Specialized Security Source Analyst; Insider Threat
Job in
Quantico, Prince William County, Virginia, 22134, USA
Listed on 2026-09-06
Listing for:
Clearance Jobs
Full Time
position Listed on 2026-09-06
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below
Job Title
Join our team at Core One! Our mission is to be at the forefront of devising analytical, operational and technical solutions to our Nation's most complex national security challenges. In order to achieve our mission, Core One values people first! We are committed to recruiting, nurturing, and retaining top talent! We offer a competitive total compensation package that sets us apart from our competition.
Core One is a team-oriented, dynamic, and growing company that values exceptional performance!
This position requires TS/SCI Clearance Responsibilities:
- The Contractor shall provide all source analytic support to the DCSA InT program.
- The Contractor shall provide Insider Threat support services.
- Aggregate, analyze, and evaluate all available InT government and open-source information to assist in the evaluation of potential risk as it relates to InT.
- Extract and organize statistical data to support the building of both quantitative and qualitative metrics products, summaries, case studies and trend products.
- Communicate complex ideas and analyses orally and in writing.
- Plan and conduct thorough research using all available InT tools and data sources to discover the information necessary to support analysis, either independently or as part of a larger analytical effort.
- Assist in the preparation and production of risk warning and situational awareness products related to InT issues.
- Assist in the preparation and production of analytical products and identifying areas for efficiencies in the production process.
- Provide editing and quality control of InT products communicating recommendations orally and in writing.
- Review InT information in support of meeting InT mission requirements and timelines.
- Propose and define new UAM policy triggers.
- Perform functional testing of proposed and modified policy triggers prior to implementation and final government approval.
- Prepare policy trigger implementation plan and impact assessment.
- Review and escalate as appropriate events triggered in the UAM tool.
- Perform configuration management activities to ensure compliance with asset management and continuous monitoring policy requirements.
- Understand and implement established policy technical and workflow procedures.
- Prepare, write, and present reports and briefings as required.
- Support analytic and operational activities to assemble, correlate, evaluate, and assess information concerning counterintelligence, security, human capital, and information assurance related insider threats against DCSA personnel, programs, information systems, and/or facilities.
- Apply knowledge of CNE tactics, techniques, and procedures associated with advanced cyber threats to develop analytical signatures and filters to refine anomaly detection with the Insider Threat Program datastore/database that are internal to the organization.
- Perform event analysis by examining network traffic data and Host Based Security Systems' audit data, SIEM data, and any other technical feeds received from Agency security tools.
- Analyze and disseminate insider threat analysis information as required, and perform insider threat analysis, forecasts, and threat alerts with recommended countermeasures to include new policy trigger protocols or tuning of existing policies.
- Prepare formal analysis products and reports with findings and recommendations.
- Make policy trigger recommendations to the government to enhance current capabilities and tune current policy triggers.
- Focus not only on anomalous network activity but also captures human behaviors such as policy violations, compliance incidents, and malicious acts at the endpoint that can service as warning signs leading up to a breach.
- Effectively detect both unauthorized access to information and unauthorized transfer of information and could be deployed for audits and inquiries across multiple network architectures using a wide variety of security concepts of operations that range from standalone, single-service systems in a two-person investigation office to large-scale clusters on a distributed enterprise with multiple stakeholders doing auditing and investigations.
- Process personnel to verify the…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×