Logo
Leidos

Insider Threat Program Hunt Team Analyst

Leidos, Springfield, Virginia, us, 22161

Save Job

Overview

The Digital Modernization Sector at Leidos currently has an opening for a Hunt Analyst supporting the HEITS Contract as part of the Department of Homeland Security (DHS) Insider Threat Program (ITP). This is an exciting opportunity to use your experience to support, sustain, design and evolve the database backbone of the ITP. The ITP mission is to identify insider threats to the department by utilizing advanced analytics, monitoring, and data correlation which in turn help address and eliminate potential threat actors from compromising the DHS mission in safeguarding the homeland. Responsibilities

Review, analyze, and search insider threat data to identify trends, patterns, and insights of potential insider threat indicators. Provide analytical, program support services related to the operation of UAM/ UEBA tool. Monitor UAM platform to identify emerging requirements related to insider threat events and coordinate across the enterprise to ensure timely response. Conduct further research on the UAM platform to identify patterns of concerning behavior related to a potential insider threat risk to the DHS enterprise. Provide proactive insider threat-based hunting across the DHS enterprise network, leveraging methodologies and behavioral analytics to detect, investigate, and mitigate anomalous activity and policy violations indicative of malicious insider behavior. Conduct continuous hunt operations across data and log sources, DHS platforms, EDR tools, and network traffic to identify patterns of insider threat behavior. Identify mitigation measures to effectively reduce insider threat risk. Utilize UEBA (User and Entity Behavior Analytics) platforms and techniques to baseline user activity and detect deviations. Provide immediate response to insider threat related events (within 2 hours during normal business hours and provide after-hour support). Normal business hours defined as 6am to 10pm Monday – Friday excluding weekends and scheduled holidays. This position is expected to eventually move to shift work to meet the requirement of 24x7 operations at an undetermined later date. Basic Qualifications

Bachelors degree and 8+ years of prior relevant insider threat experience or Masters with 6+ years of prior relevant experience. Additional years of experience with requisite certifications will be considered in lieu of degree. Minimum of 4 years demonstrated knowledge of the intelligence cycle, processes, and organizations. Minimum 4 years demonstrated knowledge of various research tools and procedures and methods of analyzing, compiling, reporting and disseminating intelligence data and information. Minimum of 4 years demonstrated knowledge of research and analytical techniques as applied to difficult and complex assignments in security, law enforcement, and counterintelligence analysis. Minimum of 4 years demonstrated knowledge of Threat Assessment & Mitigation. Must possess a strong analytical background. Must have excellent written and verbal skills with ability to deliver briefings to a diverse group of audiences. Must possess the ability to plan, coordinate, research and analyze all-source intelligence information for accuracy, timeliness, and relevance to mission. Must possess knowledge of current domestic and international threats to U.S. national security interests. Must be adept at establishing networks with relevant security, personnel, and prevention stakeholders to foster program utilization. Must be a self-starter capable of working independently to promote program goals. Advanced knowledge of User Activity Monitoring Software (UAM) and solutions. Advanced knowledge of Cybersecurity toolsets designed to support ITP mission activities. Advanced Knowledge of Open-Source toolsets. Working Knowledge of Insider Threat Frameworks; Pathway to Violence & Critical Pathway. Current TS/SCI and Must be a US Citizen. Ability to obtain DHS EOD SCI and willingness to undergo CI Polygraph. Preferred Qualifications

Master’s degree from an accredited college or university in Criminal Justice, Homeland security, Cyber Security, or related field Proven experience (10+ years) in Intelligence Analysis Experience with User Activity Monitoring products and platforms Proven experience (4+ years) in Threat Assessment & Mitigation Certified Counter-Insider Threat Professional - Fundamentals (CCITP-F) Certified Counter-Insider Threat Professional - Analysis (CCITP-A) Completion of Center for Development of Security Excellence (CDSE) Insider Threat Detection Analysis Course (ITDAC) Completion of Workplace Assessment of Violence Risk (WAVR-21) Workshop Completion of Center for Development of Security Excellence (CDSE) Curriculums; INT311.CU/INT312.CU/CI201.CU Note: This version removes extraneous marketing copy and duplicates and presents a focused, job-focused description with proper HTML structure and only allowed tags.

#J-18808-Ljbffr