Insider Threat Monitoring Analyst
Listed on 2026-07-18
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Network Security
Description
The Department of Homeland Security (DHS), Customs and Border Protection (CBP) Cyber Security Directorate (CSD) Security Operations Center (SOC) is a U.S. Government program responsible for preventing, identifying, containing, and eradicating cyber threats to CBP networks through monitoring, intrusion detection, and protective security services to CBP information systems including LAN/WAN, commercial Internet connection, public-facing websites, wireless, mobile/cellular, cloud, security devices, servers, and workstations.
The CBPSOC is responsible for the overall security of CBP Enterprise-wide information systems, collecting, investigating, and reporting any suspected and confirmed security violations. Leidos is seeking an experienced Insider Threat Expert to join our team. As a member of this highly technical digital forensics team supporting U.S. Customs and Border Protection (CBP), you will lead user activity monitoring, foreign service national monitoring, insider threat analysis, and investigate policy violations, data loss prevention (DLP) events, and sensitive data spillages.
Responsibilities
- Supporting the Cyber Defense Forensics and Insider Threat investigations using near real-time monitoring of DLP tools for potential data exfiltration attempts of CBP mission data or employee PII/SPII.
- Supporting Office of Professional Responsibility (OPR), Office of Intelligence (OI), Office of the Inspector General (OIG) and other Government Agencies in the investigation of CBP personnel operating with potentially malicious or alleged criminal intent.
- Actively monitoring Foreign Service National (FSN) network activity for misuse and policy violations.
- Supporting User Activity Monitoring (UAM) activities.
- Making recommendations for insider threat alert triggers and detections across various security tools and logging sources.
- Monitoring CBP laptops and mobile devices traveling OCONUS for suspicious activity and policy violations.
- Providing investigative support for CBP's OPR-Cyber Investigations for media leak investigations by identifying all users who have received/sent, printed, copied, downloaded/uploaded, or accessed the leaked document.
- Providing recommendations for Information Spillage Incident Response efforts on handling and sanitization methods pursuant to industry best practices, NIST 800-88 recommendations, and Federal guidelines.
- Requires BS degree and a minimum of 8 or more years of direct relevant experience.
- Requires an active and current CISSP certification.
- Degree in computer science, IT, Information/Cyber Security field from an accredited college or university.
- Additional experience or applicable certifications acceptable in lieu of degree.
- Working knowledge of defense-in-depth principles, network/HW/SW security architecture, network topology, IT device integrity, and common security elements.
- Effective communication skills with emphasis on attention to detail, ability to accurately capture and document technical remediation details, and ability to brief stakeholders on incident statuses, recovery and root causes.
- Demonstrable experience performing forensic analysis, digital media analysis, and in-depth system & network log analysis in support of forensic investigations.
- Ability to generate forensically sound cyber analysis reports detailing forensic procedures, findings, and recommendations from incident investigations.
- Strong problem-solving abilities with an analytic and qualitative eye for reasoning under pressure.
- Experience with User Activity Monitoring products and platforms.
- Experience with Endpoint Detection and Response (EDR) tools.
- Must be able to report to the Ashburn VA office up to 5 days per week.
- Must be a U.S. citizen.
- Must have a Top Secret clearance.
- Must be able to obtain and maintain a CBP BI clearance.
Master's degree from an accredited college or university in IT Management, Engineering, or related field.
- SANS GREM certification.
- Previous experience contributing to or leading insider threat investigations in support of Federal Government, DOD, or Law Enforcement environments.
- Experience performing computer forensics in Federal Government, DOD or Law Enforcement environments.
Pay Range: $ - $. The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.
Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available at
All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).