Insider Threat Analyst

Agile Defense

Washington (District of Columbia)

On-site

USD 110,000 - 160,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Agile Defense is seeking an Insider Threat Analyst to support the ITDP effort, performing day‑to‑day detection, analysis, and triage of potential insider threat activity under the direction of the Senior Insider Threat Analyst.

The analyst monitors and investigates alerts across multiple enterprise applications, distinguishing genuine insider threat incidents from false positives, and documents findings in accordance with established procedures.

Qualifications

  • U.S. citizenship and ability to obtain/maintain a Tier 5+ security clearance.
  • BS or BA degree, or equivalent experience in lieu of a degree.
  • Approximately 6 years of combined cybersecurity, security operations, investigations, or insider threat analysis.
  • Hands-on experience with enterprise insider threat, DLP, SIEM, or UEBA/UAM tools (e.g., Splunk, DTEX, Proofpoint/ObserveIT, Purview, Exabeam).
  • Ability to analyze logs and dashboards to differentiate real incidents from false positives.
  • Working knowledge of Windows, Unix, Linux environments and common insider threat indicators.
  • Knowledge of privacy and civil liberties requirements in insider threat programs.
  • Strong written communication and ability to work under supervision of senior analysts.
  • Ability to obtain Counter-Insider Threat Fundamentals Certification if required.

Responsibilities

  • Monitor and analyze logs and alerts to determine real insider threat incidents vs. false positives.
  • Triage and investigate potential indicators, escalating to Senior Analyst as needed.
  • Support configuration, tuning, and troubleshooting of application triggers for insider threat detection.
  • Assist with deployment, operation, and maintenance of enterprise detection tools.
  • Document findings with clear analytical write-ups and maintain case records.
  • Correlate data across sources to build a complete picture of activity.
  • Assist in developing workflows, playbooks, and program documentation.
  • Ensure activities protect privacy and civil liberties and comply with legal requirements.
  • Coordinate with SOC and other stakeholders to support program objectives.

Skills

Insider threat analysis
Log analysis
Written communication
Privacy & civil liberties
Security clearance readiness

Education

Bachelor's degree (BS/BA)

Tools

Splunk
DTEX
Proofpoint/ObserveIT
Microsoft Purview
Exabeam

Job description

About Agile Defense
At Agile Defense we know that action defines the outcome and new challenges require new solutions. That’s why we always look to the future and embrace change with an unmovable spirit and the courage to build for what comes next.
Our vision is to bring adaptive innovation to support our nation's most important missions through the seamless integration of advanced technologies, elite minds, and unparalleled agility—leveraging a foundation of speed, flexibility, and ingenuity to strengthen and protect our nation’s vital interests.

DESCRIPTION

The Insider Threat Analyst supports the Insider Threat Program Detection and Prevention (ITPDP) effort, performing day‑to‑day detection, analysis, and triage of potential insider threat activity under the direction of the Senior Insider Threat Analyst. The analyst monitors and investigates alerts across multiple enterprise applications, distinguishing genuine insider threat incidents from false positives, and documents findings in accordance with established procedures. Working within an established program, the analyst applies both the technical and human dimensions of insider threat analysis while ensuring activities are conducted in accordance with applicable federal insider threat guidelines and with careful attention to employee privacy and civil liberties.

ESSENTIAL FUNCTIONS
  • Monitor and analyze logs and alerts from multiple applications via dashboards and other means to determine whether activity represents an actual insider threat incident or a false positive.
  • Triage and investigate potential insider threat indicators, escalating confirmed or ambiguous incidents to the Senior Insider Threat Analyst as appropriate.
  • Support the configuration, tuning, and troubleshooting of application triggers used for insider threat detection in an enterprise environment.
  • Assist with the deployment, operation, and maintenance of enterprise tools supporting insider threat detection.
  • Document findings, produce clear analytical write‑ups, and maintain case records in accordance with established reporting procedures.
  • Correlate data across multiple sources to build a complete picture of potential insider threat activity.
  • Support the development and refinement of workflows, playbooks, and program documentation.
  • Conduct all activities in a manner that protects employee privacy and civil liberties and meets the legal requirements of an insider threat program.
  • Coordinate with SOC, investigative, and other stakeholders as directed to support program objectives.
QUALIFICATIONS
  • U.S. citizenship and ability to receive and maintain a security clearance at the Tier 5 level or higher.
  • BS or BA degree, or additional related experience in lieu of a degree.
  • Approximately 6 years of combined experience across cybersecurity, security operations, investigations, or insider threat analysis.
  • Hands‑on experience with one or more enterprise insider threat, DLP, SIEM, or UEBA/UAM tools (e.g., Splunk, DTEX, Proofpoint/ObserveIT, Microsoft Purview, Exabeam, or similar).
  • Demonstrated ability to analyze logs and dashboards to differentiate real incidents from false positives.
  • Working knowledge of Windows, Unix, and Linux environments and common insider threat indicators and behaviors.
  • Familiarity with log analysis, event correlation, and basic investigative techniques, including awareness of digital forensics concepts.
  • Understanding of the legal and ethical requirements of an insider threat program as they relate to privacy and civil liberties.
  • Strong written communication for documenting findings, and the ability to work under the direction of senior analysts within an established program.
  • Ability to obtain the Counter‑Insider Threat Fundamentals Certification if required.
Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities

This company is an equal opportunity employer.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Insider Threat Analyst (TS)
Insider Threat Analyst (TS)

Agile Defense, Inc. • Washington

On-site
USD 110,000 - 135,000
Insider Threat Analyst: Detection & Investigation Expert
Insider Threat Analyst: Detection & Investigation Expert

Agile Defense, Inc. • Washington

On-site
USD 110,000 - 135,000
Insider Threat Analyst — SIEM & Analytics Specialist
Insider Threat Analyst — SIEM & Analytics Specialist

Agile Defense • Washington

On-site
USD 110,000 - 160,000
Insider Threat Analyst
Insider Threat Analyst

NR Labs LLC • Washington

On-site
USD 95,000 - 130,000
Insider Threat Monitoring Lead (CBP)
Insider Threat Monitoring Lead (CBP)

Agile Defense • Ashburn (VA)

Hybrid
USD 120,000 - 150,000
Health Insurance
Life Insurance
Paid Time Off
+4
Insider Threat Data Specialist
Insider Threat Data Specialist

FedTec • Woodlawn (MD)

On-site
USD 110,000 - 150,000
Comprehensive medical, dental, and vis
401(k) retirement plans with company
Paid time off
+4
Insider Threat Monitoring Lead
Insider Threat Monitoring Lead

Agile Defense, LLC • Reston (VA)

Hybrid
USD 160,000 - 185,000
Insider Threat Engineer
Insider Threat Engineer

Jobtailor • Austin (TX)

On-site
USD 120,000 - 180,000
Insider Threat Program Hunt Team Analyst (w/ active TS/SCI)
Insider Threat Program Hunt Team Analyst (w/ active TS/SCI)

CriticalSolutions, LLC • Springfield (VA)

On-site
USD 120,000 - 180,000
Senior Cyber Security Specialist I - Insider Threat Analysis
Senior Cyber Security Specialist I - Insider Threat Analysis

Walgreens • United States

Hybrid
USD 98,000 - 158,000