Cybersecurity Analyst
Job Description
Insider Risk Analyst position at UnitedHealth Group in Eden Prairie, MN (hybrid) with a salary range of USD 72,800 to 130,000 per year.
Responsibilities
- Track user behavior, system logs, and alerts to spot indicators of insider risk, including data exfiltration, improper access, policy violations, or negligent actions.
- Conduct analytical triage on insider risk alerts generated by enterprise security tools such as SIEM, DLP, endpoints, identity, and email platforms.
- Define normal user behavior baselines and flag deviations that may signal insider risk activity.
- Perform insider risk investigations by collecting, correlating, and analyzing data from diverse technical and non-technical sources.
- Document investigation results, timelines, and conclusions following Insider Risk Program procedures and records-retention requirements.
- Produce clear, concise investigative summaries and risk assessments for leadership and stakeholders.
- Examine logs, email activity, file access, web usage, and authentication events to support investigations.
- Assist with digital forensic data collection and analysis for insider risk cases as appropriate.
- Develop and maintain queries, dashboards, and analytical workflows to improve detection efficiency and investigation quality.
- Collaborate with HR, Legal, Compliance, Employee Relations, Privacy, and Information Security during reviews and investigations.
- Support escalation and coordination with Enterprise Information Security for incidents requiring broader security response.
- Participate in insider risk working groups and contribute to program governance activities.
- Contribute to the development and enhancement of insider risk policies, procedures, and standard operating processes.
- Assist in defining insider risk indicators, metrics, and reporting to advance program maturity.
- Support audits, assessments, and program evaluations related to insider risk management.
Requirements
- Bachelor's degree in Cybersecurity, Information Security, Computer Science, Criminal Justice, or a related field.
- At least 3 years of experience in cybersecurity.
- 3+ years of experience in security analysis, investigations, insider risk, threat analysis, or digital forensics.
- 2+ years of hands-on experience with security logs, user activity monitoring, and investigative techniques.
- 2+ years of experience documenting findings clearly and communicating effectively with both technical and non-technical audiences.
Technologies
- Splunk
- Sentinel
Benefits
- Comprehensive benefits package
- Incentive and recognition programs
- Equity stock purchase plan
- 401(k) contribution
Soft Skills
- Strong analytical and critical thinking abilities with objective risk assessment
- Proven discretion and professionalism in handling sensitive information