation workflows, controls, test cases, and performance measures.
- Ability to assess activity objectively, distinguish indicators from substantiated findings, avoid assumptions about intent, and explain the limits of available evidence.
- Clear written and verbal communication and experience working with technical, legal, privacy, HR, and business partners on sensitive matters.
Preferred Qualifications
- Experience engineering insider-risk, data loss prevention, or endpoint data-protection capabilities and connecting their signals to SIEM, orchestration, enrichment, or case-management systems.
- Experience investigating data movement across email, cloud storage, collaboration tools, source-code repositories, build systems, artifact stores, removable media, browsers, AI tools, and unmanaged or partially managed environments.
- Experience building security data pipelines, entity timelines, relationship models, behavioral baselines, or applications used by investigators.
- Knowledge of digital forensics, evidence preservation, chain of custody, incident-response coordination, and the legal, privacy, and employee-relations requirements associated with workforce investigations.
- Experience turning investigation needs into technical capabilities. Senior candidates may also bring experience leading projects, reviewing designs, and mentoring engineers or investigators.
Compensation and Benefits
The base salary is determined by location, experience, and the pay of employees in similar positions. The base salary range is USD 168,000–270,250 for Level 4 and USD 196,000–310,500 for Level 5. The role is also eligible for equity and benefits. Applications will be accepted at least until August 21, 2026. This posting is for an existing vacancy. NVIDIA uses AI tools in its recruiting processes and is an equal opportunity employer.