Insider Threat Support Analyst

Evolver Inc

Camp Springs (MD)

On-site

USD 100,000 - 140,000

Full time

5 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Health, dental and vision insurance
401(k) plan
Flexible spending account
Paid time off and parental leave

Job summary

Evolver Inc is seeking a talented Insider Threat Support Analyst to join our Camp Springs, MD team onsite. You will focus on identifying and mitigating risks posed by trusted individuals, leveraging DLP, SIEM (Splunk), EDR/NDR, UAM (Teramind), and IAM logs.

The role emphasizes proactive risk scoring, evidence-based containment actions, and cross-functional collaboration to refine playbooks while aligning with policy and civil liberties requirements.

Qualifications

  • Bachelor's degree in Computer Science, Information Security, or related field, OR 2+ years of insider threat detection experience.
  • Active Security+ or ISC2 CISSP (or approved equivalent) required.
  • 2+ years of SPLUNK architecture experience (indexer, forwarder, search heads).
  • U.S. Citizen with Top Secret Clearance and SCI eligibility (ICD 704) without waivers.

Responsibilities

  • Independently run daily insider-threat operations across multiple telemetry sources (DLP, SIEM, EDR/NDR, UAM, IAM).
  • Conduct end-to-end risk scoring and document notable cases with evidence and containment actions.
  • Collaborate with cross-functional teams to refine playbooks and adjust risk thresholds.
  • Lead weekly coordination with Applied Intelligence and platform owners to update detection logic.
  • Prepare Monthly InT Summaries with metrics and trends.
  • Utilize SPLUNK and Teramind to optimize data analysis and incident reporting.

Skills

Insider threat analysis
Risk scoring
Self-motivated
Analytical thinking
Cross-functional collaboration

Education

Bachelor's degree in Computer Science / Information Security or related field

Tools

SPLUNK
UI/GUI development
Teramind (UAM)
DLP
EDR/NDR
IAM logging

Job description

Evolver is an information technology, cybersecurity, and digital transformation company supporting national defense, federal civilian agencies, and Fortune 500 organizations. We help customers secure critical systems, modernize enterprise technology, and solve complex operational challenges through integrated technology capabilities spanning cybersecurity, enterprise IT infrastructure, cloud, software development, data analytics, legal technology and eDiscovery, applied AI, and electronic security systems. Our teams combine deep technical expertise with mission understanding to deliver secure, reliable, and scalable solutions that advance performance in high-stakes environments.

Evolver is seeking a talented and motivated Insider Threat Support Analyst to join our team onsite in Camp Springs, MD.

The ideal candidate will have a strong background in cybersecurity and risk management, serving as a critical member of the Cyber Intelligence Operations program's dedicated insider-risk element (InT). As an Insider Threat Support Analyst, you will focus on identifying, assessing, and mitigating risks posed by trusted individuals including employees, contractors, and partners who may intentionally or unintentionally harm organizational systems, data, or personnel. Operating as a highly motivated self-starter within a lean, agile team, you must possess the technical drive and critical thinking needed to execute complex investigations and refine detection strategies with minimal oversight. Emphasizing departing-employee and high-risk user scenarios, you will leverage telemetry from DLP, SIEM (Splunk), EDR/NDR, cloud storage, email, VPN/web, UAM (Teramind), and IAM logs. You will maintain prioritized insider use-case catalogs, apply defensible risk scoring, and collaborate with cross-functional teams to define requirements for automation-first playbooks, all while ensuring strict alignment with policy, privacy, civil liberties, and inspection requirements.

Responsibilities:
  • Independently run daily operations, proactively identifying and triaging indicators of malicious, negligent, or coerced insider risk across multiple telemetry sources (DLP, SIEM, EDR/NDR, UAM, IAM).
  • Conduct end-to-end, self-directed risk scoring and categorization of user activity. Document notable cases, gather evidence, and recommend containment actions without requiring step-by-step guidance.
  • Work closely and dynamically within a small, specialized unit to share insights, cover operational gaps, and contribute insider updates to internal briefs and situational awareness (e.g., standups/shift changes).
  • Proactively maintain and refine a prioritized insider use-case catalog. Take ownership of weekly coordination with Applied Intelligence and platform owners to adjust playbooks and update risk-scoring thresholds.
  • Author Monthly InT Summaries focusing on insider-specific metrics, false positive trends, and emerging risk patterns. Act as the self-directed lead for designated case reviews to identify detection, process, and monitoring gaps.
  • Independently utilize SPLUNK architecture and UI/GUI development skills to optimize data analysis workflows. Oversee User Activity Monitoring (UAM) tools like Teramind to support robust incident reporting.
Basic Qualifications:
  • Must possess and maintain at least one active certification: Security+ or ISC2 CISSP (or other comparable certification approved in advance by the SOC PM).
  • Bachelor's degree in Computer Science, Information Security, or a related field, OR a minimum of two (2) years of dedicated experience in insider threat detection, APT mitigation, and User Activity Monitoring (e.g., Teramind).
  • 2+ years of experience with SPLUNK architecture (indexer, forwarder, search heads, etc.), including UI/GUI development and operational roles. Familiarity with DLP, EDR/NDR, and IAM logging.
  • Must be a U.S. Citizen with an active Top Secret Clearance.
  • Must meet SCI eligibility (ICD 704) with no waivers or conditions.
Preferred Qualifications:
  • Proven track record as a self-starter with a demonstrated ability to establish task priorities, manage workflows, and deliver high-quality analytical products with minimal supervision.
  • Experience working effectively in small, fast-paced team environments where cross-training, adaptability, and direct communication are critical.
  • 3+ years of experience with SPLUNK architecture, UI/GUI development, and automation-first SOAR integrations.
  • 3+ years of specific experience in insider threat detection, behavioral analytics, and mitigation techniques.
  • Strong analytical and problem-solving skills, with the ability to dissect complex security incidents, assign defensible risk scores, and communicate findings effectively to technical and non-technical stakeholders.
  • Proven ability to develop tactical metrics, monthly trend summaries, and strategic intelligence reports.
  • Familiarity with privacy, civil liberties, and HR compliance considerations regarding insider threat monitoring.

Evolver is an equal opportunity employer and welcomes all job seekers. It is the policy of Evolver not to discriminate based on race, color, ancestry, religion, gender, age, national origin, gender identity or expression, sexual orientation, genetic factors, pregnancy, physical or mental disability, military/veteran status, or any other factor protected by law.

Actual salary will depend on factors such as skills, qualifications, experience, market and work location. Evolver offers competitive benefits, including health, dental and vision insurance, 401(k), flexible spending account, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Insider Threat Support Analyst
Insider Threat Support Analyst

Socket.dev • Camp Springs (MD)

On-site
USD 90,000 - 130,000
Lead Cyber Threat Analyst
Lead Cyber Threat Analyst

Evolver Federal • Washington

On-site
USD 140,000 - 190,000
TS-Cleared Insider Threat Analyst
TS-Cleared Insider Threat Analyst

Socket.dev • Camp Springs (MD)

On-site
USD 90,000 - 130,000
Data Gathering Specialist (Forensics)
Data Gathering Specialist (Forensics)

Evolver • Camp Springs (MD)

Hybrid
USD 75,000 - 100,000
Health, dental and vision insurance
401(k)
Flexible spending account
+1
Insider Threat Support Analyst
Insider Threat Support Analyst

Zachary Piper Solutions • Camp Springs (MD), Northern (KY)

Hybrid
USD 117,000 - 143,000
PTO
Paid holidays
Medical insurance
+6
Insider Threat Analyst (TS)
Insider Threat Analyst (TS)

Agile Defense • Washington

On-site
USD 90,000 - 130,000
Lead Incident Responder
Lead Incident Responder

Evolver Federal • Washington

On-site
USD 150,000 - 190,000
Security Engineer (Insider Risk)
Security Engineer (Insider Risk)

Dragonfli Group • Washington

Hybrid
USD 120,000 - 160,000
Insurance - health, dental, and vision
Paid Time Off (PTO) and 11 Federal Holidays
401(k) employer match
Insider Risk Analyst
Insider Risk Analyst

Peraton • Herndon (VA)

On-site
USD 51,000 - 82,000
Veritas eDiscovery Platform (eDP) Engineer
Veritas eDiscovery Platform (eDP) Engineer

Evolver Federal • Washington

On-site
USD 110,000 - 160,000