This position is an onsite position and available to be filled at any Huntington Corporate office location (see location options on posting)
Summary:
The Senior Manager of Insider Risk and Digital Forensics is responsible for the strategic leadership, maturity, and day-to-day execution of the enterprise Insider Threat Program. This role leads the development of capabilities designed to identify, detect, investigate, and mitigate insider risk while protecting the organization's people, data, intellectual property, and critical assets.
A successful candidate will partner across Cybersecurity, Human Resources, Legal, Privacy, Risk Management, Compliance, and Technology teams to establish a comprehensive, intelligence-driven insider risk program that leverages behavioral analytics, AI-driven detection capabilities, threat intelligence, and advanced monitoring technologies. This leader will oversee investigations, drive program innovation, and provide strategic guidance to executive leadership regarding emerging insider threats and associated business risks.
Duties and Responsibilities:
Lead the strategic direction, maturity, and execution of the enterprise Insider Threat Program.
Develop and maintain multi-year insider risk roadmaps, operating models, governance structures, and performance metrics.
Identify opportunities to enhance insider risk capabilities through automation, AI, machine learning, and advanced analytics.
Establish program objectives aligned with enterprise cybersecurity, risk management, legal, privacy, and regulatory requirements.
Serve as the primary advisor to senior leadership on insider risk matters, emerging threats, and program effectiveness.
Lead a team responsible for the triage, investigation, remediation, and closure of insider risk and digital forensics investigations.
Oversee complex investigations involving:
Data exfiltration
Intellectual property theft
Unauthorized access
Fraud
Policy violations
Misuse of privileged access
Ensure investigations are conducted with forensic rigor, appropriate evidence handling, and chain-of-custody standards.
Coordinate response activities and remediation efforts with HR, Employee Relations, Legal, Ethics, Privacy, Security, and Technology teams.
Detection Engineering & Analytics
Design and enhance insider risk detection capabilities using:
Security Information and Event Management (SIEM)
User and Entity Behavior Analytics (UEBA)
Data Loss Prevention (DLP)
Threat Intelligence Platforms
AI and advanced analytics solutions
Develop behavioral analytics and risk scoring models to identify high-risk users and activities.
Create and optimize detection use cases, monitoring processes, investigation workflows, and escalation procedures.
Drive continuous improvement of detection accuracy and investigation efficiency.
AI & Emerging Threat Management
Support the development of AI-enabled insider risk monitoring and detection strategies.
Assess risks associated with generative AI, unauthorized AI usage, and emerging technology threats.
Leverage advanced analytics to identify abnormal behavioral patterns and emerging insider threat indicators.
Evaluate new technologies to enhance insider risk visibility, automation, and response capabilities.
Governance, Risk & Compliance
Ensure insider risk controls align with enterprise governance and risk management frameworks.
Incorporate industry best practices and frameworks, including:
CERT Insider Threat Framework
National Insider Threat Task Force (NITTF) Guidelines
MITRE ATT&CK Framework
Support regulatory examinations, audits, assessments, and compliance activities.
Develop and maintain insider threat policies, standards, procedures, and playbooks.
Cross-Functional Collaboration
Build strong partnerships with Human Resources, Legal, Privacy, Compliance, Enterprise Risk, Physical Security, and Technology leadership.
Lead workshops, interviews, and process reviews to gather requirements and drive program improvements.
Facilitate executive discussions related to insider risk events, trends, and strategic initiatives.
Represent the organization in industry forums and working groups to benchmark capabilities and identify emerging best practices.
Reporting & Executive Communication
Deliver executive-level reporting on:
Program maturity
Investigation outcomes
Emerging risk trends
Key performance indicators
Regulatory and compliance considerations
Translate technical findings into concise business-focused narratives for executives, auditors, and regulators.
Present strategic recommendations and risk assessments to senior leadership.
Awareness & Culture
Develop insider risk awareness and training programs.
Promote a culture of security, accountability, and responsible data handling.
Lead insider risk tabletop exercises and simulation activities to validate program readiness and response effectiveness.
Basic Qualifications:
4+ years of experience in leading insider risk, DLP, cyber investigations, or threat management programs.
2+ years of experience with SIEM, UEBA, DLP, case management, and investigative technologies.
2+ years of experience leading teams and managing complex, high-impact investigations.
Associate's Degree or 4+ additional years of equivalent experience.
Preferred Qualifications:
Strong understanding of insider threat methodologies, behavioral analytics, and cyber threat intelligence.
Experience partnering with HR, Legal, Privacy, Compliance, and Risk functions.
Financial services or highly regulated industry experience.
Experience implementing AI-driven security monitoring and insider risk capabilities.
Experience with digital forensics, incident response, and data protection technologies.
Knowledge of privacy regulations, governance frameworks, and regulatory requirements.
Strong written and verbal communication skills
Bachelor's Degree or 4+ additional years of equivalent experience.
Exempt Status: (Yes = not eligible for overtime pay) (No = eligible for overtime pay)
Workplace Type:
OfficeOur Approach to Office Workplace Type
Certain positions outside our branch network may be eligible for a flexible work arrangement. We’re combining the best of both worlds: in-office and work from home. Our approach enables our teams to deepen connections, maintain a strong community, and do their best work. Remote roles will also have the opportunity to come together in our offices for moments that matter. Specific work arrangements will be provided by the hiring team.
Huntington is an Equal Opportunity Employer.
Tobacco-Free Hiring Practice: Visit Huntington's Career Web Site for more details.
Note to Agency Recruiters: Huntington Bank will not pay a fee for any placement resulting from the receipt of an unsolicited resume. All unsolicited resumes sent to any Huntington Bank colleagues, directly or indirectly, will be considered Huntington Bank property. Recruiting agencies must have a valid, written and fully executed Master Service Agreement and Statement of Work for consideration.