AOUSC - Insider Threat Program Lead

cFocus Software Incorporated

Washington (District of Columbia)

On-site

USD 150,000 - 210,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

cFocus Software Incorporated is seeking an Insider Threat Program Lead to design and mature detection, analytics, and investigative support for a federal enterprise environment. You will integrate user activity monitoring, behavioral analytics, threat intelligence, and workflows to identify insider risk.

The role emphasizes leadership of insider threat operations, development of use cases, coordination with SOC, HR, legal, and security, and contributing to dashboards, governance, and executive

Qualifications

  • 10+ years in cybersecurity, counterintelligence, investigations, or insider threat.
  • 5+ years supporting insider threat or behavioral analytics programs.
  • Experience with federal agencies or classified environments.
  • Knowledge of UEBA platforms, SIEM analytics, DLP, identity analytics, and investigative workflows.
  • Knowledge of NIST insider threat guidance, behavioral analytics, digital forensics, and investigative methodologies.
  • Strong briefing and stakeholder coordination skills.

Responsibilities

  • Lead insider threat operations, analytics, and investigative support activities.
  • Develop insider threat detection methodologies and behavioral analytics use cases.
  • Coordinate with SOC, CTI, HR, legal, counterintelligence, and security stakeholders.
  • Develop insider threat monitoring strategies leveraging UEBA, SIEM, EDR, DLP and identity telemetry.
  • Lead investigations involving data exfiltration, privilege misuse, anomalous behavior, credential abuse, and policy violations.
  • Develop insider threat reporting, escalation, and case management procedures.
  • Conduct threat assessments and risk-based prioritization.
  • Support development of insider threat dashboards, metrics, and executive briefings.
  • Assist with policy development, governance, and workforce awareness initiatives.
  • Participate in oral presentations and technical solution development.

Skills

UEBA platforms
SIEM analytics
DLP
identity analytics
investigative workflows
NIST insider threat guidance
behavioral analytics
digital forensics
investigative methodologies
briefing & stakeholder coordination

Job description

Insider Threat Program Lead

The Insider Threat Lead will design, mature, and oversee insider threat detection, analysis, and investigative support capabilities for a federal enterprise environment. The Lead will integrate user activity monitoring, behavioral analytics, threat intelligence, and investigative workflows to identify and mitigate malicious, negligent, or compromised insider activity.

The ideal candidate possesses experience supporting insider threat programs within federal, intelligence community, law enforcement, or highly regulated environments.

Key Responsibilities
  • Lead insider threat operations, analytics, and investigative support activities.
  • Develop insider threat detection methodologies and behavioral analytics use cases.
  • Coordinate with SOC, CTI, HR, legal, counterintelligence, and security stakeholders.
  • Develop insider threat monitoring strategies leveraging:
    • UEBA
    • SIEM
    • EDR
    • DLP
    • and identity telemetry.
  • Lead investigations involving:
    • data exfiltration
    • privilege misuse
    • anomalous behavior
    • credential abuse
    • and policy violations.
  • Develop insider threat reporting, escalation, and case management procedures.
  • Conduct threat assessments and risk‑based prioritization.
  • Support development of insider threat dashboards, metrics, and executive briefings.
  • Assist with policy development, governance, and workforce awareness initiatives.
  • Participate in oral presentations and technical solution development.
Required Qualifications
  • 10+ years of cybersecurity, counterintelligence, investigations, or insider threat experience.
  • 5+ years supporting insider threat or behavioral analytics programs.
  • Experience supporting federal agencies or classified environments.
  • Experience with:
    • UEBA platforms
    • SIEM analytics
    • DLP
    • identity analytics
    • and investigative workflows.
  • Knowledge of:
    • NIST insider threat guidance
    • behavioral analytics
    • digital forensics
    • and investigative methodologies.
  • Strong briefing and stakeholder coordination skills.
Preferred Certifications
  • CISSP
  • CISM
  • GCFE
  • GCFA
  • CIPP
  • Insider Threat Program Manager certifications
  • Behavioral analytics or fraud investigation certifications
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

AOUSC - Insider Threat Analyst
AOUSC - Insider Threat Analyst

cFocus Software Incorporated • Washington

Hybrid
USD 80,000 - 100,000
Senior Insider Threat Program Lead
Senior Insider Threat Program Lead

cFocus Software Incorporated • Washington

On-site
USD 150,000 - 210,000
Cyber Insider Threat Analyst III
Cyber Insider Threat Analyst III

Agile Defense • Springfield (VA)

Hybrid
USD 90,000 - 120,000
Insider Threat Monitoring Analyst
Insider Threat Monitoring Analyst

Via Logic LLC • Ashburn (VA)

On-site
USD 120,000 - 180,000
Insider Threat Investigator III
Insider Threat Investigator III

Jobtailor • Atlanta (GA)

On-site
USD 110,000 - 140,000
AOUSC - Detection Engineering Lead
AOUSC - Detection Engineering Lead

cFocus Software Incorporated • Washington

Hybrid
USD 130,000 - 170,000
AOUSC - Threat Hunt Lead
AOUSC - Threat Hunt Lead

cFocus Software Incorporated • Washington

Hybrid
USD 140,000 - 170,000
AOUSC - SOC Operations Lead / Managed Detection & Response (MDR) Lead
AOUSC - SOC Operations Lead / Managed Detection & Response (MDR) Lead

cFocus Software Incorporated • Washington

On-site
USD 140,000 - 180,000
Security Engineer (Insider Risk)
Security Engineer (Insider Risk)

Dragonfli Group • Washington

Hybrid
USD 120,000 - 160,000
Insurance - health, dental, and vision
Paid Time Off (PTO) and 11 Federal Holidays
401(k) employer match
Security Specialist - Insider Threat
Security Specialist - Insider Threat

AMERICAN SYSTEMS • Arlington (VA)

On-site
USD 133,000 - 221,000