Skip to main content

Vice President - Insider Threat UEBA Lead

CLS GroupSecuritySecurity
Work mode
Hybrid
Full Time
Location
Experience
8+ yrs
Bachelor's

Iselin, NJ at a glance

Rent
#6 of 51
$2,300/mo+29% vs US avg
Weather
#24 of 51
146 mild days68 hot · 63 cold
Income tax
#5 of 51
10.75% top rateNew Jersey

What you need

  • 8+ yrs in information security roles
  • 3+ yrs of Insider Threat experience
  • Bachelor’s degree in Cybersecurity or related discipline
  • Security certification (e.g. SANS, ISC2, ISACA)
  • Experience with UEBA, SIEM, EDR, DLP tools

What you'll do

  • Integrate UEBA with SIEM, SOAR, EDR, DLP
  • Monitor user risk scores and tune logic
  • Drive insider threat investigations and incident response
  • Conduct proactive threat hunting using UEBA data
  • Develop insider threat tools and detection standards

About CLS:

CLS is the trusted party at the centre of the global FX ecosystem.  Utilized by thousands of counterparties, CLS makes FX safer, smoother and more cost effective.  Trillions of dollars’ worth of currency flows through our systems each day. 

Created by the market for the market, our unrivalled global settlement infrastructure reduces systemic risk and provides standardization for participants in many of the world’s most actively traded currencies.  We deliver huge efficiencies and savings for our clients: in fact, our approach to multilateral netting shrinks funding requirements by over 96% on average, so clients can put their capital and resources to better use.

CLS products are designed to enable clients to manage risk most effectively across the full FX lifecycle – whether through more efficient processing tools or market intelligence derived from the largest single source of FX executed data available to the market.

Our ambition to make a positive difference starts with our people.  Our values underpin everything that we do at CLS and define our working environment:

  • Pivotal purpose
  • Trusted guardian
  • Targeted innovation
  • Facilitate connections
  • Delivering excellence
  • Inclusive culture

Job information:

  • · Functional title - UEBA Use Case Developer/Manager UEBA
  • Department – IT Security
  • Corporate level – Vice President
  • Report to – Director of Insider Threat
  • Location - Iselin, New Jersey
  • Compensation – $143,000 - 166,000 base salary + variable compensation + 401(k) match + benefits

 

Overview of the role:  

CLS is seeking a highly motivated, and skilled Vice President - UEBA (User Entity Behavioral Analysis) Use Case Developer/Manager to join our Insider Threat Team. The role will be located in New Jersey. The position will report to the Director of Insider Threat and will participate in the development, implementation, and continuous improvement of a new Insider Threat team.

This role involves the identification, detection and investigation of abnormal actions from internal accounts which may be indicative of risk posed by individuals with authorized access to organizational assets, including employees and third-party vendors. The position will require collaboration with cross-functional teams to mitigate the risks of malicious, negligent, or unintentional insider actions that could lead to security breaches, data loss, or system unavailability. 

This position requires someone with an analytical mind and data analysis skills, working knowledge of company systems and IT security tools, a quick learner, and the ability to propose and execute on program improvements.  This role will also be responsible for building relationships with organizational partners and conducting investigations.

 

What you will be doing: 

•  Integrate UEBA capabilities with SIEM, SOAR, EDR DLP, and IAM systems.

•  Establish baselines of normal user behaviour across identity, network, endpoint and application activity.

•  Monitor user risk scores and tune detection logic to reduce false positives and improve detection fidelity, identifying and onboarding new telemetry sources.

•   Drive incident response and insider threat investigations with timeline and data analysis.  Conduct proactive behavioural threat hunting using UEBA data.

•   Manage playbook response actions and support investigations of suspected insider threat incidents to include preventative controls and user quarantine actions.

•   Align behavioural monitoring with privacy, legal and HR considerations.

•   Participate in the execution of the insider threat program, including the development of tools, standards, procedures, and processes to detect, prevent, and respond to insider threats.

•  Research advanced detection and monitoring tools to complement existing systems.

•  Drive continuous improvement by integrating lessons learned, industry best practices, and emerging threat intelligence.

•  Collaborate with stakeholders across the firm to evaluate and address potential insider risks across systems, networks, and organizational processes.

•  Participate in investigations and produce reports on insider threat risks, incidents, and mitigation efforts for executives to aid in their decision making.

•  Work with the intelligence team to develop threat modelling deliverables,

·

What we’re looking for: 

Experience

•   8+ years of experience in information security such as Insider Threat, Investigations, Analysis, Security Operations, Incident Response, or Threat Intelligence roles.

•  Experience with insider threat detection tools (UEBA, SIEM, EDR, DLP) and knowledge of advanced threat intelligence techniques.

•  3+ years of experience in Insider Threat or equivalent.

•   Knowledge of fundamentals of threat actors’ TTPs and MITRE ATT&CK Framework.

•  Understanding of security frameworks, incident response, and risk management practice.

•   Knowledge of relevant legal and regulatory considerations, including privacy laws and data protection requirements.

•   Excellent interpersonal and relationship management skills.

·

Professional qualifications / certifications 

•   Bachelor’s Degree in Cybersecurity studies, Information Systems, Computer Science, Business Analytics, Intelligence Studies, Criminology, or related discipline.

•   Experience or the ability to operate & tune security monitoring and analytical tools (e.g.  UEBA, SIEM, EDR, DLP) is highly preferred.

•   Expertise in managing initial incident response and supporting investigations, coordinating with multiple departments, and resolving security incidents efficiently.

•   Security certification through a credentialing organization which demonstrates knowledge of cybersecurity, defense, vulnerabilities, data and operating system security e.g.  SANS, ISC2, ISACA.

•  Experience with threat intelligence and SOC/CIRT interaction.

•  Experience in handling sensitive information.

•  Strong written and verbal communication skills as well as interview skills.

•   Ability to work on-site at least twice a week in New Jersey and/or participate in local intelligence sharing groups. 

•   Financial sector experience.


Our commitment to employees:

At CLS, we celebrate inclusion and consider this to be one of our strongest assets. We are committed to fostering an environment in which everyone feels comfortable to be who they are, and inclusion is valued. All employees have access to our inclusive benefits, including:

  • Holiday - UK/Asia: 25 holiday days and 3 ‘life days’ (in addition to bank holidays). US: 23 holiday days.
  • 2 paid volunteer days so that you can actively support causes within your community that are important to you.
  • Generous parental leave policies to ensure you can enjoy valuable time with your family.
  • Parental transition coaching programmes and support services.
  • Wellbeing and mental health support resources to ensure you are looking after yourself, and able to support others.
  • Employee Networks (including our Women’s Forum, Black Employee Network and Pride Network) in support of our organisational commitment to embrace and always be learning more about inclusivity.
  • Hybrid working to promote a healthy work/life balance, enabling employees to work collaboratively in the office when needed and work from home when they don’t.
  • Active support of flexible working for all employees where possible.
  • Monthly ‘Heads Down Days’ with no meetings across the whole company.
  • Generous non-contributory pension provision for UK/Asia employees, and 401K match from CLS for US employees.
  • Private medical insurance and dental coverage.
  • Social events that give you opportunities to meet new people and broaden your network across the organisation.
  • Annual flu vaccinations.
  • Discounts and savings and cashback across a wide range of categories including health and retail for UK employees.
  • Discounted Gym membership – Complete Body Gym Discount/Sweat equity program for US employees.
  • All employees have access to Discover – our comprehensive learning platform with 1000+ courses from LinkedIn Learning.
  • Access to frequent development sessions on a number of topics to help you be successful and develop your career at CLS.

Optimize your resume for this job

Get a match score and the keywords you're missing

Optimize resume

About CLS Group

CLS (Collecte Localisation Satellites) is a French subsidiary of CNES that provides satellite-based maritime surveillance, environmental monitoring, and Earth observation data services.

Similar Security roles

Vice President - Insider Threat UEBA Lead
CLS Group
Apply