Insider Threat Analyst

Agile Defense
Washington
Workplace: HybridFull timeUSD 110,000 - 135,000 annuallyFunction: Administration & Executive AssistanceEducation: bachelorsSkills: ["Written communication","Analytical thinking","Investigative mindset","Attention to privacy","Stakeholder coordination"]

Support the Insider Threat Program Detection and Prevention effort by performing day-to-day detection, analysis, and triage of potential insider threat activity. Monitor alerts from multiple enterprise applications, distinguish true incidents from false positives, and document findings in accordance with established procedures. Help configure and troubleshoot detection triggers, operate enterprise detection tools, correlate signals across sources, and support workflows, playbooks, and stakeholder coordination—while protecting employee privacy and civil liberties.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Agile Defense
Agile Defense
2 months ago

Insider Threat Analyst

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 5 hours agoStatus: Live

Job Summary

Support the Insider Threat Program Detection and Prevention effort by performing day-to-day detection, analysis, and triage of potential insider threat activity. Monitor alerts from multiple enterprise applications, distinguish true incidents from false positives, and document findings in accordance with established procedures. Help configure and troubleshoot detection triggers, operate enterprise detection tools, correlate signals across sources, and support workflows, playbooks, and stakeholder coordination—while protecting employee privacy and civil liberties.
Location: Washington
Workplace: Hybrid
Employment Type: Full time
Job Function: Administration & Executive Assistance
Seniority: Mid level

Key Responsibilities

  • •Monitor and analyze logs and alerts from multiple applications to determine insider threat incidents vs. false positives.
  • •Triage and investigate insider threat indicators, escalating confirmed or ambiguous cases to the Senior Insider Threat Analyst.
  • •Support configuration, tuning, and troubleshooting of application triggers for insider threat detection.
  • •Assist with deployment, operation, and maintenance of enterprise tools supporting insider threat detection.
  • •Document findings, produce analytical write-ups, maintain case records, correlate data across sources, and support workflows/playbooks while protecting privacy and civil liberties.

Pay and Benefits

Salary: USD 110,000 - 135,000 annually

Key Requirements

  • •U.S. citizenship and ability to receive and maintain a Tier 5+ security clearance (Top Secret).
  • •BS or BA degree, or additional related experience in lieu of a degree.
  • •Approximately 6 years of combined experience across cybersecurity, security operations, investigations, or insider threat analysis.
  • •Hands-on experience with enterprise insider threat, DLP, SIEM, or UEBA/UAM tools (e.g., Splunk, DTEX, Proofpoint/ObserveIT, Microsoft Purview, Exabeam).
  • •Working knowledge of Windows, Unix, and Linux environments; ability to analyze logs/dashboards to differentiate true incidents from false positives.
Experience:CybersecuritySecurity operationsInvestigationsInsider threat analysis
Education:Bachelor's
Skills:Written communicationAnalytical thinkingInvestigative mindsetAttention to privacyStakeholder coordination
Certifications:Counter-Insider Threat Fundamentals Certification
Tech Stack:Insider threat programDLPSIEMUEBAUAMSplunkDTEXProofpointObserveITMicrosoft PurviewExabeamDashboardsWindowsUnixLinuxLog analysisEvent correlationDigital forensics

Eligibility

Security Clearance:Top Secret

Company Brief

Agile Defense
Provides cybersecurity services including managed detection and response, incident response, vulnerability assessments, and security operations to help organizations detect, respond to, and remediate cyber threats while meeting regulatory and compliance requirements.
Industry: Cybersecurity
Website