> Markdown version of [/jobs/ext/3571849-cyber-intel-associate-analyst-insider-threat-cirt-rockville-md](https://www.wearedevelopers.com/jobs/ext/3571849-cyber-intel-associate-analyst-insider-threat-cirt-rockville-md). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Intel Associate Analyst - Insider Threat / CIRT / Rockville MD - **Company:** Lockheed Martin - **Location:** Rockville, MD, United States - **Salary:** $75,400.0 - $140,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Agile Methodology, Artificial Intelligence, Data Analysis, Confluence, JIRA, Bash Shell, Cloud Computing, CompTIA Security+, Cyber Security, Linux, Issue Tracking Systems, Information Technology Operations, Intelligence Analysis, Intrusion Detection and Prevention, Python (Programming Language), Network Security, Machine Learning, Windows PowerShell, Scrum Methodology, Jupyter Notebook, Image Acquisition, Scripting, Gitlab, SC Clearance, AI Platforms, Information Technology, Cybercrime, Low-code, 3-tier Architectures, Splunk, Software Version Control, Unsupervised Learning - **Published:** October 3, 2026 - **Apply:** https://www.careerjet.com/job/use523602bb65afec0a0d8f87c27a1579f/eaa ## About the Role * Bachelor's degree (or equivalent experience) in Computer Science, Information Technology, Cyber-Security, Data Science, or a related technical field * Basic knowledge of Splunk (search language, dashboard creation) * Familiarity with at least one scripting language (Python, PowerShell, Bash) * Experience working in a Unix/Linux command-line environment * Demonstrated ability to interpret raw log data, draw logical conclusions, and document findings * Strong written and verbal communication and ability to present technical material to both technical and non-technical audiences * Proven ability to work collaboratively within a team and follow defined processes * Willingness to work flexible hours or on-call rotations as required by mission needs * US Citizenship with eligibility for Secret Clearance or higher ## Desired Skills * Familiarity with basic forensic concepts (memory/image capture, timeline creation) or participation in a cyber-incident response exercise. * Understanding of insider-threat lifecycle, misuse cases, and behavioral analytics. * Hands-on experience with Splunk Machine Learning Toolkit, Jupyter notebooks, or other low-code AI platforms; basic understanding of supervised vs. unsupervised learning. * Experience using JIRA, Git Lab, or similar version-control and ticketing systems. * Splunk Core Certified User, CompTIA Security+, EC-Council CEH, or a foundational AI/ML certification (e.g., Coursera "AI for Everyone"). * Prior exposure to IT operations, system administration, network security, or intelligence analysis. ## Description Lockheed Martin's Computer Incident Response Team (CIRT) Insider Threat Team is hiring a Cyber Intel Associate Analyst. This role will report to the Insider Threat Team Associate Manager within Corporate Information Security (CIS). What You Will Be Doing: This role will build on foundational knowledge rooted in Cyber Security, focusing on Insider Threat detection methodologies against various operating system, network, and security infrastructure logs to identify potential insider threats within the organization. You will leverage native analytics tools in conjunction with internal and commercial AI/ML models to uncover, surface, and mitigate insider-threat activity. The role is hands-on, collaborative, and will provide exposure to the full CIRT lifecycle-from data collection through detection design, automation, and reporting. You will also work with various teams within CIRT, CIS, and across the Enterprise to advance the LM-CIRT missions. Your key responsibilities will include the following: * Support Complex Problem Investigation. You will be collaborating with senior analysts to explore insider threat scenarios that lack existing detection coverage, executing hypothesis driven searches, aggregating relevant log data, and documenting preliminary findings. Under senior guidance, you will be prototyping a simple detection rule or automation script, testing it on sandbox data, and updating team documentation with the validated solution. This iterative process builds foundational analytical skills while contributing to the evolution of LM CIRT's detection capabilities. * Detection Development. You will create Splunk alerts, reports, and simple correlation searches, and be exposed to building YARA rules. * Log & Data Analysis. You will parse operating system, network, endpoint, and security infrastructure logs (Windows, Linux, cloud) to identify patterns indicative of insider threat behavior. * Automation & Workflow Enablement. You will identify routine analytic steps that can be automated and create scripts or automation playbooks to reduce manual effort. * AI assisted Detection Development. You will assist senior analysts in building and refining detection content that incorporates leveraging AI models, Splunk, and automation capabilities. * Threat Hunting Support. You will participate in structured threat hunting cycles, executing hypothesis driven queries and documenting findings for senior review. * Reporting & Knowledge Sharing. You will produce concise detection tuning notes, dashboards, and fused intelligence briefings for internal stakeholders (CIRT, Counterintelligence, leadership). * Agile Collaboration. You will work within the team's Agile development process (Scrum/Kanban) using JIRA, Git Lab, and Confluence to track work, version control detection code, and maintain documentation. * Continuous Learning. You will be able to stay current on emerging insider threat tactics, AI/ML advances, and relevant regulatory requirements (e.g., NIST 800 53, DFARS)., The Tier 3 Cybersecurity Analyst serves as a senior technical leader within the SOC, responsible for advanced threat detection, incident response, threat hunting, and forensic anal… + 8 days ago +