Specialized Security All Source Analyst (Insider Threat)

Posted Yesterday
Be an Early Applicant
Quantico, VA, USA
In-Office
85K-95K Annually
Senior level
Security • Cybersecurity
The Role
Provide all-source insider-threat analysis and support to the DCSA InT program. Aggregate and analyze government and open-source data, develop and tune UAM policy triggers, perform event and network/host log analysis (SIEM/HIDS), produce metrics, reports, briefings, and recommendations, and support personnel security and background investigation processes.
Summary Generated by Built In

Join our team at Core One! Our mission is to be at the forefront of devising analytical, operational and technical solutions to our Nation's most complex national security challenges. In order to achieve our mission, Core One values people first! We are committed to recruiting, nurturing, and retaining top talent! We offer a competitive total compensation package that sets us apart from our competition. Core One is a team-oriented, dynamic, and growing company that values exceptional performance!

*This position requires TS/SCI Clearance * 

Responsibilities:
  • The Contractor shall provide all source analytic support to the DCSA InT program. The Contractor shall leverage their education, expertise, and understanding of the DoD population to accomplish the specific tasks.
  • The Contractor shall provide Insider Threat support services. The Contractor shall provide Insider Threat analysts responsible for conducting comprehensive all source research, analysis and fusion of traditional and not-traditional sources of information supporting the Insider Threat mission. The Contractor shall produce innovative, all-source InT-related products for a broad set of customers, including those in the DoD, intelligence, security and law enforcement communities and other senior audiences.
  • Aggregate, analyze, and evaluate all available InT government and open-source information to assist in the evaluation of potential risk as it relates to InT.
  • Extract and organize statistical data to support the building of both quantitative and qualitative metrics products, summaries, case studies and trend products.
  • Communicate complex ideas and analyses orally and in writing.
  • Plan and conduct thorough research using all available InT tools and data sources to discover the information necessary to support analysis, either independently or as part of a larger analytical effort.
  • Assist in the preparation and production of risk warning and situational awareness products related to InT issues.
  • Assist in the preparation and production of analytical products and identifying areas for efficiencies in the production process.
  • Provide editing and quality control of InT products communicating recommendations orally and in writing.
  • Review InT information in support of meeting InT mission requirements and timelines. 
  • Propose and define new UAM policy triggers.
  • Perform functional testing of proposed and modified policy triggers prior to implementation and final government approval.
  • Prepare policy trigger implementation plan and impact assessment. The Contractor shall prepare and present findings in support of new UAM policy triggers.
  • Review and escalate as appropriate events triggered in the UAM tool.
  • Perform configuration management activities to ensure compliance with asset management and continuous monitoring policy requirements.
  • Understand and implement established policy technical and workflow procedures.
  • Prepare, write, and present reports and briefings as required. The Contractor shall provide written support for UAM policy approval requests.
  • Support analytic and operational activities to assemble, correlate, evaluate, and assess information concerning counterintelligence, security, human capital, and information assurance related insider threats against DCSA personnel, programs, information systems, and/or facilities.
  • Apply knowledge of CNE tactics, techniques, and procedures associated with advanced cyber threats to develop analytical signatures and filters to refine anomaly detection with the Insider Threat Program datastore/database that are internal to the organization. The primary distinguishing characteristic of this capability is knowing the specific content being read, moved, and altered within the organization by the internal threat and applying context and analysis to that knowledge.
  • Perform event analysis by examining network traffic data and Host Based Security Systems’ audit data, SIEM data, and any other technical feeds received from Agency security tools.
  • Analyze and disseminate insider threat analysis information as required, and perform insider threat analysis, forecasts, and threat alerts with recommended countermeasures to include new policy trigger protocols or tuning of existing policies.
  • Prepare formal analysis products and reports with findings and recommendations. The Contractor shall prepare and present briefings as a subject matter expert, as required.
  • Make policy trigger recommendations to the government to enhance current capabilities and tune current policy triggers.
  • Focus not only on anomalous network activity but also captures human behaviors such as policy violations, compliance incidents, and malicious acts at the endpoint that can service as warning signs leading up to a breach.
  • Effectively detect both unauthorized access to information and unauthorized transfer of information and could be deployed for audits and inquiries across multiple network architectures using a wide variety of security concepts of operations that range from standalone, single-service systems in a two-person investigation office to large-scale clusters on a distributed enterprise with multiple stakeholders doing auditing and investigations.
  • Process personnel to verify the appropriate security clearance and/or SCI eligibility prior to granting access to DCSA facilities and information. In addition, support the DCSA Personnel Security (PS) Program includes:
  • Request/Review/Initiate/Track Personnel Security Background Investigations.
  • Provide accurate and analytical establishment, maintenance, review, receipt, accountability, transmission, reproduction, storage, safeguarding, and destruction of collected personal history, case files, data entry,
Qualifications:
  • Bachelor's Degree in area related to the position
  • TS/SCI Clearance
  • 8 years of experience in a directly related position

Salary

  • $85,000 - $95,000

The pay range reflected above is a general guideline for this position and labor category and is not a guarantee of a specific salary or offer. Final compensation is determined based on factors including, but not limited to, relevant experience, education, certifications, security clearance level, contract requirements, geographic location, and internal pay equity, and may reflect market data specific to the awarded contract.

Security Clearance:
  • TS/SCI

Core One is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender identity, sexual orientation, national origin, or protected veteran status and will not be discriminated against on the basis of disability.

__PRESENT__PRESENT__PRESENT__PRESENT

__PRESENT

__PRESENT__PRESENT

__PRESENT__PRESENT

__PRESENT__PRESENT__PRESENT__PRESENT

Skills Required

  • Bachelor's degree in a related field
  • TS/SCI security clearance
  • Eight years of directly related experience
  • Insider threat analysis experience (all-source research and fusion)
  • Experience with SIEM and host-based security systems and network traffic analysis
  • Experience with UAM tools, policy trigger definition, testing, and implementation
  • Knowledge of CNE tactics, techniques, and procedures to develop analytical signatures
  • Experience preparing analytical products, reports, and briefings for senior audiences
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Sterling, VA
61 Employees

What We Do

Our mission is to be at the forefront of devising analytical, operational and technical solutions to the most complex national security challenges by delivering superior advice, building trusted partnerships, and augmenting the capabilities of our clients.

Similar Jobs

BlackLine Logo BlackLine

Artificial Intelligence Engineer

Cloud • Fintech • Information Technology • Machine Learning • Software • App development • Generative AI
Remote or Hybrid
USA
1810 Employees
128K-160K Annually

Enverus Logo Enverus

Owner Relations Agent - 25270

Big Data • Information Technology • Software • Analytics • Energy
In-Office or Remote
3 Locations
1800 Employees
43K-58K Annually

Enverus Logo Enverus

Consultant

Big Data • Information Technology • Software • Analytics • Energy
In-Office or Remote
5 Locations
1800 Employees
120K-135K Annually

Applied Systems Logo Applied Systems

Director, Product Marketing - Carrier

Cloud • Insurance • Payments • Software • Business Intelligence • App development • Big Data Analytics
Remote or Hybrid
United States
3079 Employees
150K-180K Annually

Similar Companies Hiring

Credal.ai Thumbnail
Software • Security • Productivity • Machine Learning • Artificial Intelligence
Brooklyn, NY
Milestone Systems Thumbnail
Artificial Intelligence • Security • Software • Analytics • Big Data Analytics
Lake Oswego, OR
1500 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account