×
Register Here to Apply for Jobs or Post Jobs. X

Insider Threat Analyst

Job in Huntsville, Madison County, Alabama, 35898, USA
Listing for: DEFTEC Corporation
Full Time position
Listed on 2026-08-18
Job specializations:
  • IT/Tech
    Data Analyst, Information Security & Data Protection, Cybersecurity
Job Description & How to Apply Below

Insider Threat Analyst

The Federal Bureau of Investigation (FBI) is charged with protecting and defending the United States against terrorist and foreign intelligence threats, enforcing the criminal laws of the United States, and providing leadership and criminal justice services to federal, state, municipal, and international partners. In 2011, Executive Order 13587 directed all agencies operating or accessing classified computer networks to safeguard classified information and establish insider threat detection programs.

The FBI's Insider Threat Office (InTO) serves as the central coordinating component for all insider threat issues, with a mission to detect, deter, and mitigate risks originating from within the organization. This position provides critical analytical support to InTO by conducting research, analysis, and reporting that directly contribute to safeguarding FBI personnel, systems, and information from insider risks.

Job Responsibilities:

  • Research, fuse, and analyze large, disparate datasets to identify insider-threat trends/indicators and assess COAs, using SQL/Python for large-set manipulation and automation, and producing decision-quality visuals in Power BI/Tableau and Excel (macros/VBA).
  • Conduct insider-threat monitoring across UAM/DLP/UBA/SIEM; triage alerts and perform log analysis in Splunk and Microsoft Sentinel; develop repeatable detections leveraging KQL/SPL and automation in Python/Excel VBA.
  • Build and tune data pipelines, queries, and automations aligned to InTO SOPs with minimal re-work (SQL/Python, Splunk saved searches/alerts, Sentinel analytics rules, Power BI dataflows).
  • Utilize Microsoft Purview, Defender, and Sentinel;
    Azure services; and tools such as Everfox, Digital Guardian, and Forcepoint to detect, investigate, and respond to data-loss and misuse events.
  • Access classified and open-source systems; collect, organize, and format data per InTO SOPs; manage secure processing/transmittal/storage while applying configuration and privilege management best practices.
  • Compare and fuse multi-source reporting (FBI HQ, field offices, partner agencies) to find correlations, discrepancies, and gaps; generate and triage leads/alerts using Splunk dashboards, Sentinel workbooks, and Power BI.
  • Develop and prototype analytics (queries, programs, algorithms) for large-scale analysis using SQL/Python and Azure; perform statistical analysis/data exploration and optimize datasets for strategic program support.
  • Produce clear, concise analytic products, reports, briefs, charts, tables, and graphs, in Power BI/Tableau/Excel; present findings and recommendations to stakeholders.
  • Perform DLP functions and insider-risk investigations using Purview/Defender, Digital Guardian, Forcepoint, and Splunk/Sentinel; identify inappropriate/unauthorized activity, associations, or communications.
  • Provide technical/operational support for data and case requests; create Splunk searches, Sentinel queries, and Excel/Power BI views to accelerate discovery and response.
  • Execute QC of analytic processes/products (query validation, dashboard accuracy, SOP compliance) across Splunk/Sentinel/Power BI; prioritize multiple projects effectively.
  • (ITMU role) Mentor/QA less-senior analysts; set detection standards; lead prototype analytics; and mature enterprise use of the Microsoft security stack (Purview/Defender/Sentinel/Azure), Splunk, Power BI, and automation with SQL/Python/Excel VBA.

Required Qualifications:

  • Active TS/SCI clearance.
  • Education/

    Experience:

    Bachelor's degree; or an additional 4 years of directly related experience (totaling 8+ years) in lieu of a degree.
  • Experience:

    Minimum 4 years performing administrative, analytical, and research functions in national-security or operational-security environments.
  • Productivity & Tools:
    Proficiency with Microsoft Office (Outlook, Word, PowerPoint, Excel) and Google Chrome; ability to navigate multiple browser windows/tabs, and copy/paste across applications.
  • Communication:
    Excellent interpersonal skills; proven ability to brief and collaborate with diverse stakeholders.
  • Analytic Communication:
    Demonstrated skill in oral presentations and in writing reports that explain methods and results of mathematical/quantitative analysis to non-technical audiences.

Preferred Qualifications:

  • Data & Scripting:
    Strong SQL and Python for large-dataset manipulation, automation, and ETL; working knowledge of KQL (Microsoft Sentinel/Log Analytics) and SPL (Splunk).
  • SIEM & Logging:
    Splunk hands-on (data onboarding/normalization, dashboards, alerts; ES/CIM mappings).
  • Microsoft Security Stack:
    Microsoft Sentinel (analytic rules, workbooks, UEBA, automation/Logic Apps), Microsoft Defender (Endpoint/Identity/Email), and Microsoft Purview (DLP policies, sensitivity labels, insider-risk controls).
  • Cloud & Telemetry:
    Azure familiarity (Log Analytics/Kusto, Azure Monitor, Data Explorer; basic Data Factory/orchestration) supporting pipelines and playbooks.
  • DLP/Insider Risk:
    Experience with Digital Guardian, Forcepoint,…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary