Insider Threat Analyst (TS)

Posted Yesterday
Be an Early Applicant
Washington, DC, USA
Hybrid
110K-135K Annually
Senior level
Information Technology • Software • Cybersecurity • Defense
The Role
Supports an insider threat detection and prevention program by monitoring alerts, triaging and investigating potential incidents, tuning detection triggers, correlating data, and documenting findings. The role maintains insider threat tools, develops workflows and playbooks, coordinates with SOC and investigative stakeholders, and protects employee privacy and civil liberties while complying with federal guidelines.
Summary Generated by Built In
About Agile Defense
 
At Agile Defense we know that action defines the outcome and new challenges require new solutions. That’s why we always look to the future and embrace change with an unmovable spirit and the courage to build for what comes next.
 
Our vision is to bring adaptive innovation to support our nation's most important missions through the seamless integration of advanced technologies, elite minds, and unparalleled agility—leveraging a foundation of speed, flexibility, and ingenuity to strengthen and protect our nation’s vital interests.

Requisition #: 
Job Title: Insider Threat Analyst
Location: Onsite, Washington, DC
Clearance: Top Secret
DESCRIPTIONThe Insider Threat Analyst supports the Insider Threat Program Detection and Prevention (ITPDP) effort, performing day-to-day detection, analysis, and triage of potential insider threat activity under the direction of the Senior Insider Threat Analyst. The analyst monitors and investigates alerts across multiple enterprise applications, distinguishing genuine insider threat incidents from false positives, and documents findings in accordance with established procedures. Working within an established program, the analyst applies both the technical and human dimensions of insider threat analysis while ensuring activities are conducted in accordance with applicable federal insider threat guidelines and with careful attention to employee privacy and civil liberties. ESSENTIAL FUNCTIONS

· Monitor and analyze logs and alerts from multiple applications via dashboards and other means to determine whether activity represents an actual insider threat incident or a false positive.

· Triage and investigate potential insider threat indicators, escalating confirmed or ambiguous incidents to the Senior Insider Threat Analyst as appropriate.

· Support the configuration, tuning, and troubleshooting of application triggers used for insider threat detection in an enterprise environment.

· Assist with the deployment, operation, and maintenance of enterprise tools supporting insider threat detection.

· Document findings, produce clear analytical write-ups, and maintain case records in accordance with established reporting procedures.

· Correlate data across multiple sources to build a complete picture of potential insider threat activity.

· Support the development and refinement of workflows, playbooks, and program documentation.

· Conduct all activities in a manner that protects employee privacy and civil liberties and meets the legal requirements of an insider threat program.

· Coordinate with SOC, investigative, and other stakeholders as directed to support program objectives.

QUALIFICATIONS

· U.S. citizenship and ability to receive and maintain a security clearance at the Tier 5 level or higher.

· BS or BA degree, or additional related experience in lieu of a degree.

· Approximately 6 years of combined experience across cybersecurity, security operations, investigations, or insider threat analysis.

· Hands-on experience with one or more enterprise insider threat, DLP, SIEM, or UEBA/UAM tools (e.g., Splunk, DTEX, Proofpoint/ObserveIT, Microsoft Purview, Exabeam, or similar).

· Demonstrated ability to analyze logs and dashboards to differentiate real incidents from false positives.

· Working knowledge of Windows, Unix, and Linux environments and common insider threat indicators and behaviors.

· Familiarity with log analysis, event correlation, and basic investigative techniques, including awareness of digital forensics concepts.

· Understanding of the legal and ethical requirements of an insider threat program as they relate to privacy and civil liberties.

· Strong written communication for documenting findings, and the ability to work under the direction of senior analysts within an established program.

· Ability to obtain the Counter-Insider Threat Fundamentals Certification if required.

Our Core Values
 
Employees of Agile Defense are our number one priority, and the importance we place on our culture here is fundamental. Our culture is alive and evolving, but it always stays true to its roots. Here, you are valued as a family member, and we believe that we can accomplish great things together. Agile Defense has been highly successful in the past few years due to our employees and the culture we create together. 
 
What makes us Agile? We call it the 6Hs, the values that define our culture and guide everything we do. Together, these values infuse vibrancy, integrity, and a tireless work ethic into advancing the most important national security and critical civilian missions. It's how we show up every day. It's who we are.
 
  • Happy - Be Infectious. Happiness multiplies and creates a positive and connected environment where motivation and satisfaction have an outsized effect on everything we do.
  • Helpful - Be Supportive. Being helpful is the foundation of teamwork, resulting in a supportive atmosphere where collaboration flourishes, and collective success is celebrated.
  • Honest - Be Trustworthy. Honesty serves as our compass, ensuring transparent communication and ethical conduct, essential to who we are and the complex domains we support.
  • Humble - Be Grounded. Success is not achieved alone, humility ensures a culture of mutual respect, encouraging open communication, and a willingness to learn from one another and take on any task.
  • Hungry - Be Eager. Our hunger for excellence drives an insatiable appetite for innovation and continuous improvement, propelling us forward in the face of new and unprecedented challenges.
  • Hustle - Be Driven. Hustle is reflected in our relentless work ethic, where we are each committed to going above and beyond to advance the mission and achieve success.
 
Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities

Skills Required

  • U.S. citizenship and ability to receive and maintain a Tier 5 or higher security clearance
  • Bachelor’s degree or additional related experience in lieu of a degree
  • Approximately 6 years of combined experience in cybersecurity, security operations, investigations, or insider threat analysis
  • Hands-on experience with enterprise insider threat, DLP, SIEM, UEBA, or UAM tools such as Splunk, DTEX, Proofpoint, ObserveIT, Microsoft Purview, or Exabeam
  • Ability to analyze logs and dashboards and distinguish genuine incidents from false positives
  • Working knowledge of Windows, Unix, and Linux environments and common insider threat indicators
  • Familiarity with log analysis, event correlation, investigative techniques, and digital forensics concepts
  • Understanding of legal and ethical insider threat requirements involving privacy and civil liberties
  • Strong written communication and ability to work under senior analyst direction
  • Ability to obtain Counter-Insider Threat Fundamentals Certification if required
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: McLean, VA
2,000 Employees
Year Founded: 1998

What We Do

Agile Defense is a technology services company that provides advanced digital transformation, data analytics, and cybersecurity solutions to support critical national security and civilian government missions. With a global presence, the company focuses on delivering outcome-driven, AI-powered capabilities to solve complex mission challenges for federal and defense customers.

Similar Jobs

PwC Logo PwC

Tax Manager

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Hybrid
21 Locations
370000 Employees
99K-266K Annually

PwC Logo PwC

Asset & Wealth Management Tax Senior Manager

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Hybrid
23 Locations
370000 Employees
124K-335K Annually

PwC Logo PwC

Asset & Wealth Management Tax Director

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Hybrid
22 Locations
370000 Employees
150K-438K Annually

PwC Logo PwC

Asset & Wealth Management - Renewable Energy Tax Senior Associate

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Hybrid
10 Locations
370000 Employees
77K-214K Annually

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel.io Thumbnail
Aerospace • Hardware • Robotics • Software
US
50 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software • Productivity
US
15 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account