Insider Threat Technical Lead

Posted Yesterday
Be an Early Applicant
Hiring Remotely in United States
Remote
155K-185K Annually
Senior level
Artificial Intelligence • Cloud • Machine Learning • Software • Business Intelligence • Cybersecurity • Big Data Analytics
Serving the federal government with courage, integrity, and excellence.
The Role
Serve as the technical lead for USPTO's Insider Risk program: design and tune Microsoft Purview policies, build Sentinel dashboards and playbooks, operate across SIEMs (QRadar, Splunk), develop Power Automate flows, mentor analysts, brief leadership on KPIs, and advise on Microsoft 365 Copilot security and NIST guidance.
Summary Generated by Built In

9th Way Insignia is a service-disabled, veteran-owned small business bringing transformative technology to our government customers so they can achieve their missions.  Our specialties include cybersecurity, cloud modernization, software development, data analytics, enterprise architecture, enterprise IT, analytics, process automation, and artificial intelligence.  Learn more about 9th Way Insignia at https://9thwayinsignia.com/.

Application password: Niner

Position Overview

9th Way Insignia is seeking a hands-on Insider Threat Technical Lead to serve as the technical lead for an established Insider Risk program supporting the United States Patent and Trademark Office (USPTO). This is an individual-contributor technical leadership role — not a management position. You will be the senior technical voice on a small delivery team, guiding insider-risk analysts, advising government data owners and program leadership, and personally building and tuning the Microsoft security tooling the program runs on.

What You Will Do
  • Serve as the insider-risk technical lead and trusted advisor to USPTO stakeholders: run regular customer syncs, deliver polished status reporting, and proactively bring emerging requirements (CISA directives, NIST guidance, AI policy) to the customer with an implementation path.
  • Own the technical direction of the insider-risk toolset in Microsoft Purview: Insider Risk Management policies, indicators, trigger events, sequence detection, privacy/anonymization settings, role groups and permissions, DLP, sensitivity labels and auto-labeling, eDiscovery/legal holds, and unified audit log analysis.
  • Design and maintain custom dashboards, workbooks, and playbooks in Microsoft Sentinel; work across the program’s additional SIEMs (QRadar, Splunk) and custom Microsoft UBA rule engines; investigate and triage insider-risk alerts alongside the analysts and guide them on findings.
  • Build, edit, and troubleshoot Power Automate flows that drive program automation (the program currently operates 50+ production flows), using KQL, JSON, and YAML.
  • Advise the customer on securing Microsoft 365 Copilot adoption: Purview Data Security Posture Management, permission and sharing remediation, restricted content discovery, acceptable-use and DLP policy alignment, and NIST AI RMF alignment.
  • Define, track, and brief insider-risk program KPIs to leadership (alert volume and fidelity, true/false positive rates, MTTD/MTTR, repeat offenders, exfiltration channels, departmental trends) and recommend program improvements.
  • Mentor and technically guide the program’s insider-risk analysts; answer their questions on data findings and investigation paths.
  • Operate effectively in an environment where backend administration is held by government teams: the program performs front-end policy configuration and monitoring, and works through USPTO administrators for backend changes. Patience and influence without direct admin access are essential.
Required Qualifications 
  • Bachelor's degree from an accredited institution in Information Technology, Computer Science, Information Systems Management, Cybersecurity, or a related field. 
  • Seven (7) years of specialized experience in one or more of the following: Cyberspace Operations, Network Security, Computer Forensics, Network Forensics, Computer Network Defense (CND), Attack Sensing & Warning (AS&W), Intelligence Analysis, Cyber Threat Hunting, Penetration Testing, Insider Threat Detection/Mitigation, or Incident Detection & Response. Candidates holding a Master's degree from an accredited institution in information technology, information assurance, information systems management, cybersecurity, or a related field may substitute that degree for two (2) years of experience, reducing the requirement to five (5) years of specialized experience.
  • Primary certification — must currently hold one (1) of: CISSP or GIAC Security Expert (GSE).
  • Secondary certification — in addition to the primary certification above, must currently hold one (1) or more of: GIAC Certified Detection Analyst (GCDA); GIAC Certified Intrusion Analyst (GCIA); GIAC Certified Forensic Analyst (GCFA); GIAC Cyber Threat Intelligence (GCTI); GIAC Network Forensic Analyst (GNFA); GIAC Penetration Tester (GPEN); GIAC Reverse Engineering Malware (GREM).
  • Active SECRET clearance, or the ability to obtain and maintain one. 
Location

Remote

Salary Range
$155,000$185,000 USD

9th Way Insignia’s range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

Clearance/Background Investigation
Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information.

Benefits
Eligible employees will have access to our comprehensive benefits package which includes Medical, Dental, Vision, Voluntary Life Insurance, 401(k), Basic Life A&D, STD, LTD, PTO, Telehealth, paid holidays, FSA, HSA. Additional resources include our Employee Assistance Program (EAP) and Traveling Assistance.

Legal
We’re an equal employment opportunity employer that empowers our people to fearlessly drive change – no matter their race, color, religion, sex (including pregnancy, childbirth, lactation, or related medical conditions), national origin, age, marital status, sexual orientation, gender identity, disability, veteran status, military or uniformed service member status, genetic information, or any other status protected by applicable federal, state, or local law.

Skills Required

  • Bachelor's degree in Information Technology, Computer Science, Information Systems Management, Cybersecurity, or related field
  • Seven (7) years specialized experience in Cyberspace Operations, Network Security, Forensics, CND, Threat Hunting, Penetration Testing, Insider Threat, or Incident Detection & Response (Master's may substitute for two years)
  • Must currently hold one primary certification: CISSP or GIAC Security Expert (GSE)
  • Must currently hold one or more secondary certifications: GCDA, GCIA, GCFA, GCTI, GNFA, GPEN, or GREM
  • Active SECRET clearance, or ability to obtain and maintain one
  • Hands-on experience configuring and tuning Microsoft Purview Insider Risk Management (policies, indicators, privacy settings, DLP, sensitivity labels, auto-labeling, eDiscovery)
  • Experience designing and maintaining dashboards, workbooks, and playbooks in Microsoft Sentinel and working across QRadar and Splunk SIEMs
  • Experience building, editing, and troubleshooting Power Automate flows; familiarity with KQL, JSON, and YAML
  • Ability to advise on Microsoft 365 security posture, Copilot adoption, permissions and sharing remediation, and NIST AI RMF alignment
  • Experience mentoring/technically guiding insider-risk analysts and briefing leadership on KPIs (MTTD/MTTR, false positive rates, exfiltration channels)
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Ashburn, VA
91 Employees
Year Founded: 2018

What We Do

9th Way Insignia is a service-disabled veteran-owned small business (SDVOSB) that provides results-oriented technical solutions to the federal government. Led by experienced industry leaders, we bring software development, enterprise architecture, cybersecurity, enterprise IT, and data analytics capabilities to our customer base within the Departments of Veterans Affairs, Health and Human Services, Transportation, Commerce, and State.

Similar Jobs

Huntress Logo Huntress

Chief Of Staff

Information Technology • Cybersecurity
Easy Apply
Remote
United States of America
780 Employees
200K-275K Annually

Beyond Finance Logo Beyond Finance

Platform Engineer

Fintech • Financial Services
Easy Apply
Remote or Hybrid
United States
2200 Employees
170K-205K Annually

BrainPOP Logo BrainPOP

Regional Head of Growth and Success - North

Edtech • Kids + Family • Social Impact • Software
Easy Apply
Remote or Hybrid
Midwest City, OK, USA
225 Employees
120K-160K Annually

SailPoint Logo SailPoint

Senior Data Engineer

Artificial Intelligence • Cloud • Sales • Security • Software • Cybersecurity • Data Privacy
Remote or Hybrid
United States
2461 Employees
113K-190K Annually

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account