Insider Threat Analyst Lead
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Insider Threat Analyst Lead (Cybersecurity): Leading the operationalization of the AOUSC Insider Threat Program, developing governance frameworks, and collaborating with various teams to support enterprise-wide insider risk management efforts with an accent on identifying, analyzing, and mitigating insider threat risks. Focus on refining alerting logic, improving visibility, and reducing false positives within existing alerting frameworks.
Location: Hybrid, onsite in Washington, DC
Company
seeks a Insider Threat Analyst Lead to join their program supporting the Administrative Office of the United States Courts (AOUSC).
What you will do
- Lead and support the operationalization of the AOUSC Insider Threat Program.
- Develop and maintain Insider Threat governance frameworks and operational procedures.
- Collaborate with various teams to support enterprise-wide insider risk management efforts.
- Design, document, and operationalize insider threat use cases and indicators for integration into the SIEM and detection engineering framework.
- Analyze telemetry, user activity, and security events to identify potential insider threat activity and emerging organizational risks.
- Develop insider threat awareness materials, workforce training, and executive briefings.
Requirements
- Active Public Trust clearance
- B.S. in Computer Science, Information Technology, or a related field.
- 5+ years’ experience in conducting in-depth technical analysis of insider threat.
- 3+ years’ experience in conducting behavioral analytics.
- 2+ years of experience using Splunk SIEM to correlate cybersecurity alerts.
- 2+ years of experience managing overall case management for cybersecurity investigations.
- Active CCITP Program certification
Culture & Benefits
- Participate in weekly technical meetings and monthly program management reviews with AO stakeholders and leadership.
- Support Agile workflows and track operational tasks, action items, and improvements through Jira and ServiceNow platforms.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →