We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
New

Insider Threat Detection Engineer

KLA
paid time off, tuition reimbursement, 401(k)
United States, Michigan, Ann Arbor
1200 Woodridge Avenue (Show on map)
Mar 28, 2026

Company Overview

KLA is a global leader in diversified electronics for the semiconductor manufacturing ecosystem. Virtually every electronic device in the world is produced using our technologies. No laptop, smartphone, wearable device, voice-controlled gadget, flexible screen, VR device or smart car would have made it into your hands without us. KLA invents systems and solutions for the manufacturing of wafers and reticles, integrated circuits, packaging, printed circuit boards and flat panel displays. The innovative ideas and devices that are advancing humanity all begin with inspiration, research and development. KLA focuses more than average on innovation and we invest 15% of sales back into R&D. Our expert teams of physicists, engineers, data scientists and problem-solvers work together with the world's leading technology providers to accelerate the delivery of tomorrow's electronic devices. Life here is exciting and our teams thrive on tackling really hard problems. There is never a dull moment with us.

Job Description/Preferred Qualifications

The KLA Cybersecurity group defends against cyber-attacks and provides cybersecurity tools, incident response services and assessment capabilities to safeguard the environments that support the essential operations of KLA. We are passionate about identifying adversarial activities and anticipating a wide variety of threats to strengthen our defenses and the overall protection of

KLA Intellectual Property.

We are seeking a qualified Detection Engineer to join our Digital Information Risk team. In this role, you will add, modify and enhance security tool detections. Come join our team in this critical role to protect KLA!

What You Will Be Doing:

This position encompasses a range of technical skills and the ability to work across many different facets of cyber security. You will facilitate interoperability with our legal partners as well as the Security Operations team and IT Daily tasks involve, but are not limited to, creating new policies resulting in hardening overall security posture; modification and tuning of current policies; solving advanced problems by leveraging components of data science, data analytics and information protection fundamentals. Responsibilities include:

  • Handle daily use case management and tuning across insider risk platforms (e.g. SIEM, UEBA, DLP, etc.).

  • Design, deploy, test, and optimize new insider risk policies to reduce and mitigate risks.

  • Collaborate across Cybersecurity, Legal, and HR teams to translate regulatory requirements (GDPR, CCPA, etc.) into technical policies.

  • Engineer automated workflows for incident triage and notification to focus on team efficiencies, ensuring seamless handoffs between automation and insider risk analyst reviews.

  • Correlate events to support insider risk triage and response requirements.

  • Support response, troubleshooting, and investigating security issues that may require additional event details.

  • Keep current with news and threat intelligence related to insider threats and proposed mitigations across the industry to minimize impact.

  • Research, validate and deploy solutions meeting security and business needs.

  • Collaborate with vendors to submit new feature requests and provide a strong voice of the customer.

  • Conduct root cause analyses to drive corrective actions and mitigation after case closure to include identifying opportunities for a change in security controls.

Preferred Qualifications:

  • Cybersecurity certifications such as Certification in Certified Information Systems Security Professional (CISSP).

  • Experience with data analytics tools to identify trends and correlate data sources.

  • Experience with SQL or Python.

  • Experience in developing detection rules and alerts.

  • Ability to read, speak, and write in a foreign language where KLA conducts business.

Minimum Qualifications

  • Completion of a Bachelor's degree from an accredited course of study, in Computer Science, Computer Informatics, Cybersecurity, IT Security, Information Technology or similar.

  • Minimum five (5) years of relevant experience in Cybersecurity

  • Experience with insider risk or similar role monitoring for digital risks such as abuse, fraud, intellectual property theft.

  • Demonstrated experience with UEBA/UBA, DLP, EDR, and SIEM tools.

  • Effective communication, interpersonal skills, and ability to work with partners across the business.

  • Self-sufficient, motivated individual with the ability to calmly operate in high stress environment to meet goals in a timely manner.

  • Proficiency in Microsoft Office suite to analyze data, collaborate with peers, and communicate findings.

Base Pay Range: $90,400.00 - $153,700.00 Annually Primary Location: USA-MI-Ann Arbor-KLA KLA's total rewards package for employees may also include participation in performance incentive programs and eligibility for additional benefits including but not limited to: medical, dental, vision, life, and other voluntary benefits, 401(K) including company matching, employee stock purchase program (ESPP), student debt assistance, tuition reimbursement program, development and career growth opportunities and programs, financial planning benefits, wellness benefits including an employee assistance program (EAP), paid time off and paid company holidays, and family care and bonding leave.

Interns are eligible for some of the benefits listed. Our pay ranges are determined by role, level, and location. The range displayed reflects the pay for this position in the primary location identified in this posting. Actual pay depends on several factors, including state minimum pay wage rates, location, job-related skills, experience, and relevant education level or training. We are committed to complying with all applicable federal and state minimum wage requirements where applicable. If applicable, your recruiter can share more about the specific pay range for your preferred location during the hiring process.

KLA is proud to be an Equal Opportunity Employer. We will ensure that qualified individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us at talent.acquisition@kla.com or at +1-408-352-2808 to request accommodation.

Be aware of potentially fraudulent job postings or suspicious recruiting activity by persons that are currently posing as KLA employees. KLA never asks for any financial compensation to be considered for an interview, to become an employee, or for equipment. Further, KLA does not work with any recruiters or third parties who charge such fees either directly or on behalf of KLA. Please ensure that you have searched KLA's Careers website for legitimate job postings. KLA follows a recruiting process that involves multiple interviews in person or on video conferencing with our hiring managers. If you are concerned that a communication, an interview, an offer of employment, or that an employee is not legitimate, please send an email to talent.acquisition@kla.com to confirm the person you are communicating with is an employee. We take your privacy very seriously and confidentially handle your information.

Applied = 0

(web-bd9584865-vpmzc)