1

Insider Risk Jobs in Florida (NOW HIRING)

... Insider Risk Management). * Participate in requirements gathering, workshops, and documentation efforts. * Execute assigned tasks within project plans and contribute to on-time, high-quality delivery.

... Insider Risk Management). * Participate in requirements gathering, workshops, and documentation efforts. * Execute assigned tasks within project plans and contribute to on-time, high-quality delivery.

... Insider Risk Management). * Participate in requirements gathering, workshops, and documentation efforts. * Execute assigned tasks within project plans and contribute to on-time, high-quality delivery.

... insider risk management. Varonis protects data first, not last. Learn more atwww.varonis.com. The Role: As a Business Operations Analyst, you will be responsible for supporting revenue business units ...

Microsoft Purview (data governance, data classification, DLP, insider risk concepts). * Power Platform security model: * Environment strategy, tenant isolation, connector governance * Data loss ...

Showing results 21-40

Insider Risk information

What is an insider risk professional?

An Insider Risk professional is responsible for identifying, assessing, and mitigating threats posed by individuals within an organization, such as employees, contractors, or business partners. These threats can include data theft, fraud, sabotage, or unintentional errors that could harm the company. Insider Risk professionals develop policies, monitor user behavior, and implement security controls to protect sensitive information and assets. Their goal is to balance organizational security with privacy and productivity.

What are the key skills and qualifications needed to thrive as an insider risk analyst, and why are they important?

To thrive as an Insider Risk Analyst, you need a solid background in information security, risk assessment, and data analysis, often supported by a degree in cybersecurity or a related field. Familiarity with security information and event management (SIEM) tools, user behavior analytics, and certifications such as CISSP or CISA are commonly required. Strong analytical thinking, discretion, and communication skills are crucial for identifying threats and collaborating with cross-functional teams. These skills ensure prompt detection and mitigation of internal security threats, protecting organizational assets and data integrity.

What are some common challenges faced by professionals in insider risk roles, and how can they be addressed?

Professionals in Insider Risk roles often face challenges such as balancing employee privacy with security needs, detecting subtle behavioral indicators of risk, and fostering a culture of trust while enforcing policies. Addressing these challenges requires strong communication skills, collaboration with HR and IT departments, and the utilization of advanced monitoring tools that respect privacy regulations. Additionally, ongoing training and clear protocols help teams respond effectively while maintaining organizational transparency.

What is the difference between Insider Risk vs Insider Threat Analyst?

AspectInsider RiskInsider Threat Analyst
Primary FocusIdentifying and managing potential risks posed by insiders to prevent security breachesDetecting, analyzing, and responding to insider threats and security incidents
Required CredentialsSecurity certifications (CISSP, CISA), risk management experienceCybersecurity certifications (CEH, GIAC), threat analysis experience
Work EnvironmentRisk management teams, security departments, corporate settingsSecurity operations centers, incident response teams, cybersecurity units

Insider Risk professionals focus on proactively identifying and mitigating potential insider-related threats, emphasizing risk management strategies. In contrast, Insider Threat Analysts are more involved in detecting and responding to actual threats and security incidents. Both roles require cybersecurity knowledge and certifications but differ in their primary responsibilities within security teams.

What does an insider risk analyst do?

An insider risk analyst monitors and investigates potential threats from employees or trusted individuals who may intentionally or unintentionally compromise an organization’s security. They analyze data, use security tools, and develop strategies to detect, prevent, and respond to insider threats, often working with cybersecurity teams and requiring knowledge of risk management and security protocols.

What job categories do people searching Insider Risk jobs in Florida look for?

The top searched job categories for Insider Risk jobs in Florida are:

Infographic showing various Insider Risk job openings in Florida as of August 2026, with employment types broken down into 1% As Needed, 86% Full Time, 10% Part Time, and 3% Contract. Highlights an 87% Physical, 5% Hybrid, and 8% Remote job distribution.

Full-time

Posted 19 days ago


Morgan & Morgan rating

6.7

Company rating: 6.7 out of 10

Based on 49 frontline employees who took The Breakroom Quiz

30th of 34 rated law firms


Job description

Cloud Security Engineer 

Location: Orlando, FL or Tampa, FL (Onsite, Full-Time)

Work Arrangement: This is an in-office position, open to local candidates only.

About the Role

Our firm is a large, multi-state law practice with a sophisticated technology environment and a deep responsibility to protect highly sensitive client and matter data. We are seeking a Cloud Security Engineer to strengthen and mature our Microsoft-centered security program. This is a hands-on engineering role for someone who thrives on threat detection, tenant hardening, identity modernization, and security automation - and who can clearly communicate risk and remediation to both technical teams and firm leadership.

Key ResponsibilitiesDetection and Response
  • Engineer, tune, and operate detections and response workflows across Microsoft Defender XDR and Microsoft Sentinel, including authoring and optimizing KQL queries, analytics rules, workbooks, and hunting content.
Tenant and Endpoint Hardening
  • Lead and execute M365 tenant hardening initiatives across the E5 stack, establishing and maintaining secure baselines and configuration standards.
  • Administer and harden endpoint security through Microsoft Defender for Endpoint and Intune, including device compliance, configuration profiles, and attack surface reduction.
Security Automation and Vulnerability Management
  • Build and maintain security automation (e.g., Logic Apps, automation rules/playbooks, PowerShell, Azure Functions) to reduce manual effort and accelerate response.
  • Own vulnerability assessment and remediation tracking, partnering with IT and infrastructure teams to close gaps.
Cloud, Identity, and Data Governance
  • Secure and govern Azure infrastructure, applying cloud security best practices across resources and workloads.
  • Configure and manage Microsoft Purview for data governance, information protection, data loss prevention, insider risk, and compliance.
  • Strengthen identity and access management (IAM) practices firm-wide, including least-privilege enforcement and access reviews.
AI Security and Documentation
  • Secure and govern AI and AI agents across the firm, addressing data exposure, identity and access for agents, acceptable-use controls, and the confidentiality and privilege concerns unique to a legal environment.
  • Document standards, procedures, and runbooks; communicate security posture, incidents, and recommendations clearly to technical staff and firm leadership.
  • Manage application security assessments and lifecycle oversight to retire applications that are inactive or pose security risks.
Qualifications
  • Strong hands-on expertise across: Defender XDR enterprise defense suite and Microsoft Sentinel with proficient KQL; M365 tenant hardening (Entra ID, Exchange, Teams, SharePoint); Azure infrastructure security; security automation (SOAR); Entra ID and Conditional Access; vulnerability assessment; Defender for Endpoint, Intune, Application Control; and Microsoft Purview (DSPM, IP, DLP, IRM, DLM, AI).
  • Strong technical, organizational, time-management, and communication skills.
  • Participate in scheduled after-hours changes as needed.
Education and Experience
  • Experience at a law firm or in a similarly regulated, confidentiality-driven environment.
  • Demonstrated experience securing AWS and/or GCP environments in enterprise settings.
  • Experience designing and implementing security controls for AI and agent-based workloads.
  • 4-7+ years of experience as a Security Engineer at a large, multi-state organization.

#LI-MB1


What Morgan & Morgan employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom