InInsider Threat Program Hunt Team Analyst

Leidos

Springfield (VA)

On-site

USD 105,000 - 190,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

The Digital Sector at Leidos has an opening for a Hunt Analyst supporting the HEITS Contract as part of the DHS Insider Threat Program. The role focuses on identifying insider threat indicators and evolving the database backbone of the ITP.

Responsibilities include hunting across data sources, monitoring UAM/UEBA platforms, and coordinating with security stakeholders to mitigate threats. Requires TS/SCI and US citizenship.

Qualifications

  • Bachelor's degree and 12+ years of prior relevant insider threat experience or Masters with 10+ years of prior relevant experience.
  • Minimum of 10+ years demonstrated knowledge of the intelligence cycle, analytic techniques, systems, processes, and organizations.
  • Minimum of 10+ years demonstrated knowledge of Threat Assessment & Mitigation Strategies.
  • Excellent written and verbal skills with ability to deliver briefings to a diverse group of audiences.
  • Knowledge of current domestic and international threats to U.S. national security interests.
  • Be adept at establishing networks with relevant security, personnel, and prevention stakeholders to foster program utilization.
  • Be a self-starter capable of working independently to promote program goals.
  • Working knowledge of User Activity Monitoring Software (UAM) and solutions.
  • Working knowledge of Cybersecurity toolsets designed to support ITP mission activities.
  • Working Knowledge of Open-Source toolsets.
  • Working Knowledge of Insider Threat Frameworks; Pathway to Violence & Critical Pathway.
  • Current TS/SCI and Must be a US Citizen.
  • Ability to obtain DHS EOD SCI and willingness to undergo CI Polygraph.

Responsibilities

  • Examine, analyze, and search insider threat data to identify trends, patterns, and insights of potential insider threat indicators.
  • Provide analytical, program support services related to the operation of UAM/ UEBA tool.
  • Monitor UAM platform to identify emerging requirements related to insider threat events and coordinate across the enterprise to ensure timely response.
  • Provide proactive insider threat-based hunting across the DHS enterprise network, leveraging methodologies and behavioral analytics to detect, investigate, and mitigate anomalous activity and policy violations indicative of malicious insider behavior.
  • Conduct continuous hunt operations across data and log sources, DHS platforms, EDR tools, and network traffic to identify patterns of insider threat behavior.

Skills

Insider threat analysis
UAM/UEBA knowledge
Data analytics
Intelligence cycle knowledge
Briefing/presentation skills
Networking with security stakeholders

Education

Bachelor's degree
Master's degree

Tools

UAM tools
UEBA platforms
Cybersecurity toolsets
Open-source toolsets

Job description

Description


The Digital Sector at Leidos currently has an opening for a Hunt Analyst supporting the HEITS Contract as part of the Department of Homeland Security (DHS) Insider Threat Program (ITP). This is an exciting opportunity to use your experience to support, sustain, design and evolve the database backbone of the ITP. The ITP mission is to identify insider threats to the department by utilizing advanced analytics, monitoring, and data correlation which in turn help address and eliminate potential threat actors from compromising the DHS mission in safeguarding the homeland.


The selected candidate will be responsible for the following:


Normal business hours will be defined as a schedule combination to include weekdays 2pm-10pm shift and weekends 6am-6pm shift. The candidate will have 2- 3 days off based on the schedule determined & the work week should not exceed 40 hours. This position is expected to eventually move to shift work to meet the requirement of 24x7 operations at an undetermined later date. Examine, analyze, and search insider threat data to identify trends, patterns, and insights of potential insider threat indicators.


Provide analytical, program support services related to the operation of UAM/ UEBA tool. Monitor UAM platform to identify emerging requirements related to insider threat events and coordinate across the enterprise to ensure timely response. Conduct further research on the UAM platform to identify patterns of concerning behavior related to a potential insider threat risk to the DHS enterprise. Provide proactive insider threat-based hunting across the DHS enterprise network, leveraging methodologies and behavioral analytics to detect, investigate, and mitigate anomalous activity and policy violations indicative of malicious insider behavior. Conduct continuous hunt operations across data and log sources, DHS platforms, EDR tools, and network traffic to identify patterns of insider threat behavior.


Identify mitigation strategies to assist the investigative team in effectively reducing insider threat risk.


Utilize UEBA (User and Entity Behavior Analytics) platforms and techniques to baseline user activity and detect deviations. Provide timely response to critical/high UAM alerts (within 4 hours during normal business hours).


Basic Qualifications:


  • Bachelors degree and 12+ years of prior relevant insider threat experience or Masters with 10+ years of prior relevant experience. Additional years of experience with requisite certifications will be considered in leu of degree.
  • Minimum of 10+ years demonstrated knowledge of the intelligence cycle, analytic techniques, systems, processes, and organizations.
  • Minimum of 10+ years demonstrated knowledge of Threat Assessment & Mitigation Strategies.
  • Have excellent written and verbal skills with ability to deliver briefings to a diverse group of audiences.
  • Possess knowledge of current domestic and international threats to U.S. national security interests.
  • Be adept at establishing networks with relevant security, personnel, and prevention stakeholders to foster program utilization.

  • Be a self-starter capable of working independently to promote program goals.
  • Working knowledge of User Activity Monitoring Software (UAM) and solutions.
  • Working knowledge of Cybersecurity toolsets designed to support ITP mission activities.
  • Working Knowledge of Open-Source toolsets.
  • Working Knowledge of Insider Threat Frameworks; Pathway to Violence & Critical Pathway.
  • Current TS/SCI and Must be a US Citizen.
  • Ability to obtain DHS EOD SCI and willingness to undergo CI Polygraph.

Preferred Qualifications:


  • Master’s degree from an accredited college or university in Criminal Justice, Homeland security, Cyber Security, or related field

  • Proven experience (10+ years) in Intelligence Analysis
  • Experience with User Activity Monitoring products and platforms
  • Proven experience (4+ years) in Threat Assessment & Mitigation
  • Certified Counter-Insider Threat Professional - Fundamentals (CCITP-F)
  • Certified Counter-Insider Threat Professional - Analysis (CCITP-A)
  • Completion of Center for Development of Security Excellence (CDSE) Insider Threat Detection Analysis Course (ITDAC)
  • Completion of Workplace Assessment of Violence Risk (WAVR-21) Workshop

Completion of Center for Development of Security Excellence (CDSE) Curriculums; INT311.CU/INT312.CU/CI201.CU


If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo - because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history - because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 - and moving faster than anyone else dares.


Original Posting:

September 11, 2026


Pay Range:

Pay Range $105,300.00 - $190,350.00


The Leidos pay range for this job level is a general guideline onlyand not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.


About Leidos


Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $16.7 billion for the fiscal year ended January 3, 2025. For more information, visit www.Leidos.com.


Pay and Benefits


Pay and benefits are fundamental to any career decision. That's why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available at www.leidos.com/careers/pay-benefits.


Securing Your Data


Beware of fake employment opportunities using Leidos’ name. Leidos will never ask you to provide payment-related information during any part of the employment application process (i.e., ask you for money), nor will Leidos ever advance money as part of the hiring process (i.e., send you a check or money order before doing any work). Further, Leidos will only communicate with you through emails that are generated by the Leidos.com automated system - never from free commercial services (e.g., Gmail, Yahoo, Hotmail) or via WhatsApp, Telegram, etc. If you received an email purporting to be from Leidos that asks for payment-related information or any other personal information (e.g., about you or your previous employer), and you are concerned about its legitimacy, please make us aware immediately by emailing us at LeidosCareersFraud@leidos.com.


If you believe you are the victim of a scam, contact your local law enforcement and report the incident to U.S. Federal Trade Commission.


Commitment to Non-Discrimination


All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Insider Threat Program Support Officer
Insider Threat Program Support Officer

Leidos • Springfield (VA)

On-site
USD 116,000 - 210,000
Health and Wellness programs
Retirement plan
Tier 3 Cyber Threat Intelligence Analyst
Tier 3 Cyber Threat Intelligence Analyst

Via Logic LLC • Mississippi

On-site
USD 110,000 - 160,000
Insider Threat Program Senior Network Engineer
Insider Threat Program Senior Network Engineer

Leidos • United States

On-site
USD 139,000 - 252,000
Competitive compensation
Health and Wellness programs
Retirement
Tier 3 Cyber Threat Intelligence Analyst
Tier 3 Cyber Threat Intelligence Analyst

Leidos • Washington

On-site
USD 140,000 - 200,000
Tier 3 Cyber Threat Intelligence Analyst
Tier 3 Cyber Threat Intelligence Analyst

Leidos • Chandler (AZ)

On-site
USD 120,000 - 170,000
Cyber Threat Hunter
Cyber Threat Hunter

Leidos • Washington

On-site
USD 107,000 - 196,000
Competitive compensation
Health and Wellness programs
Paid Leave and Retirement
Tier 2 Cyber Incident Response Analyst
Tier 2 Cyber Incident Response Analyst

Leidos Inc • Ashburn (VA)

On-site
USD 87,000 - 157,000
Cyber Intelligence Fusion Analyst
Cyber Intelligence Fusion Analyst

Leidos Inc • Alexandria (VA)

On-site
USD 108,000 - 195,000
Tier 2 Cyber Incident Response Analyst
Tier 2 Cyber Incident Response Analyst

Leidos • Ashburn (VA)

On-site
USD 87,000 - 157,000
Insider Threat Program Senior System Engineer
Insider Threat Program Senior System Engineer

Leidos • Fairfax (VA)

On-site
USD 148,000 - 270,000