Insider Threat Monitoring Analyst

VIA Inc
Ashburn, VA, United States
7 days ago
Apply on startup.jobs
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$106,000.0 - $126,000.0
Working hours
Regular working hours
Job source

Tech stack

Cyber Security Computer Forensics Information Leak Prevention Data Loss Network Monitoring Security Information and Event Management Technical Data Management Systems Data Logging Enterprise Software Applications Information Technology

Job description

Join Via Logic supporting U.S. Customs and Border Protection cybersecurity operations. As a Mid-Level Insider Threat Monitoring Analyst, you’ll support insider threat monitoring activities by analyzing user behavior, access patterns, and security events to identify potential insider threat indicators.

You’ll use insider threat monitoring and security tools to identify anomalous activity, investigate alerts, and determine whether activity may represent an insider threat, data loss, or security policy concern. You’ll also support security investigations and help document findings that protect sensitive information and government systems.

Eligibility & Clearance Requirements

Due to CBP contract requirements, applicants must:

  • Be a U.S. citizen.
  • Be able to obtain and maintain the required CBP background investigation and suitability determination for access to government facilities and systems.
  • Be available to work onsite, primarily in Ashburn, VA, with specific worksite and travel expectations confirmed for the assignment.

Your Mission

  • Support insider threat monitoring activities by analyzing user behavior, access patterns, security events, and other relevant activity for potential insider threat indicators.
  • Monitor Data Loss Prevention (DLP) solutions and other applicable security tools to support insider threat and security operations investigations.
  • Investigate DLP alerts involving potential data exfiltration of CBP mission data or sensitive employee information.
  • Support User Activity Monitoring (UAM) activities and investigative tasks as directed by government staff.
  • Monitor network activity for potential misuse and security policy violations.
  • Analyze alerts and investigative information to identify suspicious or anomalous activity and support appropriate investigative action.
  • Support investigations involving potential malicious activity, alleged criminal activity, or unauthorized disclosure of information.
  • Support sensitive-data spillage response by helping assess incidents and recommending appropriate handling and sanitization methods in accordance with applicable guidance and procedures.
  • Monitor government laptops and mobile devices associated with foreign travel for suspicious activity and policy violations.
  • Recommend improvements to insider threat alert triggers and detections across security tools and logging sources.
  • Document investigative activity and contribute to incident notifications, case analysis, reports, and other required work products., * This position works full-time onsite in Ashburn, VA at a government site.
  • You’ll collaborate with Via Logic teammates, government partners, cybersecurity teams, and investigative stakeholders using tools approved for your work environment.
  • Core task coverage is generally weekdays, 8:30 a.m.-5:00 p.m. Eastern Time, with on-call support requirements based on assignment needs.
  • When virtual meetings are part of the work, we expect active participation and use video when appropriate and permitted by the client environment.

Requirements

  • 3+ years of relevant professional experience in cybersecurity operations, insider threat monitoring, security investigations, incident detection and response, cyber forensics, or a related area.
  • Experience analyzing user activity, security events, alerts, logs, or similar technical data to identify suspicious or anomalous behavior.
  • Experience investigating or supporting investigations involving security incidents, policy violations, data loss, or potentially unauthorized activity.
  • Knowledge of Data Loss Prevention (DLP), User Activity Monitoring (UAM), or similar security monitoring concepts and capabilities.
  • Ability to analyze information from multiple sources, identify relevant patterns or concerns, and document investigative findings clearly.
  • Ability to communicate technical findings and collaborate effectively with security analysts, investigators, government personnel, and other stakeholders., * Experience working within or closely alongside a Security Operations Center or insider threat program.
  • Hands-on experience with DLP or UAM tools and workflows.
  • Experience supporting cyber forensic or security investigations.
  • Experience investigating potential data exfiltration, sensitive-data spillages, or misuse of enterprise systems.
  • Experience developing or refining security alerting or detection logic based on investigative findings.

Benefits & conditions

  • Healthcare coverage and paid time off that give you room to take care of life outside work.
  • Teammates who share knowledge, pitch in, and help each other grow.
  • Opportunities to deepen your specialty and explore adjacent areas of cybersecurity as new assignments open up.
  • Meaningful work protecting systems and information that support a federal mission.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on startup.jobs
Prepare application

Good distractions

Loading talks and stories from around this role…