1

Insider Risk Manager Jobs in Lancaster, TX (NOW HIRING)

Senior Security Engineer

Plano, TX · On-site

$109K - $150K/yr

Qualifications * 5+ years in security engineering, with direct hands-on experience configuring Microsoft 365 security tooling (Purview DLP, sensitivity labels, Insider Risk Management, Audit) and ...

TAMs are accountable for translating Varonis capabilities into reduced risk, controlled access, and ... insider threats, cyber-attacks, and policy violations * Help customers identify and mitigate risks ...

TAMs are accountable for translating Varonis capabilities into reduced risk, controlled access, and ... insider threats, cyber-attacks, and policy violations * Help customers identify and mitigate risks ...

Cybersecurity Manager

Dallas, TX · On-site

$109K - $148K/yr

Manage an insider threat program, including data loss prevention * Oversee SOC analysts' response ... Support application security scanning and vulnerability risk analysis * Manage threat hunting and ...

... ransomware groups, insider threats, and emerging AI-enabled attack techniques. Translate ... Drive innovation while ensuring exercises remain aligned with business objectives and risk ...

Showing results 21-40

Insider Risk Manager information

See Lancaster, TX salary details

$48.8K

$105.8K

$161.2K

How much do insider risk manager jobs pay per year?

As of Aug 18, 2026, the average yearly pay for insider risk manager in Lancaster, TX is $105,756.00, according to ZipRecruiter salary data. Most workers in this role earn between $85,300.00 and $122,300.00 per year, depending on experience, location, and employer.

What does an insider risk manager do?

An Insider Risk Manager is responsible for identifying, assessing, and mitigating risks posed by individuals within an organization, such as employees, contractors, or business partners. Their work focuses on preventing data breaches, intellectual property theft, and other security incidents caused by trusted insiders. They develop policies, conduct investigations, monitor employee activity for suspicious behavior, and collaborate with other departments to strengthen security measures. Ultimately, their goal is to protect the organization's assets and reputation from internal threats.

What are some common challenges faced by an insider risk manager, and how can they be addressed?

Insider Risk Managers often face challenges such as detecting subtle behavioral changes that may signal insider threats, balancing employee privacy with effective monitoring, and fostering a culture of security awareness. Addressing these challenges typically involves working closely with IT, HR, and legal teams to implement risk assessment tools, develop clear communication strategies, and provide regular training. Additionally, staying updated on the latest threat trends and maintaining transparent incident response protocols help Insider Risk Managers mitigate potential risks effectively.

What are the key skills and qualifications needed to thrive as an insider risk manager, and why are they important?

To thrive as an Insider Risk Manager, you need expertise in cybersecurity, risk assessment, and incident response, often supported by a degree in information security or a related field. Familiarity with SIEM tools, DLP systems, and certifications like CISSP or CISM are typically required. Strong analytical thinking, discretion, and communication skills help in identifying threats and collaborating with stakeholders. These skills ensure effective mitigation of insider threats, protecting organizational assets and sensitive information.

What is the difference between Insider Risk Manager vs Data Loss Prevention Specialist?

AspectInsider Risk ManagerData Loss Prevention Specialist
CredentialsSecurity certifications (CISSP, CISM), risk management experienceSecurity certifications, technical knowledge of DLP tools
Work EnvironmentCorporate security teams, risk assessment settingsIT security teams, technical implementation roles
Industry UsageFinancial, healthcare, government sectorsTech, finance, enterprise sectors
Primary FocusIdentifying and mitigating insider threatsPreventing data exfiltration and leaks

The Insider Risk Manager focuses on detecting and managing risks posed by internal employees, while the Data Loss Prevention Specialist concentrates on technical measures to prevent data leaks. Both roles require security certifications and are vital in protecting organizational assets, but they differ in scope and daily responsibilities.

What cities near Lancaster, TX are hiring for Insider Risk Manager jobs?

Cities near Lancaster, TX with the most Insider Risk Manager job openings:

Senior Security Engineer

Vailexa

Plano, TX • On-site

$109K - $150K/yr

Full-time

Posted 21 days ago


Job description

Build More Than Just a Career. Build Your Future.

At Vailexa, we're not just hiring — we're building thinkers, creators, and future leaders.

We believe in giving people the space to grow, the freedom to think, and the opportunity to create real impact from day one. If you're someone who wants to learn fast, take ownership, and grow beyond limits, you'll feel right at home here.

  • Client is seeking a Senior Security Engineer to support a broader enterprise data security program focused on identifying, classifying, labeling, and remediating sensitive data exposure across Microsoft 365 environments.
  • This role is not intended to participate directly in a proof-of-value or vendor evaluation effort. Instead, the resource will become part of the remediation workstream that follows discovery and classification, helping the client turn security findings into closed, documented outcomes.
  • The role will work alongside the client's internal security, DLP, and operations teams to triage findings, validate root cause, coordinate corrective action, and support closure of remediation items. The emphasis is on practical execution: understanding what data is exposed, how it should be classified or labeled, what risk it creates, and what action is needed to reduce that risk.
  • This is a core delivery resource for the overall project, with involvement beginning during data discovery, classification, tagging, labeling, and remediation planning, then increasing during remediation execution and post-deployment stabilization.
  • Program Context: This engagement supports the client's broader Enterprise Information Management and Data Security objectives. The work should be positioned as a reusable operating model for discovery, classification, labeling, policy alignment, remediation, and ongoing incident response across current and future data security channels.

Responsibilities

  • Support activities including data discovery, classification, tagging, labeling, risk prioritization, and remediation planning.
  • Partner with client security, DLP, SOC, and data governance teams to understand current workflows, ownership models, ticket volume, and remediation hand-offs.
  • Triage findings surfaced through data security tooling, monitoring, or validation activities and help determine the appropriate remediation path.
  • Drive remediation actions to closure, including access changes, policy adjustments, data handling updates, quarantine or containment steps, and coordination with the appropriate operational owners.
  • Coordinate with the SOC and response teams when findings indicate incident response, containment, or escalation requirements.
  • Document remediation decisions, closure evidence, recurring patterns, and operational lessons learned to support audit readiness and future-state process improvement.
  • Provide technical input into the remediation roadmap and target-state data security operating model based on findings encountered during the engagement. Ongoing / Post-Deployment
  • Continue as the primary hands-on remediation and incident-response resource — investigating false positives/negatives, adjusting behavioral baselines, and driving real findings to closure as the environment sees production traffic.
  • Remain the day-to-day working partner to Client's in-house DLP engineer for as long as the engagement continues, rather than handing remediation entirely back to the client after go-live.

Qualifications

  • 5+ years in security engineering, with direct hands-on experience configuring Microsoft 365 security tooling (Purview DLP, sensitivity labels, Insider Risk Management, Audit) and Entra ID.
  • Direct, hands-on remediation experience — not just detection or reporting. Able to take a Cyera or DLP finding and personally drive it to resolution: revoke access, adjust a policy, quarantine data, or take the equivalent corrective action. This is the client's top priority for this role.
  • Practical expertise in Cyera specifically (Client's enterprise-standard DSPM platform) and deep expertise in Microsoft Purview and the broader Microsoft 365 security stack.
  • Working knowledge of SIEM/SOC alerting pipelines and incident response processes — this role is a key hand-off point between DLP/DSPM detection and SOC-driven containment, so understanding both sides matters.
  • Comfort working as a peer alongside a client's existing in-house DLP engineer on shared remediation work, communicating clearly about who is handling what.
  • Demonstrated experience designing or executing controlled, purple-team-style validation exercises in an isolated test environment — not full red-team penetration testing.
  • Practical understanding of common SharePoint/OneDrive incident patterns: compromised-account exfiltration, oversharing/public-link exposure, insider data theft, ransomware via sync clients, malicious OAuth consent grants, and lateral movement via overprivileged access.
  • Ability to translate technical remediation work into clear documentation suitable for both technical and client-facing review.

Preferred:

  • Hands-on experience with both Cyera and Varonis — the client has indicated familiarity with both platforms is a plus, even though Cyera is the enterprise standard for this engagement.
  • Experience with UEBA/behavioral-baseline tooling specifically for insider-risk or departing-employee scenarios.
  • Familiarity with OneDrive sync-client behavior and endpoint EDR correlation for ransomware-pattern detection.
  • Relevant certifications such as GIAC/SANS (e.g., GCIA, GCIH), Microsoft SC-200, or vendor-specific DSPM certifications.
  • Prior experience embedded alongside a client's in-house security/DLP team on an ongoing remediation or hyper care basis, rather than a discrete assessment of engagement.

Ready to take the next step?

If you're excited about this role and ready to grow with a team that values ambition, ideas, and impact — we'd love to hear from you.