Insider Threat Monitoring Analyst

Via Logic LLC

Ashburn (VA)

On-site

USD 120,000 - 180,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Leidos seeks an experienced Insider Threat Expert to lead investigations, monitor insider activity, and coordinate forensics for CBP. The role covers data loss prevention, policy violations, and sensitive data handling, with close collaboration with OPR, OIG, and other agencies. The position is based in Ashburn, VA, with potential on-site duties.

Required are a BS with 8+ years of related experience, active CISSP, U.S. citizenship, and ability to obtain CBP BI clearance.

Qualifications

  • BS degree with a minimum of 8 years of directly relevant experience.
  • Active CISSP certification.
  • U.S. citizenship and ability to obtain CBP BI clearance.
  • Experience with User Activity Monitoring and Endpoint Detection & Response tools.
  • Experience performing forensic and digital media analysis.
  • Ability to brief stakeholders and document remediation details.

Responsibilities

  • Lead investigations and support for insider threat and forensics activities, including near real-time monitoring of DLP tools for potential data exfiltration of CBP mission data or employee PII/SPII.
  • Support investigations with the Office of Professional Responsibility (OPR), Office of Intelligence (OI), Office of the Inspector General (OIG), and other government agencies when CBP personnel may be malicious or have alleged criminal intent.
  • Actively monitor Foreign Service National (FSN) network activity for misuse and policy violations.
  • Support User Activity Monitoring (UAM) activities.
  • Recommend insider threat alert triggers and detections across various security tools and logging sources.
  • Monitor CBP laptops and mobile devices traveling OCONUS for suspicious activity and policy violations.
  • Provide investigative support for CBP’s OPR-Cyber Investigations related to media leak investigations by identifying all users who accessed, sent, printed, copied, downloaded/uploaded, or received leaked documents.
  • Provide recommendations for Information Spillage Incident Response, following industry best practices, NIST 800-88, and federal guidelines.

Skills

Insider threat
Digital forensics
Forensic analysis
Incident response
UAM tools
EDR tools
CISSP
Clearance requirements

Education

Bachelor's degree in IT/CS/Security
Master's degree (preferred)

Tools

DLP tools
EDR tools
FSN monitoring tools
UAM platforms

Job description

Overview

The Department of Homeland Security (DHS), Customs and Border Protection (CBP) Cyber Security Directorate (CSD) Security Operations Center (SOC) is a US Government program responsible for preventing, identifying, containing, and eradicating cyber threats to CBP networks through monitoring, intrusion detection, and protective security services. The CBP SOC secures CBP Enterprise-wide information systems (LAN/WAN, cloud, mobile, wireless, websites, and devices) and collects, investigates, and reports suspected and confirmed security violations. Leidos is seeking an experienced Insider Threat Expert to join our team to lead user activity monitoring, FSN monitoring, insider threat analysis, and investigations of policy violations, data loss prevention (DLP) events, and sensitive data spillages in support of CBP.

Primary Responsibilities
  • Lead investigations and support for insider threat and forensics activities, including near real-time monitoring of DLP tools for potential data exfiltration of CBP mission data or employee PII/SPII.
  • Support investigations with the Office of Professional Responsibility (OPR), Office of Intelligence (OI), Office of the Inspector General (OIG), and other government agencies when CBP personnel may be malicious or have alleged criminal intent.
  • Actively monitor Foreign Service National (FSN) network activity for misuse and policy violations.
  • Support User Activity Monitoring (UAM) activities.
  • Recommend insider threat alert triggers and detections across various security tools and logging sources.
  • Monitor CBP laptops and mobile devices traveling OCONUS for suspicious activity and policy violations.
  • Provide investigative support for CBP’s OPR-Cyber Investigations related to media leak investigations by identifying all users who accessed, sent, printed, copied, downloaded/uploaded, or received leaked documents.
  • Provide recommendations for Information Spillage Incident Response, following industry best practices, NIST 800-88, and federal guidelines.
Qualifications
  • BS degree with a minimum of 8 years of directly relevant experience.
  • Active and current CISSP certification.
  • Degree in computer science, IT, Information/Cyber Security from an accredited college or university; additional experience or applicable certifications may be accepted in lieu of a degree.
  • Working knowledge of defense-in-depth principles, security architecture (network/HW/SW), IT device integrity, and common security elements.
  • Effective communication skills with attention to detail, ability to document technical remediation details, and ability to brief stakeholders on incident statuses, recovery, and root causes.
  • Experience performing forensic and digital media analysis, and in-depth system and network log analysis to support investigations.
  • Ability to generate forensically sound cyber analysis reports detailing procedures, findings, and recommendations.
  • Strong problem-solving abilities with analytical reasoning under pressure.
  • Experience with User Activity Monitoring products and platforms.
  • Experience with Endpoint Detection and Response (EDR) tools.
  • Ability to report to the Ashburn, VA office up to 5 days per week.
  • U.S. citizenship is required.
  • Active Top Secret clearance and ability to obtain and maintain a CBP BI clearance.
Preferred Qualifications
  • Master’s degree in IT Management, Engineering, or a related field.
  • SANS GREM certification.
  • Experience contributing to or leading insider threat investigations in Federal Government, DOD, or Law Enforcement environments.
  • Experience performing computer forensics in Federal Government, DOD, or Law Enforcement environments.

All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, disability, genetic information, pregnancy, family structure, marital status, or any other Basis prohibited by law. Leidos will also consider qualified applicants with criminal histories consistent with relevant laws.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Insider Threat Monitoring Analyst
Insider Threat Monitoring Analyst

Leidos Inc • Ashburn (VA)

On-site
USD 107,000 - 196,000
Insider Threat & Digital Forensics Analyst
Insider Threat & Digital Forensics Analyst

Leidos Inc • Ashburn (VA)

On-site
USD 107,000 - 196,000
Insider Threat Monitoring & Investigations Analyst
Insider Threat Monitoring & Investigations Analyst

Via Logic LLC • Ashburn (VA)

On-site
USD 120,000 - 180,000
Insider Threat Program Support Officer
Insider Threat Program Support Officer

Leidos • Springfield (VA)

On-site
USD 116,000 - 210,000
Health and Wellness programs
Retirement plan
Assessment & Authorization Analyst
Assessment & Authorization Analyst

Leidos Inc • Ashburn (VA)

On-site
USD 69,550 - 125,725
Health and Wellness programs
Income Protection
Paid Leave
+1
Insider Threat Support Analyst
Insider Threat Support Analyst

Piper Companies • Camp Springs (MD)

On-site
USD 117,000 - 143,000
Salary up to $130,000
Full Benefits Package
Assessment & Authorization Analyst
Assessment & Authorization Analyst

Koitecc Solutions • Ashburn (VA)

On-site
USD 87,000 - 157,000
Health and Wellness programs
Paid Leave
Retirement
Insider Threat Support Analyst
Insider Threat Support Analyst

Zachary Piper Solutions • Camp Springs (MD), Northern (KY)

On-site
USD 117,000 - 143,000
PTO
Paid holidays
Medical insurance
+6
InInsider Threat Program Hunt Team Analyst
InInsider Threat Program Hunt Team Analyst

Leidos Inc • Springfield (VA)

On-site
USD 105,000 - 190,000
Senior Incident Response Analyst
Senior Incident Response Analyst

Leidos Inc • Arlington (VA)

On-site
USD 131,000 - 238,000
Competitive compensation
Health and wellness programs
Paid leave
+1