Staff Threat Protection Engineer

cribl· IT & Security
Apply Now ↗
🌍 Remote📍 Remote - United States💰 USD 128K–200K

About this role

Join the company that’s building the telemetry infrastructure for the AI era. At Cribl, we partner with IT and Security teams at many of the world’s biggest enterprises, including half of the Fortune 100, to bridge the gap between AI ambition and infrastructure reality. As the AI Platform for Telemetry, we give customers the choice, control, and flexibility to manage and analyze telemetry for both humans and agents, so they can build what’s next.

We’re one of the fastest‑growing private companies and a leading player in a massive, fast‑moving market. With a global workforce, we’re remote‑first and grounded in a simple idea: software is a people business. Cribl is the place where curious, collaborative people can do their best work, grow fast, and bring their full selves to the herd.

Why You’ll Love This Role

We're looking for a staff-level investigator who operates at the intersection of insider threat, digital/hardware forensics, and executive protection. This is a hybrid role for someone who has led complex insider risk cases end-to-end, can walk into a forensic exam and brief executives in the same week, and is equally comfortable planning a principal's travel security as they are imaging a hard drive for a legal hold. You'll be the senior technical and investigative resource on a small, high-trust team, and you'll help mature our insider risk, forensics, and physical security programs.


As An Active Member Of Our Team, You Will…

Insider Threat & Investigations

  • Lead insider risk investigations from initial detection through closure, including scoping, evidence collection, interviews, findings, and remediation recommendations
  • Partner closely with HR, Legal, and Employee Relations to ensure investigations are conducted defensibly, confidentially, and in compliance with employment law and privacy requirements
  • Build and mature insider risk program components: detection use cases, escalation criteria, case management workflows, and cross-functional playbooks
  • Brief sensitive findings to senior stakeholders (Legal, HR, executive leadership) with appropriate discretion and documentation

Digital & Hardware Forensics

  • Conduct forensic acquisition and analysis of laptops, mobile devices, removable media, and network artifacts in support of investigations
  • Maintain chain of custody and produce forensically sound, litigation-ready documentation
  • Perform hardware-level forensics (disk imaging, device teardown/analysis, embedded storage) in addition to standard digital forensics
  • Apply and maintain relevant certifications (IACIS CFCE or equivalent; EnCE, GCFE, or similar strongly preferred)

Physical Security & Executive Protection

  • Provide executive protection coverage for principals during domestic and international travel and at company events and conferences.
  • Lead security planning for company conferences and events
  • Conduct pre-travel intelligence and risk assessments (geopolitical, environmental, venue-specific) to inform protective planning
  • Coordinate directly with executive assistants on itineraries, logistics, and advance planning to ensure protection is seamless and low-friction
  • Support physical security assessments of office locations, facilities and events, identifying and mitigating potential vulnerabilities and additional ways to secure them


If You’ve Got It - We Want It

  • 7+ years of experience across insider threat investigations, digital/hardware forensics, and physical/executive protection (or a combination demonstrating equivalent depth)
  • Demonstrated experience serving as lead investigator on insider risk cases involving sensitive, high-stakes, or legally exposed matters
  • Working knowledge of employment law, HR investigation standards, and confidentiality requirements as they apply to internal investigations
  • Hands-on forensic skills with standard tooling (e.g., EnCase, FTK, Cellebrite, X-Ways) and hardware-level forensic techniques
  • Active or recent certification through IACIS (CFCE) or comparable digital forensics credentialing body
  • Prior experience in executive protection, including travel risk assessment/intelligence gathering and direct coordination with executive support staff
  • Excellent judgment and discretion; ability to hold confidentiality under pressure and manage competing stakeholder interests
  • Strong written and verbal communication skills, including the ability to translate technical forensic findings for non-technical, legal, and executive audiences
  • Willingness and ability to travel on short notice, including internationally

Preferred

  • Background in law enforcement, military, or federal investigative service
  • Experience building or scaling an insider risk program from an early or immature state
  • Clearance at the TS level preferred, Secret will be reviewed
  • Familiarity with UEBA/DLP tooling and insider threat detection platforms


#LI-KJ1
#LI-Remote

The salary for this role is dependent on geographic location and will be based on the individual candidate's job-related knowledge, skills, and experience.

In addition to base salary, for sales and some sales-adjacent roles, employees are eligible to earn incentive compensation (commission). For all other roles, employees are eligible to participate in the Cribl Corporate Bonus Program.

In addition to a competitive salary, Cribl also offers a generous benefits package which includes health, dental, vision, short-term disability, and life insurance, paid holidays and paid time off, a fertility treatment benefit, 401(k), and equity.

Base Salary Range
$128,000—$200,000 USD

Bring Your Whole Self

Diversity drives innovation, enables better decisions to support our customers, and inspires change for the better. We’re building a culture where differences are valued and welcomed, and we work together to bring out the best in each other. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or any other applicable legally protected characteristics in the location in which the candidate is applying.

Interested in joining the Cribl herd? Learn more about the smartest, funniest, most passionate goats you’ll ever meet at cribl.io/about-us. 

Frequently Asked Questions

What is the salary for the Staff Threat Protection Engineer role at cribl?
The listed salary for this Staff Threat Protection Engineer position at cribl is USD 128K–200K. This is a remote full-time role.
Is the Staff Threat Protection Engineer job at cribl remote?
Yes, this Staff Threat Protection Engineer position at cribl is remote, with team members based in Remote - United States. You can work from home or anywhere in the supported regions.
Which team or department does the Staff Threat Protection Engineer at cribl belong to?
This Staff Threat Protection Engineer position is part of the IT & Security department at cribl. See the full job description for more information about the team structure and responsibilities.
How do I apply for the Staff Threat Protection Engineer position at cribl?
Click the "Apply Now" button on this page. You will be redirected to cribl's official application portal hosted on greenhouse where you can submit your application directly.
When was the Staff Threat Protection Engineer job at cribl posted?
This Staff Threat Protection Engineer position at cribl was posted on Oct 7, 2026. Apply as soon as possible — early applications are often reviewed first.
Staff Threat Protection Engineer
cribl · 💰 USD 128K–200K
Apply for this role ↗

You'll be redirected to cribl's official application page on Greenhouse.