Insider Threat Monitoring Analyst

Posted 20 Days Ago
Be an Early Applicant
Ashburn, VA, USA
In-Office
108K-195K Annually
Senior level
Information Technology • Software
The Role
Lead insider threat monitoring and forensic investigations including near-real-time DLP and UAM monitoring, FSN activity review, EDR analysis, support to OPR/OIG/OI, detect/tune insider alerts, investigate data spillage per NIST 800-88, and produce forensically sound reports.
Summary Generated by Built In

The Department of Homeland Security (DHS), Customs and Border Protection (CBP) Cyber Security Directorate (CSD) Security Operations Center (SOC) is a US Government program responsible to prevent, identify, contain and eradicate cyber threats to CBP networks through monitoring, intrusion detection and protective security services to CBP information systems including local area networks/wide area networks (LAN/WAN), commercial Internet connection, public facing websites, wireless, mobile/cellular, cloud, security devices, servers and workstations.  The CBP SOC is responsible for the overall security of CBP Enterprise-wide information systems, and collects, investigates, and reports any suspected and confirmed security violations. 

Leidos is seeking an experienced Insider Threat Expert to join our team. As a member of this highly technical digital forensics team supporting U.S. Customs and Border Protection (CBP), you will be responsible for leading user activity monitoring activities, foreign service national monitoring, insider threat analysis, and investigating policy violations, data loss prevention (DLP) events, and sensitive data spillages.

Primary Responsibilities

The candidate will be responsible for:

  • Supporting the Cyber Defense Forensics and Insider Threat investigations using near real- time (when possible, based on tools) monitoring of DLP tools for potential data exfiltration attempts of CBP mission data or employee PII/SPII
  • Support Office of Professional Responsibility (OPR), Office of Intelligence (OI), Office of the Inspector General (OIG) and Other Government Agencies in the investigation of CBP personnel operating with potentially malicious or alleged criminal intent.
  • Actively monitor Foreign Service National (FSN) network activity for network misuse and policy violations.
  • Support User Activity Monitoring (UAM) activities.
  • Make recommendations for insider threat alert triggers and detections across various security tools and logging sources.
  • Monitor CBP laptops and mobile devices traveling OCONUS for suspicious activity and policy violations.
  • Provide investigative support for CBP's OPR-Cyber Investigations for media leak investigations by identifying all users who have received/sent, printed, copied, downloaded/uploaded, or accessed the leaked document.
  • Provide recommendations for Information Spillage Incident Response efforts on handling and sanitization methods pursuant to industry best practices, NIST 800-88 recommendations, and Federal guidelines.

Basic Qualifications

  • Requires BS degree and a minimum of 8 or more years of direct relevant experience.
  • Requires an active and current CISSP certification
  • Degree in computer science, IT, Information/Cyber Security field from an accredited college or university.
    • Additional experience or applicable certifications acceptable in lieu of degree.
  • Working knowledge of defense-in-depth principles, network/HW/SW security architecture, network topology, IT device integrity, and common security elements
  • Effective communication skills with emphasis on attention to detail, ability to accurately capture and document technical remediation details, and ability to brief stakeholders on incident statuses, recovery and root causes.
  • Demonstrable experience performing forensic analysis, digital media analysis, and in-depth system & network log analysis in support of forensic investigations.
  • Ability to generate forensically sound cyber analysis reports detailing forensically sound analysis procedures, findings, and recommendations from incident investigations.
  • Strong problem-solving abilities with an analytic and qualitative eye for reasoning under pressure.
  • Experience with User Activity Monitoring products and platforms
  • Experience with Endpoint Detection and Response (EDR) tools
  • Must be able to report to the Ashburn VA office up to 5 days per week
  • Must be have a US Citizenship
  • Must have a Top Secret clearance
  • Must be able to obtain and maintain a CBP BI clearance.

Preferred Qualifications

Master’s degree from an accredited college or university in IT Management, Engineering, or related field 

  • SANS GREM certification
  • Previous experience contributing to or leading insider threat investigations in support of Federal Government, DOD, or Law Enforcement environments.
  • Experience performing computer forensics in Federal Government, DOD or Law Enforcement environments.

If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares.

Original Posting:July 13, 2026

For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

Pay Range:Pay Range $107,900.00 - $195,050.00

The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

Skills Required

  • BS degree and a minimum of 8 or more years of direct relevant experience
  • Active and current CISSP certification
  • Degree in computer science, IT, Information/Cyber Security field (or equivalent experience/certifications in lieu of degree)
  • Working knowledge of defense-in-depth principles, network/HW/SW security architecture, network topology, and common security elements
  • Effective communication skills, attention to detail, technical documentation and stakeholder briefings
  • Demonstrable experience performing forensic analysis, digital media analysis, and in-depth system & network log analysis
  • Ability to generate forensically sound cyber analysis reports detailing procedures, findings, and recommendations
  • Experience with User Activity Monitoring products and platforms
  • Experience with Endpoint Detection and Response (EDR) tools
  • Ability to report to the Ashburn VA office up to 5 days per week
  • US Citizenship
  • Must have a Top Secret clearance
  • Must be able to obtain and maintain a CBP BI clearance
  • Master's degree in IT Management, Engineering, or related field
  • SANS GREM certification
  • Previous experience contributing to or leading insider threat investigations in Federal Government, DOD, or Law Enforcement environments
  • Experience performing computer forensics in Federal Government, DOD or Law Enforcement environments

Leidos Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Leidos and has not been reviewed or approved by Leidos.

  • Healthcare Strength Healthcare coverage is described as comprehensive, with multiple plan options, low office-visit copays in some plans, and access to mental health and wellness support tools. The availability of HSA/FSA options and employer contributions is positioned as a meaningful part of the total package.
  • Retirement Support Retirement benefits are framed as a strong component of total rewards, highlighted by a 401(k) match and immediate vesting in the standard package. The Employee Stock Purchase Plan is also presented as an additional long-term wealth-building feature.
  • Wellbeing & Lifestyle Benefits Wellbeing and lifestyle supports extend beyond core insurance, including wellness programs, fitness-related stipends, and assistance resources. Work flexibility and related perks are also included as part of the broader rewards experience.

Leidos Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Reston, VA
27,104 Employees
Year Founded: 1969

What We Do

We Are Leidos For 50 years we have been tackling some of the biggest problems that face our nation and our world. OUR MISSION Through our culture of innovation and history of performance, we develop deep customer trust built on integrity and create enduring solutions that improve our world. Leidos is a science and technology solutions leader working to address some of the world’s toughest challenges in the defense, intelligence, homeland security, civil, and healthcare markets. The company’s 43,000 employees support vital missions for government and commercial customers. Headquartered in Reston, Va., Leidos reported annual revenues of approximately $11.09 billion for the fiscal year ended January 3, 2020. Leidos was cited for the meaningful work employees perform that is challenging, impactful, and aligned with our customers’ missions as reasons professionals want to work and stay at our company. Leidos has also been named to lists including Forbes’ Best Employers for Diversity, Forbes’ America’s Best Employers for Women, Military Times Best for Vets Employers, and Ethisphere Institute’s World's Most Ethical Companies®. Employees enjoy career enrichment opportunities available through mobility and development and experience rewarding relationships with supportive supervisors and talented colleagues and customers. Employees appreciate our flexible work environment, allowing for and encouraging a true work-life balance. Our professionals are also excited about our Employee Resource Groups, like the newly launched Collaborative Outreach with Remote and Embedded Employees (CORE), which strives to create an environment where every employee, regardless of location, feels fully engaged as a valued employee of Leidos. Your most important work is ahead.

Similar Jobs

Wipfli Logo Wipfli

Architect

Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Remote or Hybrid
United States
3000 Employees
117K-158K Annually

Wells Fargo Logo Wells Fargo

Branch Manager University Mall

Fintech • Financial Services
Hybrid
Blacksburg, VA, USA
205000 Employees
31K-58K Hourly

Wells Fargo Logo Wells Fargo

Lead Software Engineer

Fintech • Financial Services
Hybrid
McLean, VA, USA
205000 Employees
119K-224K Annually
Hybrid
McLean, VA, USA
205000 Employees
167K-260K Annually

Similar Companies Hiring

Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account