· Monitor and analyze logs and alerts from multiple applications via dashboards and other means to determine whether activity represents an actual insider threat incident or a false positive.
· Triage and investigate potential insider threat indicators, escalating confirmed or ambiguous incidents to the Senior Insider Threat Analyst as appropriate.
· Support the configuration, tuning, and troubleshooting of application triggers used for insider threat detection in an enterprise environment.
· Assist with the deployment, operation, and maintenance of enterprise tools supporting insider threat detection.
· Document findings, produce clear analytical write-ups, and maintain case records in accordance with established reporting procedures.
· Correlate data across multiple sources to build a complete picture of potential insider threat activity.
· Support the development and refinement of workflows, playbooks, and program documentation.
· Conduct all activities in a manner that protects employee privacy and civil liberties and meets the legal requirements of an insider threat program.
· Coordinate with SOC, investigative, and other stakeholders as directed to support program objectives.
· U.S. citizenship and ability to receive and maintain a security clearance at the Tier 5 level or higher.
· BS or BA degree, or additional related experience in lieu of a degree.
· Approximately 6 years of combined experience across cybersecurity, security operations, investigations, or insider threat analysis.
· Hands-on experience with one or more enterprise insider threat, DLP, SIEM, or UEBA/UAM tools (e.g., Splunk, DTEX, Proofpoint/ObserveIT, Microsoft Purview, Exabeam, or similar).
· Demonstrated ability to analyze logs and dashboards to differentiate real incidents from false positives.
· Working knowledge of Windows, Unix, and Linux environments and common insider threat indicators and behaviors.
· Familiarity with log analysis, event correlation, and basic investigative techniques, including awareness of digital forensics concepts.
· Understanding of the legal and ethical requirements of an insider threat program as they relate to privacy and civil liberties.
· Strong written communication for documenting findings, and the ability to work under the direction of senior analysts within an established program.
· Ability to obtain the Counter-Insider Threat Fundamentals Certification if required.

Agile Defense: Always Evolving
Agile Defense stands at the forefront of innovation, driving advanced capabilities and solutions tailored to the most critical national security and civilian missions. With operations in North America, Europe, Asia, and the Middle East, Agile Defense supports our customer missions around the globe. Whether developing specialized solutions, contextualizing data, or strengthening cybersecurity, our expertise is instrumental in safeguarding our nation's sensitive assets.
Advanced National Security and Civilian Capabilities
Digital Transformation
Applying advanced services, capabilities, and solutions securely to enhance mission operations and achieve optimal outcomes.
Data Analytics
Leveraging a data-driven approach, we deliver data insights that provide clarity to accelerate the decision-making process.
Cyber
Delivering Cyber Systems and Cyber Operations capabilities to defend against advanced and emerging cyber threats with certainty.