AOUSC - Insider Threat Program Lead

cFocus Software Incorporated

Washington

On-site

USD 150,000 - 190,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

cFocus Software Incorporated is seeking an Insider Threat Program Lead to design, mature, and oversee insider threat detection, analysis, and investigative support for a federal enterprise environment.

The Lead will integrate user activity monitoring, behavioral analytics, threat intelligence, and investigative workflows to identify and mitigate insider risk. Applicants should have extensive experience in federal or highly regulated settings.

Qualifications

  • Requires 10+ years in cybersecurity, counterintelligence, investigations, or insider threat.
  • 5+ years supporting insider threat or behavioral analytics programs.

Responsibilities

  • Lead insider threat operations, analytics, and investigative support activities.
  • Develop insider threat detection methodologies and behavioral analytics use cases.
  • Coordinate with SOC, CTI, HR, legal, counterintelligence, and security stakeholders.
  • Develop insider threat monitoring strategies leveraging UEBA, SIEM, EDR, DLP, and identity telemetry.
  • Lead investigations involving data exfiltration, privilege misuse, anomalous behavior, credential abuse, and policy violations.
  • Develop insider threat reporting, escalation, and case management procedures.
  • Conduct threat assessments and risk-based prioritization.
  • Support development of insider threat dashboards, metrics, and executive briefings.
  • Assist with policy development, governance, and workforce awareness initiatives.
  • Participate in oral presentations and technical solution development.

Skills

Cybersecurity
Investigations
Threat analysis
Stakeholder coordination
Briefing

Tools

UEBA platforms
SIEM analytics
DLP
Identity analytics
Investigative workflows

Job description

Position Title

Insider Threat Program Lead


Position Overview

The Insider Threat Lead will design, mature, and oversee insider threat detection, analysis, and investigative support capabilities for a federal enterprise environment. The Lead will integrate user activity monitoring, behavioral analytics, threat intelligence, and investigative workflows to identify and mitigate malicious, negligent, or compromised insider activity.


The ideal candidate possesses experience supporting insider threat programs within federal, intelligence community, law enforcement, or highly regulated environments.


Key Responsibilities


  • Lead insider threat operations, analytics, and investigative support activities.

  • Develop insider threat detection methodologies and behavioral analytics use cases.

  • Coordinate with SOC, CTI, HR, legal, counterintelligence, and security stakeholders.

  • Develop insider threat monitoring strategies leveraging:

    • UEBA,

    • SIEM,

    • EDR,

    • DLP,

    • and identity telemetry.



  • Lead investigations involving:

    • data exfiltration,

    • privilege misuse,

    • anomalous behavior,

    • credential abuse,

    • and policy violations.



  • Develop insider threat reporting, escalation, and case management procedures.

  • Conduct threat assessments and risk-based prioritization.

  • Support development of insider threat dashboards, metrics, and executive briefings.

  • Assist with policy development, governance, and workforce awareness initiatives.

  • Participate in oral presentations and technical solution development.


Required Qualifications


  • 10+ years of cybersecurity, counterintelligence, investigations, or insider threat experience.

  • 5+ years supporting insider threat or behavioral analytics programs.

  • Experience supporting federal agencies or classified environments.

  • Experience with:

    • UEBA platforms,

    • SIEM analytics,

    • DLP,

    • identity analytics,

    • and investigative workflows.



  • Knowledge of:

    • NIST insider threat guidance,

    • behavioral analytics,

    • digital forensics,

    • and investigative methodologies.



  • Strong briefing and stakeholder coordination skills.


Preferred Certifications


  • CISSP

  • CISM

  • GCFE

  • GCFA

  • CIPP

  • Insider Threat Program Manager certifications

  • Behavioral analytics or fraud investigation certifications

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

AOUSC - Insider Threat Program Lead
AOUSC - Insider Threat Program Lead

cFocus Software Incorporated • Washington

On-site
USD 150,000 - 210,000
Senior Insider Threat Lead: Analytics & Investigations
Senior Insider Threat Lead: Analytics & Investigations

cFocus Software Incorporated • Washington

On-site
USD 150,000 - 190,000
Senior Insider Threat Program Lead
Senior Insider Threat Program Lead

cFocus Software Incorporated • Washington

On-site
USD 150,000 - 210,000
Insider Threat Monitoring Lead
Insider Threat Monitoring Lead

Agile Defense • Reston (VA)

On-site
USD 160,000 - 185,000
Senior Manager, Insider Risk, Digital Forensics
Senior Manager, Insider Risk, Digital Forensics

Jobtailor • Missouri

On-site
USD 120,000 - 180,000
AOUSC - Cyber Threat Intelligence & Threat Hunting Lead
AOUSC - Cyber Threat Intelligence & Threat Hunting Lead

cFocus Software Incorporated • Washington

On-site
USD 140,000 - 210,000
Insider Threat Analyst
Insider Threat Analyst

Motion Recruitment Partners LLC • Washington, Northern (KY)

Hybrid
USD 90,000 - 140,000
Insider Threat Investigator III
Insider Threat Investigator III

Jobtailor • Atlanta (GA)

On-site
USD 110,000 - 140,000
Insider Threat Analyst (TS)
Insider Threat Analyst (TS)

Agile Defense • Washington

On-site
USD 90,000 - 130,000
Insider Threat Analyst (TS)
Insider Threat Analyst (TS)

Agile Defense, Inc. • Washington

On-site
USD 110,000 - 135,000