Insider Threat Program Hunt Team Analyst (w/ active TS/SCI)
On-siteSpringfield, Virginia, United States
Job Summary
Examine, analyze, and search insider threat data to identify trends, patterns, and insights of potential insider threat indicators. Provide analytical, program support services related to the operation of the UAM/UEBA tool by monitoring the platform to identify emerging requirements and coordinate enterprise-wide responses. Conduct continuous hunt operations across data and log sources, Agency platforms, EDR tools, and network traffic to detect, investigate, and mitigate anomalous activity indicative of malicious insider behavior. Utilize UEBA platforms to baseline user activity and detect deviations, while providing timely response to critical/high UAM alerts within four hours during normal business hours. Identify mitigation strategies to assist the investigative team in effectively reducing insider threat risk.
Required Qualifications
- Active Top Secret/SCI or SCI eligible
- Bachelors degree and (8)+ years of prior relevant insider threat experience or Masters with (6)+ years of prior relevant experience
- Additional years of experience with requisite certifications will be considered in lieu of degree
- Minimum of 4 years demonstrated knowledge of the intelligence cycle, analytic techniques, systems, processes, and organizations
- Minimum of 4 years demonstrated knowledge of Threat Assessment & Mitigation Strategies
- Excellent written and verbal skills with ability to deliver briefings to a diverse group of audiences
- Knowledge of current domestic and international threats to U.S. national security interests
- Adept at establishing networks with relevant security, personnel, and prevention stakeholders to foster program utilization
- Self-starter capable of working independently to promote program goals
- Working knowledge of User Activity Monitoring Software (UAM) and solutions
- Working knowledge of Cybersecurity toolsets designed to support ITP mission activities
- Working knowledge of Open-Source toolsets
- Working knowledge of Insider Threat Frameworks; Pathway to Violence & Critical Pathway
- Current TS/SCI and Must be a US Citizen
- Ability to obtain Agency EOD SCI and willingness to undergo CI Polygraph
- Must possess an active DoD Top Secret Clearance
- Must undergo background investigation (BI) and fingerprinting by the federal agency and successfully pass the preceding
- US CITIZENSHIP IS REQUIRED
Desired Qualifications
- Master's degree from an accredited college or university in Criminal Justice, Homeland security, Cyber Security, or related field
- Proven experience (10+ years) in Intelligence Analysis
- Experience with User Activity Monitoring products and platforms
- Proven experience (4+ years) in Threat Assessment & Mitigation
- Certified Counter-Insider Threat Professional - Fundamentals (CCITP-F)
- Certified Counter-Insider Threat Professional - Analysis (CCITP-A)
- Completion of Center for Development of Security Excellence (CDSE) Insider Threat Detection Analysis Course (ITDAC)
- Completion of Workplace Assessment of Violence Risk (WAVR-21) Workshop
- Completion of Center for Development of Security Excellence (CDSE) Curriculums; INT311.CU/INT312.CU/CI201.CU
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.