InInsider Threat Program Hunt Team Analyst

Leidos Inc

Springfield (VA)

On-site

USD 105,000 - 190,000

Full time

4 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

The Digital Sector at Leidos invites applications for a Hunt Analyst supporting the DHS Insider Threat Program. You will hunt, analyze, and correlate insider threat indicators using UAM/UEBA, monitor platforms, and coordinate rapid responses to high alerts within the DHS enterprise.

Strong analytic and briefing skills are essential for diverse stakeholders. Required: advanced experience in intelligence analysis, threat assessment, and insider threat frameworks; TS/SCI clearance and US

Qualifications

  • Bachelor's degree plus 12+ years insider threat experience, or Master's with 10+ years.
  • 10+ years knowledge of the intelligence cycle, analytic techniques, systems, processes, and organizations.
  • 10+ years knowledge of Threat Assessment & Mitigation Strategies.
  • Excellent written and verbal skills with ability to brief diverse audiences.
  • Knowledge of current domestic and international threats to U.S. national security.
  • Ability to establish networks with security stakeholders to foster program utilization.
  • Self-starter capable of working independently to promote program goals.
  • Working knowledge of UAM and related solutions.
  • Working knowledge of cybersecurity toolsets for ITP activities.
  • Working knowledge of Open-Source toolsets.
  • Working knowledge of Insider Threat Frameworks; Pathway to Violence & Critical Pathway.
  • Current TS/SCI and US Citizenship.

Responsibilities

  • Examine, analyze, and search insider threat data to identify trends and insights.
  • Provide analytical support for operation of UAM/UEBA tools and coordinate responses.
  • Conduct research on UAM platform to identify patterns of concern related to insider threat.
  • Provide proactive insider threat hunting across DHS enterprise networks and log sources.
  • Perform continuous hunt operations across data sources to identify insider threat patterns.
  • Identify mitigation strategies to reduce insider threat risk for the investigative team.
  • Use UEBA to baseline user activity and detect deviations; respond to high alerts promptly.

Skills

UAM
Threat analysis
Analytical skills
Briefing skills
Cybersecurity tools

Education

Bachelor's degree
Master's degree
TS/SCI clearance
US Citizenship

Tools

Open-Source toolsets
Insider Threat Frameworks
Cybersecurity toolsets
UAM platform

Job description

Description

The Digital Sector at Leidos currently has an opening for a Hunt Analyst supporting the HEITS Contract as part of the Department of Homeland Security (DHS) Insider Threat Program (ITP). This is an exciting opportunity to use your experience to support, sustain, design and evolve the database backbone of the ITP. The ITP mission is to identify insider threats to the department by utilizing advanced analytics, monitoring, and data correlation which in turn help address and eliminate potential threat actors from compromising the DHS mission in safeguarding the homeland.

The selected candidate will be responsible for the following:

Normal business hours will be defined as a schedule combination to include weekdays 2pm-10pm shift and weekends 6am-6pm shift. The candidate will have 2- 3 days off based on the schedule determined & the work week should not exceed 40 hours. This position is expected to eventually move to shift work to meet the requirement of 24x7 operations at an undetermined later date. Examine, analyze, and search insider threat data to identify trends, patterns, and insights of potential insider threat indicators.

Provide analytical, program support services related to the operation of UAM/ UEBA tool. Monitor UAM platform to identify emerging requirements related to insider threat events and coordinate across the enterprise to ensure timely response. Conduct further research on the UAM platform to identify patterns of concerning behavior related to a potential insider threat risk to the DHS enterprise. Provide proactive insider threat-based hunting across the DHS enterprise network, leveraging methodologies and behavioral analytics to detect, investigate, and mitigate anomalous activity and policy violations indicative of malicious insider behavior. Conduct continuous hunt operations across data and log sources, DHS platforms, EDR tools, and network traffic to identify patterns of insider threat behavior.

Identify mitigation strategies to assist the investigative team in effectively reducing insider threat risk.

Utilize UEBA (User and Entity Behavior Analytics) platforms and techniques to baseline user activity and detect deviations. Provide timely response to critical/high UAM alerts (within 4 hours during normal business hours).

Basic Qualifications
  • Bachelors degree and 12+ years of prior relevant insider threat experience or Masters with 10+ years of prior relevant experience. Additional years of experience with requisite certifications will be considered in leu of degree.
  • Minimum of 10+ years demonstrated knowledge of the intelligence cycle, analytic techniques, systems, processes, and organizations.
  • Minimum of 10+ years demonstrated knowledge of Threat Assessment & Mitigation Strategies.
  • Have excellent written and verbal skills with ability to deliver briefings to a diverse group of audiences.
  • Possess knowledge of current domestic and international threats to U.S. national security interests.
  • Be adept at establishing networks with relevant security, personnel, and prevention stakeholders to foster program utilization.
  • Be a self-starter capable of working independently to promote program goals.
  • Working knowledge of User Activity Monitoring Software (UAM) and solutions.
  • Working knowledge of Cybersecurity toolsets designed to support ITP mission activities.
  • Working Knowledge of Open-Source toolsets.
  • Working Knowledge of Insider Threat Frameworks; Pathway to Violence & Critical Pathway.
  • Current TS/SCI and Must be a US Citizen.
  • Ability to obtain DHS EOD SCI and willingness to undergo CI Polygraph.
Preferred Qualifications
  • Master's degree from an accredited college or university in Criminal Justice, Homeland security, Cyber Security, or related field
  • Proven experience (10+ years) in Intelligence Analysis
  • Experience with User Activity Monitoring products and platforms
  • Proven experience (4+ years) in Threat Assessment & Mitigation
  • Certified Counter-Insider Threat Professional - Fundamentals (CCITP-F)
  • Certified Counter-Insider Threat Professional - Analysis (CCITP-A)
  • Completion of Center for Development of Security Excellence (CDSE) Insider Threat Detection Analysis Course (ITDAC)
  • Completion of Workplace Assessment of Violence Risk (WAVR-21) Workshop

Completion of Center for Development of Security Excellence (CDSE) Curriculums; INT311.CU/INT312.CU/CI201.CU

If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo - because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 - and moving faster than anyone else dares.

For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

Pay Range: Pay Range $105,300.00 - $190,350.00

About Leidos

Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $16.7 billion for the fiscal year ended January 3, 2025. For more information, visit www.Leidos.com.

Pay and Benefits

Pay and benefits are fundamental to any career decision. That's why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available at www.leidos.com/careers/pay-benefits.

Commitment to Non-Discrimination

All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

InInsider Threat Program Hunt Team Analyst
InInsider Threat Program Hunt Team Analyst

Leidos • Springfield (VA)

On-site
USD 105,000 - 190,000
Insider Threat Program Support Officer
Insider Threat Program Support Officer

Leidos • Springfield (VA)

On-site
USD 116,000 - 210,000
Health and Wellness programs
Retirement plan
Insider Threat Program Senior System Engineer
Insider Threat Program Senior System Engineer

Leidos • Fairfax (VA)

On-site
USD 148,000 - 270,000
Insider Threat Program Support Officer
Insider Threat Program Support Officer

Koitecc Solutions • Springfield (VA)

On-site
USD 116,000 - 210,000
Insider Threat Program Support Officer
Insider Threat Program Support Officer

Leidos Inc • Springfield (VA)

On-site
USD 116,000 - 210,000
Insider Threat Program Senior Network Engineer
Insider Threat Program Senior Network Engineer

Leidos • United States

On-site
USD 139,000 - 252,000
Competitive compensation
Health and Wellness programs
Retirement
Tier 3 Cyber Threat Intelligence Analyst
Tier 3 Cyber Threat Intelligence Analyst

Leidos Inc • Chandler (AZ)

On-site
USD 140,000 - 170,000
Tier 3 Cyber Threat Intelligence Analyst
Tier 3 Cyber Threat Intelligence Analyst

Leidos Inc • Mississippi

On-site
USD 120,000 - 160,000
Tier 3 Cyber Threat Intelligence Analyst
Tier 3 Cyber Threat Intelligence Analyst

Leidos • Mississippi

On-site
USD 90,000 - 150,000
Cyber Intelligence Fusion Analyst
Cyber Intelligence Fusion Analyst

Leidos Inc • Alexandria (VA)

On-site
USD 108,000 - 195,000