User and Entity Behavior Analytics Engineer
Listed on 2026-09-21
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Data Analyst, Security Management & Operations
Join a culture of empowerment and connectivity.
Develop your craftLearn the skills you need to accelerate your career.
Discover benefits that support your life and work.
Innovate with intentionBuild mission-ready tech that protects the nation.
User and Entity Behavior Analytics EngineerThe Opportunity:
As an Enterprise Cybersecurity User and Entity Behavior Analytics (UEBA) Engineer , you will help strengthen Booz Allen's identity, security, and insider risk programs by improving visibility into user and entity behavior. Your work will support the detection, investigation, and response to anomalous activity, account compromise, insider risk, and other cybersecurity threats. By developing actionable behavioral analytics and risk indicators, you will help enable effective threat detection and coordinated response across the enterprise.
In this role, you will analyze user, device, application, network, cloud, and security telemetry to identify deviations from expected behavior and uncover indicators of compromise, insider risk, account compromise, and other cyber threats. You will collaborate closely with cyber operators, threat analysts, incident responders, data scientists, and AI engineers to develop and operationalize behavioral analytics that support real-time situational awareness, automated triage, and semi-autonomous cybersecurity workflows across the enterprise.
Due to the nature of work performed within this facility, U.S. citizenship is required.
Develop, tune, and maintain UEBA detections, behavioral baselines, anomaly detection rules, and risk-based analytics across users, devices, applications, and cloud entities
Deploy, configure, and maintain UEBA software
Partner with cyber operators, threat analysts, incident responders, and security stakeholders to define requirements, validate detections, and integrate UEBA analytics into SOC workflows
Develop dashboards, reports, and risk indicators that communicate behavioral trends, high-risk activity, and investigation findings to technical and executive audiences
Continuously assess and improve detection logic by evaluating alert quality, reducing false positives, and incorporating analyst feedback and lessons learned from security incidents
Join us. The world can’t wait.
You Have:3+ years of experience in cybersecurity analytics, security operations, threat detection, threat hunting, insider risk, or user and entity behavior analytics
1+ years of experience with a UEBA tool, including Ever Fox , Crowd Strike, or Splunk
Experience developing, tuning, and operationalizing behavioral analytics, anomaly detection rules, risk scores, or correlation logic
Experience using SIEM, UEBA, EDR, identity, or cybersecurity platforms
Ability to document analytical methods, investigation findings, detection logic, and recommended actions clearly and accurately
Ability to work independently and collaboratively in a team environment
Ability to be self-motivated, pay close attention to detail, and manage multiple priorities
Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or Data Analytics or 5+ years of experience in cybersecurity, information technology, or analytics in lieu of a degree
Experience supporting insider threat, data loss prevention, fraud detection, account takeover, or privileged-user monitoring programs
Knowledge of cybersecurity domain
Possession of strong analytical, problem-solving, and critical thinking skills
Possession of strong written and verbal communication skills, including presenting complex information in a clear and concise manner
At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).