Insider Threat Monitoring Analyst

Leidos, Inc.
Ashburn, VA, United States
28 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Compensation
$107,900.0 - $195,050.0
Working hours
Regular working hours

Tech stack

Cyber Security Computer Forensics Information Leak Prevention Digital Forensics Network Topologies IT Management Log Analysis Data Logging Information Technology Cyber Warfare

Job description

Leidos is seeking an experienced Insider Threat Expert to join our team. As a member of this highly technical digital forensics team supporting U.S. Customs and Border Protection (CBP), you will be responsible for leading user activity monitoring activities, foreign service national monitoring, insider threat analysis, and investigating policy violations, data loss prevention (DLP) events, and sensitive data spillages.

The candidate will be responsible for:

  • Supporting the Cyber Defense Forensics and Insider Threat investigations using near real- time (when possible, based on tools) monitoring of DLP tools for potential data exfiltration attempts of CBP mission data or employee PII/SPII
  • Support Office of Professional Responsibility (OPR), Office of Intelligence (OI), Office of the Inspector General (OIG) and Other Government Agencies in the investigation of CBP personnel operating with potentially malicious or alleged criminal intent.
  • Actively monitor Foreign Service National (FSN) network activity for network misuse and policy violations.
  • Support User Activity Monitoring (UAM) activities.
  • Make recommendations for insider threat alert triggers and detections across various security tools and logging sources.
  • Monitor CBP laptops and mobile devices traveling OCONUS for suspicious activity and policy violations.
  • Provide investigative support for CBP’s OPR-Cyber Investigations for media leak investigations by identifying all users who have received/sent, printed, copied, downloaded/uploaded, or accessed the leaked document.
  • Provide recommendations for Information Spillage Incident Response efforts on handling and sanitization methods pursuant to industry best practices, NIST 800-88 recommendations, and Federal guidelines.

Requirements

  • Requires BS degree and a minimum of 8 or more years of direct relevant experience.
  • Requires an active and current CISSP certification
  • Degree in computer science, IT, Information/Cyber Security field from an accredited college or university.
  • Additional experience or applicable certifications acceptable in lieu of degree.
  • Working knowledge of defense-in-depth principles, network/HW/SW security architecture, network topology, IT device integrity, and common security elements
  • Effective communication skills with emphasis on attention to detail, ability to accurately capture and document technical remediation details, and ability to brief stakeholders on incident statuses, recovery and root causes.
  • Demonstrable experience performing forensic analysis, digital media analysis, and in-depth system & network log analysis in support of forensic investigations.
  • Ability to generate forensically sound cyber analysis reports detailing forensically sound analysis procedures, findings, and recommendations from incident investigations.
  • Strong problem-solving abilities with an analytic and qualitative eye for reasoning under pressure.
  • Experience with User Activity Monitoring products and platforms
  • Experience with Endpoint Detection and Response (EDR) tools
  • Must be able to report to the Ashburn VA office up to 5 days per week
  • Must be have a US Citizenship
  • Must have a Top Secret clearance
  • Must be able to obtain and maintain a CBP BI clearance.

Master’s degree from an accredited college or university in IT Management, Engineering, or related field

  • SANS GREM certification
  • Previous experience contributing to or leading insider threat investigations in support of Federal Government, DOD, or Law Enforcement environments.
  • Experience performing computer forensics in Federal Government, DOD or Law Enforcement environments.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

11:18 min

Addressing audience questions on security and microservice architectures

Reinhard Kugler · LIVE

1:10 min

Exposing sensitive information through partial search logs

Dennis Schulz Dennis Schulz +1 · WWC Europe 2026

1:53 min

Managing infrastructure limitations with managed Amazon Aurora databases

Dharin Shah Dharin Shah · WWC 2025

3:29 min

Forecasting organizational cybersecurity risks through public employee reviews

3:48 min

Leveraging multi-agent systems for autonomous software testing

Ondřej Gróf Ondřej Gróf · WWC Europe 2026

1:37 min

Leveraging continuous intelligence tracking for rapid vulnerability alerting

Matthew Brady Matthew Brady · WWC Europe 2026

Videos

See all

Related articles

See all