· Monitor and analyze logs and alerts from multiple applications via dashboards and other means to determine whether activity represents an actual insider threat incident or a false positive.
· Triage and investigate potential insider threat indicators, escalating confirmed or ambiguous incidents to the Senior Insider Threat Analyst as appropriate.
· Support the configuration, tuning, and troubleshooting of application triggers used for insider threat detection in an enterprise environment.
· Assist with the deployment, operation, and maintenance of enterprise tools supporting insider threat detection.
· Document findings, produce clear analytical write-ups, and maintain case records in accordance with established reporting procedures.
· Correlate data across multiple sources to build a complete picture of potential insider threat activity.
· Support the development and refinement of workflows, playbooks, and program documentation.
· Conduct all activities in a manner that protects employee privacy and civil liberties and meets the legal requirements of an insider threat program.
· Coordinate with SOC, investigative, and other stakeholders as directed to support program objectives.
QUALIFICATIONS· U.S. citizenship and ability to receive and maintain a security clearance at the Tier 5 level or higher.
· BS or BA degree, or additional related experience in lieu of a degree.
· Approximately 6 years of combined experience across cybersecurity, security operations, investigations, or insider threat analysis.
· Hands-on experience with one or more enterprise insider threat, DLP, SIEM, or UEBA/UAM tools (e.g., Splunk, DTEX, Proofpoint/ObserveIT, Microsoft Purview, Exabeam, or similar).
· Demonstrated ability to analyze logs and dashboards to differentiate real incidents from false positives.
· Working knowledge of Windows, Unix, and Linux environments and common insider threat indicators and behaviors.
· Familiarity with log analysis, event correlation, and basic investigative techniques, including awareness of digital forensics concepts.
· Understanding of the legal and ethical requirements of an insider threat program as they relate to privacy and civil liberties.
· Strong written communication for documenting findings, and the ability to work under the direction of senior analysts within an established program.
· Ability to obtain the Counter-Insider Threat Fundamentals Certification if required.
- Happy - Be Infectious. Happiness multiplies and creates a positive and connected environment where motivation and satisfaction have an outsized effect on everything we do.
- Helpful - Be Supportive. Being helpful is the foundation of teamwork, resulting in a supportive atmosphere where collaboration flourishes, and collective success is celebrated.
- Honest - Be Trustworthy. Honesty serves as our compass, ensuring transparent communication and ethical conduct, essential to who we are and the complex domains we support.
- Humble - Be Grounded. Success is not achieved alone, humility ensures a culture of mutual respect, encouraging open communication, and a willingness to learn from one another and take on any task.
- Hungry - Be Eager. Our hunger for excellence drives an insatiable appetite for innovation and continuous improvement, propelling us forward in the face of new and unprecedented challenges.
- Hustle - Be Driven. Hustle is reflected in our relentless work ethic, where we are each committed to going above and beyond to advance the mission and achieve success.
Skills Required
- U.S. citizenship and ability to receive and maintain a Tier 5 or higher security clearance
- Bachelor’s degree or additional related experience in lieu of a degree
- Approximately 6 years of combined experience in cybersecurity, security operations, investigations, or insider threat analysis
- Hands-on experience with enterprise insider threat, DLP, SIEM, UEBA, or UAM tools such as Splunk, DTEX, Proofpoint, ObserveIT, Microsoft Purview, or Exabeam
- Ability to analyze logs and dashboards and distinguish genuine incidents from false positives
- Working knowledge of Windows, Unix, and Linux environments and common insider threat indicators
- Familiarity with log analysis, event correlation, investigative techniques, and digital forensics concepts
- Understanding of legal and ethical insider threat requirements involving privacy and civil liberties
- Strong written communication and ability to work under senior analyst direction
- Ability to obtain Counter-Insider Threat Fundamentals Certification if required
What We Do
Agile Defense is a technology services company that provides advanced digital transformation, data analytics, and cybersecurity solutions to support critical national security and civilian government missions. With a global presence, the company focuses on delivering outcome-driven, AI-powered capabilities to solve complex mission challenges for federal and defense customers.






