Insider Threat Data Specialist
Role details
Job location
Tech stack
Job description
Prudent Technology is seeking a Insider Threat Data Specialist , who will be responsible for identifying, analyzing, and mitigating insider threats through advanced security analytics, threat hunting, and cyber intelligence activities. The position supports enterprise security operations by leveraging data from multiple security platforms to detect anomalous behavior, investigate potential insider risks, and provide actionable intelligence to stakeholders. The analyst will serve as a subject matter expert on cyber adversary capabilities, insider threat indicators, and data-driven risk analysis., * Support updates to insider threat policies and procedures for the agency, interagency, or federal intelligence community-wide initiatives.
- Conduct proactive threat hunting activities across enterprise networks, endpoints, and cloud environments.
- Utilize Splunk Enterprise Security (ES) to develop dashboards, reports, alerts, correlation searches, and detection use cases.
- Leverage Trellix DLP, CrowdStrike Falcon, and Tanium to collect, analyze, and correlate security data.
- Investigate insider threat incidents involving unauthorized access, data exfiltration, misuse of privileges, and suspicious user activity.
- Develop methods and procedures to extract data from enterprise IT systems to identify high-risk activities and vulnerabilities.
- Collaborate with Security Operations Center (SOC), Incident Response (IR), Watch Desk/WDV, Threat Intelligence, and other IT teams to investigate and mitigate security events.
- Coordinate with cross-functional IT teams to collect and analyze data from multiple enterprise platforms supporting insider threat investigations.
- Participate in incident triage, response, containment, recovery, and remediation activities.
- Prepare analytical reports, executive summaries, dashboards, risk assessments, and technical briefings for leadership and stakeholders.
- Document investigative findings, threat assessments, and recommendations in accordance with organizational standards.
- Assess cyber adversary capabilities, intentions, and TTPs targeting U.S. government and private-sector networks.
- Participate in information-sharing activities, working groups, and meetings with federal cybersecurity partners.
Requirements
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Data Analytics, or related discipline.
- Minimum 5 years of experience in cybersecurity, insider threat analysis, security analytics, or threat intelligence.
- Minimum 5 years of hands-on experience with Splunk Enterprise Security (ES).
- Experience with Trellix DLP, CrowdStrike Falcon, and Tanium.
- Experience conducting threat hunting investigations and security event analysis.
- Experience supporting Federal Government contracts and working within federal agency environments.
- Experience collaborating with SOC, IR, Cyber Threat Intelligence, and enterprise IT teams.
- Experience preparing technical reports, investigative summaries, executive briefings, and risk assessments.
- Strong understanding of cyber threat intelligence and adversary TTPs.
- Strong analytical, problem-solving, and communication skills.
- Ability to obtain and maintain a Public Trust clearance; Active Public Trust or Secret clearance preferred.
Additional Requirements
- Experience supporting Insider Threat Programs within Federal Government or highly regulated environments.
- Knowledge of UBA, UAM, and Insider Risk Management methodologies.
- Familiarity with MITRE ATT&CK and Cyber Kill Chain frameworks.
- Experience developing SOPs, playbooks, policy updates, and process improvement recommendations.
- Experience developing security use cases, detection logic, and monitoring capabilities.
- Active Public Trust, Secret, or higher security clearance is highly desirable.
- Experience supporting SSA, DHS, DoD, Intelligence Community, or other Federal civilian agencies is preferred.
- Professional certifications such as CISSP, CISM, CEH, GCIH, GCFA, Security+, or Splunk ES certifications are preferred.
Benefits & conditions
Prudent Technology LLC is a Women Owned Small Business company providing innovative IT Automation and Data solutions to our federal clients. We are a team of self-starters, innovators and consultants providing cutting edge technologies for the federal government. We help our clients achieve their business and operational goals by solving complex problems through experience and intellect and build sustainable solutions that last. At , we value our employees and are committed to supporting their professional growth, well-being, and work-life balance. We offer a competitive benefits package that may include comprehensive medical, dental, and vision coverage, 401(k) retirement plans with company support, paid time off, paid holidays, training and certification opportunities, career advancement programs, and flexible work arrangements based on program needs. Our collaborative and employee-focused culture empowers team members to grow their careers while contributing to meaningful federal and commercial technology initiatives. Commitment to Non-Discrimination As an Equal Opportunity Employer, we consider all qualified applicants without regard to disability, protected veteran status, or any other status protected by law. We are committed to a fair and inclusive workplace where advancement is based on merit, skills, and contributions. If you feel that your qualifications, talents, and values align with our culture, we welcome you to apply by submitting your resume today! No Agencies Please