> Markdown version of [/jobs/ext/517739-insider-threat-program-hunt-team-analyst-w-active-ts-sci](https://www.wearedevelopers.com/jobs/ext/517739-insider-threat-program-hunt-team-analyst-w-active-ts-sci). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Insider Threat Program Hunt Team Analyst (w/ active TS/SCI) - **Company:** Critical Solutions - **Location:** Lorton, VA, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Data Analysis, Cyber Security, Computer Networks, Monitoring of Systems, Intelligence Analysis, Open Source Technology, Cyber Threat Analysis - **Published:** June 10, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=c3b1df9e61a375a9 ## About the Role Do you have experience in Threat intelligence?, Do you have a Master's degree in cybersecurity?, * Active Top Secret/SCI or SCI eligible. * Bachelors degree and (8)+ years of prior relevant insider threat experience or Masters with (6)+ years of prior relevant experience. Additional years of experience with requisite certifications will be considered in leu of degree. * Minimum of 4 years demonstrated knowledge of the intelligence cycle, analytic techniques, systems, processes, and organizations. * Minimum of 4 years demonstrated knowledge of Threat Assessment & Mitigation Strategies. * Have excellent written and verbal skills with ability to deliver briefings to a diverse group of audiences. * Possess knowledge of current domestic and international threats to U.S. national security interests. * Be adept at establishing networks with relevant security, personnel, and prevention stakeholders to foster program utilization. * Be a self-starter capable of working independently to promote program goals. * Working knowledge of User Activity Monitoring Software (UAM) and solutions. * Working knowledge of Cybersecurity toolsets designed to support ITP mission activities. * Working Knowledge of Open-Source toolsets. * Working Knowledge of Insider Threat Frameworks; Pathway to Violence & Critical Pathway. * Current TS/SCI and Must be a US Citizen. * Ability to obtain Agency EOD SCI and willingness to undergo CI Polygraph., * Master's degree from an accredited college or university in Criminal Justice, Homeland security, Cyber Security, or related field * Proven experience (10+ years) in Intelligence Analysis * Experience with User Activity Monitoring products and platforms * Proven experience (4+ years) in Threat Assessment & Mitigation * Certified Counter-Insider Threat Professional - Fundamentals (CCITP-F) * Certified Counter-Insider Threat Professional - Analysis (CCITP-A) * Completion of Center for Development of Security Excellence (CDSE) Insider Threat Detection Analysis Course (ITDAC) * Completion of Workplace Assessment of Violence Risk (WAVR-21) Workshop * Completion of Center for Development of Security Excellence (CDSE) Curriculums; INT311.CU/INT312.CU/CI201.CU ADDITIONAL INFORMATION: CLEARANCE REQUIREMENT: Must possess an active DoD Top Secret Clearance. In addition, selected candidate must undergo background investigation (BI) and finger printing by the federal agency and successfully pass the preceding to qualify for the position. US CITIZENSHIP IS REQUIRED. ## Description Critical Solutions is seeking an Insider Threat Program Hunt Team Analyst to support our federal customer., * Examine, analyze, and search insider threat data to identify trends, patterns, and insights of potential insider threat indicators. * Provide analytical, program support services related to the operation of UAM/ UEBA tool. * Monitor UAM platform to identify emerging requirements related to insider threat events and coordinate across the enterprise to ensure timely response. * Conduct further research on the UAM platform to identify patterns of concerning behavior related to a potential insider threat risk to the Agency enterprise. * Provide proactive insider threat-based hunting across the Agency enterprise network, leveraging methodologies and behavioral analytics to detect, investigate, and mitigate anomalous activity and policy violations indicative of malicious insider behavior. * Conduct continuous hunt operations across data and log sources, Agency platforms, EDR tools, and network traffic to identify patterns of insider threat behavior. * Identify mitigation strategies to assist the investigative team in effectively reducing insider threat risk. * Utilize UEBA (User and Entity Behavior Analytics) platforms and techniques to baseline user activity and detect deviations. * Provide timely response to critical/high UAM alerts (within 4 hours during normal business hours). ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Data Science in Retail](https://www.wearedevelopers.com/videos/586-data-science-in-retail) - [Distributed search under the hood](https://www.wearedevelopers.com/videos/256-distributed-search-under-the-hood) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Forecasting Cyber Attacks with Glassdoor Reviews - Lianne Potter](https://www.wearedevelopers.com/videos/2143-forecasting-cyber-attacks-with-glassdoor-reviews-lianne-potter) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer) - [Dev Digest 166: Sycophancy, Zip bombs and AI Native Development](https://www.wearedevelopers.com/magazine/585-dev-digest-166-sycophancy-zip-bombs-and-ai-native-development) - [Top 6 Hackathons for Developers in 2023](https://www.wearedevelopers.com/magazine/263-top-6-hackathons-for-developers-in-2023)