×
Register Here to Apply for Jobs or Post Jobs. X

Insider Threat Program UAM Team Analyst

Job in Springfield, Fairfax County, Virginia, 22161, USA
Listing for: Leidos Inc
Full Time position
Listed on 2025-12-25
Job specializations:
  • IT/Tech
    Cybersecurity, Data Security, Security Manager
Job Description & How to Apply Below
Position: Insider Threat Program UAM Hunt Team Analyst

Description

The Digital Modernization Sector at Leidos currently has an opening for a Hunt Analyst supporting the HEITS Contract as part of the Department of Homeland Security (DHS) Insider Threat Program (ITP). This is an exciting opportunity to use your experience to support, sustain, design and evolve the database backbone of the ITP. The ITP mission is to identify insider threats to the department by utilizing advanced analytics, monitoring, and data correlation which in turn help address and eliminate potential threat actors from compromising the DHS mission in safeguarding the homeland.

Responsibilities
  • Examine, analyze, and search insider threat data to identify trends, patterns, and insights of potential insider threat indicators.
  • Provide analytical, program support services related to the operation of UAM/ UEBA tool.
  • Monitor UAM platform to identify emerging requirements related to insider threat events and coordinate across the enterprise to ensure timely response.
  • Conduct further research on the UAM platform to identify patterns of concerning behavior related to a potential insider threat risk to the DHS enterprise.
  • Provide proactive insider threat-based hunting across the DHS enterprise network, leveraging methodologies and behavioral analytics to detect, investigate, and mitigate anomalous activity and policy violations indicative of malicious insider behavior.
  • Conduct continuous hunt operations across data and log sources, DHS platforms, EDR tools, and network traffic to identify patterns of insider threat behavior.
  • Identify mitigation strategies to assist the investigative team in effectively reducing insider threat risk.
  • Utilize UEBA (User and Entity Behavior Analytics) platforms and techniques to baseline user activity and detect deviations. Provide timely response to critical/high UAM alerts (within 4 hours during normal business hours).
Basic Qualifications
  • Bachelors degree and (15)+ years of prior relevant insider threat experience or Masters with (13)+ years of prior relevant experience. Additional years of experience with requisite certifications will be considered in lieu of degree.
  • Minimum of 4 years demonstrated knowledge of the intelligence cycle, analytic techniques, systems, processes, and organizations.
  • Minimum of 4 years demonstrated knowledge of Threat Assessment & Mitigation Strategies.
  • Have excellent written and verbal skills with ability to deliver briefings to a diverse group of audiences.
  • Possess knowledge of current domestic and international threats to U.S. national security interests.
  • Be adept at establishing networks with relevant security, personnel, and prevention stakeholders to foster program utilization.
  • Be a self-starter capable of working independently to promote program goals.
  • Working knowledge of User Activity Monitoring Software (UAM) and solutions.
  • Working knowledge of Cybersecurity toolsets designed to support ITP mission activities.
  • Working Knowledge of Open-Source toolsets.
  • Working Knowledge of Insider Threat Frameworks;
    Pathway to Violence & Critical Pathway.
  • Current TS/SCI and Must be a US Citizen.
  • Ability to obtain DHS EOD SCI and willingness to undergo CI Polygraph.
Preferred Qualifications
  • Master's degree from an accredited college or university in Criminal Justice, Homeland security, Cyber Security, or related field
  • Proven experience (10+ years) in Intelligence Analysis
  • Experience with User Activity Monitoring products and platforms
  • Proven experience (4+ years) in Threat Assessment & Mitigation
  • Certified Counter-Insider Threat Professional - Fundamentals (CCITP-F)
  • Certified Counter-Insider Threat Professional - Analysis (CCITP-A)
  • Completion of Center for Development of Security Excellence (CDSE) Insider Threat Detection Analysis Course (ITDAC)
  • Completion of Workplace Assessment of Violence Risk (WAVR-21) Workshop
  • Completion of Center for Development of Security Excellence (CDSE) Curriculums; INT
    311.CU/INT
    312.CU/CI201.CU

Come break things (in a good way). Then build them smarter.

We're the tech company everyone calls when things get weird. We don't wear capes (they're a safety hazard), but we do solve high-stakes problems with code, caffeine, and a healthy…

To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)

Job Posting Language
Employment Category
Education (minimum level)
Filters
Education Level
Experience Level (years)
Posted in last:
Salary