Insider Threat Analyst
Listed on 2025-12-18
-
IT/Tech
Cybersecurity, Security Manager, Data Security, Information Security
Saronic Technologies is a leader in revolutionizing autonomy at sea, dedicated to developing state-of-the-art solutions that enhance maritime operations through autonomous and intelligent platforms.
Job SummaryThe Insider Threat Analyst will help build and operate Saronic’s emerging Insider Threat Program under the direction of the Senior Insider Threat Analyst. You will support the detection, assessment, and mitigation of risks that originate from within the organization, whether cyber, physical, or personnel-related. This role focuses on behavioral indicators, adherence to security standards, and early identification of concerning patterns across both technical and non-technical data sources.
Working closely with Cybersecurity, Physical Security, HR/People, Legal/Compliance, and other internal stakeholders, you will help protect our people, data, and intellectual property while promoting a culture of security awareness and trust. This is a mid-career, hands‑on role that emphasizes structured analysis, consistent documentation, and disciplined execution of established playbooks. The position requires an active TS/SCI clearance, or the ability to obtain one, and will frequently involve work in classified environments, including SCIFs, in alignment with NISPOM (32 CFR Part 117) and the 13 adjudicative guidelines.
Responsibilities- Detection & Response
- Monitor employee and user activity across approved tools (e.g., access logs, case management systems, incident tickets) to identify potential insider risks or policy violations.
- Triage alerts and escalations from insider threat detections, HR referrals, and physical security incidents, escalating to senior analysts when warranted.
- Support containment and remediation activities during insider threat incidents by following established playbooks and direction from senior analysts or the Insider Threat Program lead.
- Investigation & Behavioral Analysis
- Identify, collect, and analyze data from multiple sources (HR/People data, security tools, access and badge logs, incident reports, and open‑source/internal information) to validate suspicious behaviors and develop an initial risk picture.
- Incorporate the 13 adjudicative guidelines and relevant USG standards into basic behavioral assessments, focusing on indicators such as financial distress, foreign influence, substance misuse, or unexplained changes in behavior.
- Ensure investigation details, evidence, and analytic findings are accurately documented in the case management system, including timelines, rationale for decisions, and recommended next steps.
- Contribute to metrics development by ensuring cases, indicators, and outcomes are recorded consistently for program reporting.
- Collaboration & Stakeholder Engagement
- Collaborate with Physical Security to review facility access controls, assess anomalous badge activity, and respond to in‑person security incidents involving personnel.
- Partner with HR/People on pre‑employment checks, continuous evaluation inputs, and employee support or counseling processes related to behavior‑based concerns.
- Coordinate with Cybersecurity, Legal/Compliance, and other internal teams to ensure investigations are handled lawfully, consistently, and in line with corporate policies and regulatory requirements.
- Participate in cross‑functional meetings to discuss personnel‑related risks and contribute to appropriate mitigation strategies (e.g., access restrictions, monitoring enhancements, referrals to HR).
- Process, Playbooks & Continuous Improvement
- Follow established insider threat playbooks and standard operating procedures for triage, investigation, and escalation.
- Provide feedback on playbooks, runbooks, and standard templates to help improve clarity, consistency, and analyst usability.
- Assist in maintaining and updating documentation for tools, workflows, and data sources used in insider threat investigations.
- Support the development, testing, and tuning of detections by providing case‑driven feedback to senior analysts, security engineers, or product owners.
- Training, Awareness & Reporting
- Assist in delivering security awareness sessions and briefings focused on behavioral indicators,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).