Insider Threat Monitoring Analyst

Leidos Inc

Ashburn (VA)

On-site

USD 107,900 - 195,050

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Leidos Inc. seeks an experienced Insider Threat Expert to join the CBP Cyber Security Directorate’s SOC. You will lead user activity monitoring, insider threat analysis, and investigations into data loss, policy violations, and sensitive data spills.

The role requires conducting forensic analysis, generating forensically sound cyber analysis reports, and coordinating with OPR/OI/OIG and other agencies. You will work in Ashburn, VA with TS clearance requirements.

Qualifications

  • Requires BS degree and 8+ years of direct relevant experience.
  • Active and current CISSP certification.
  • Degree in computer science, IT, Information/Cyber Security field from an accredited college.
  • Working knowledge of defense-in-depth principles, network/HW/SW security architecture, and IT device integrity.
  • Demonstrated forensic analysis, digital media analysis, and in-depth system & network log analysis in support of investigations.
  • Must be a U.S. citizen with a Top Secret clearance and ability to obtain CBP BI clearance.

Responsibilities

  • Support Cyber Defense Forensics and Insider Threat investigations via near real-time monitoring of DLP tools.
  • Support investigations with other Government Agencies into CBP personnel behavior.
  • Monitor Foreign Service National network activity for misuse and policy violations.
  • Support User Activity Monitoring (UAM) activities.
  • Recommend insider threat alert triggers and detections across security tools and logs.
  • Monitor CBP laptops and mobile devices for suspicious activity.
  • Provide investigative support for media leak investigations by identifying users who accessed leaks.
  • Provide recommendations for Information Spillage Incident Response per NIST 800-88.

Skills

CISSP certification
Forensic analysis
Digital forensics
Threat monitoring
Incident reporting

Education

BS degree in Computer Science / IT / Information Security
Master's degree (preferred)

Tools

EDR tools
DLP tools
Security monitoring platforms

Job description

Description

The Department of Homeland Security (DHS), Customs and Border Protection (CBP) Cyber Security Directorate (CSD) Security Operations Center (SOC) is a U.S. Government program responsible for preventing, identifying, containing, and eradicating cyber threats to CBP networks through monitoring, intrusion detection, and protective security services to CBP information systems including LAN/WAN, commercial Internet connection, public-facing websites, wireless, mobile/cellular, cloud, security devices, servers, and workstations. The CBPSOC is responsible for the overall security of CBP Enterprise-wide information systems, collecting, investigating, and reporting any suspected and confirmed security violations. Leidos is seeking an experienced Insider Threat Expert to join our team. As a member of this highly technical digital forensics team supporting U.S. Customs and Border Protection (CBP), you will lead user activity monitoring, foreign service national monitoring, insider threat analysis, and investigate policy violations, data loss prevention (DLP) events, and sensitive data spillages.

Primary Responsibilities
  • Supporting the Cyber Defense Forensics and Insider Threat investigations using near real-time monitoring of DLP tools for potential data exfiltration attempts of CBP mission data or employee PII/SPII.
  • Supporting Office of Professional Responsibility (OPR), Office of Intelligence (OI), Office of the Inspector General (OIG) and other Government Agencies in the investigation of CBP personnel operating with potentially malicious or alleged criminal intent.
  • Actively monitoring Foreign Service National (FSN) network activity for misuse and policy violations.
  • Supporting User Activity Monitoring (UAM) activities.
  • Making recommendations for insider threat alert triggers and detections across various security tools and logging sources.
  • Monitoring CBP laptops and mobile devices traveling OCONUS for suspicious activity and policy violations.
  • Providing investigative support for CBP's OPR-Cyber Investigations for media leak investigations by identifying all users who have received/sent, printed, copied, downloaded/uploaded, or accessed the leaked document.
  • Providing recommendations for Information Spillage Incident Response efforts on handling and sanitization methods pursuant to industry best practices, NIST 800-88 recommendations, and Federal guidelines.
Basic Qualifications
  • Requires BS degree and a minimum of 8 or more years of direct relevant experience.
  • Requires an active and current CISSP certification.
  • Degree in computer science, IT, Information/Cyber Security field from an accredited college or university.
  • Additional experience or applicable certifications acceptable in lieu of degree.
  • Working knowledge of defense-in-depth principles, network/HW/SW security architecture, network topology, IT device integrity, and common security elements.
  • Effective communication skills with emphasis on attention to detail, ability to accurately capture and document technical remediation details, and ability to brief stakeholders on incident statuses, recovery and root causes.
  • Demonstrable experience performing forensic analysis, digital media analysis, and in-depth system & network log analysis in support of forensic investigations.
  • Ability to generate forensically sound cyber analysis reports detailing forensic procedures, findings, and recommendations from incident investigations.
  • Strong problem-solving abilities with an analytic and qualitative eye for reasoning under pressure.
  • Experience with User Activity Monitoring products and platforms.
  • Experience with Endpoint Detection and Response (EDR) tools.
  • Must be able to report to the Ashburn VA office up to 5 days per week.
  • Must be a U.S. citizen.
  • Must have a Top Secret clearance.
  • Must be able to obtain and maintain a CBP BI clearance.
Preferred Qualifications

Master's degree from an accredited college or university in IT Management, Engineering, or related field.

  • SANS GREM certification.
  • Previous experience contributing to or leading insider threat investigations in support of Federal Government, DOD, or Law Enforcement environments.
  • Experience performing computer forensics in Federal Government, DOD or Law Enforcement environments.
Pay and Benefits

Pay Range: $107,900.00 - $195,050.00. The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available at www.leidos.com/careers/pay-benefits.

Commitment to Non-Discrimination

All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Insider Threat Monitoring Analyst
Insider Threat Monitoring Analyst

Via Logic LLC • Ashburn (VA)

On-site
USD 120,000 - 180,000
Tier 2 Cyber Incident Response Analyst
Tier 2 Cyber Incident Response Analyst

Leidos • Ashburn (VA)

On-site
USD 87,000 - 157,000
Insider Threat Program Support Officer
Insider Threat Program Support Officer

Leidos • Springfield (VA)

On-site
USD 116,000 - 210,000
Health and Wellness programs
Retirement plan
Insider Threat & Digital Forensics Analyst
Insider Threat & Digital Forensics Analyst

Leidos Inc • Ashburn (VA)

On-site
USD 107,000 - 196,000
Insider Threat Monitoring & Investigations Analyst
Insider Threat Monitoring & Investigations Analyst

Via Logic LLC • Ashburn (VA)

On-site
USD 120,000 - 180,000
Tier 2 Cyber Incident Response Analyst
Tier 2 Cyber Incident Response Analyst

Leidos Inc • Ashburn (VA)

On-site
USD 87,000 - 157,000
InInsider Threat Program Hunt Team Analyst
InInsider Threat Program Hunt Team Analyst

Leidos • Springfield (VA)

On-site
USD 105,000 - 190,000
Assessment & Authorization Analyst
Assessment & Authorization Analyst

Leidos Inc • Ashburn (VA)

On-site
USD 69,550 - 125,725
Health and Wellness programs
Income Protection
Paid Leave
+1
Assessment & Authorization Analyst
Assessment & Authorization Analyst

Koitecc Solutions • Ashburn (VA)

On-site
USD 87,000 - 157,000
Health and Wellness programs
Paid Leave
Retirement
Assessment & Authorization Analyst
Assessment & Authorization Analyst

Leidos • Ashburn (VA)

On-site
USD 87,000 - 157,000
Health benefits
Paid leave
Retirement plan