Insider Threat Program Hunt Team Analyst
2 weeks ago
Description
The Digital Modernization Sector at Leidos currently has an opening for a Hunt Analyst supporting the HEITS Contract as part of the Department of Homeland Security (DHS) Insider Threat Program (ITP). This is an exciting opportunity to use your experience to support, sustain, design and evolve the database backbone of the ITP. The ITP mission is to identify insider threats to the department by utilizing advanced analytics, monitoring, and data correlation which in turn help address and eliminate potential threat actors from compromising the DHS mission in safeguarding the homeland.
The selected candidate will be responsible for the following:
- Normal business hours will be defined as a schedule combination to include weekdays 2pm-10pm shift and weekends 6am-6pm shift. The candidate will have 2- 3 days off based on the schedule determined & the work week should not exceed 40 hours.
- This position is expected to eventually move to shift work to meet the requirement of 24x7 operations at an undetermined later date. Examine, analyze, and search insider threat data to identify trends, patterns, and insights of potential insider threat indicators.
- Provide analytical, program support services related to the operation of UAM/ UEBA tool.
- Monitor UAM platform to identify emerging requirements related to insider threat events and coordinate across the enterprise to ensure timely response.
- Conduct further research on the UAM platform to identify patterns of concerning behavior related to a potential insider threat risk to the DHS enterprise.
- Provide proactive insider threat-based hunting across the DHS enterprise network, leveraging methodologies and behavioral analytics to detect, investigate, and mitigate anomalous activity and policy violations indicative of malicious insider behavior.
- Conduct continuous hunt operations across data and log sources, DHS platforms, EDR tools, and network traffic to identify patterns of insider threat behavior.
- Identify mitigation strategies to assist the investigative team in effectively reducing insider threat risk.
- Utilize UEBA (User and Entity Behavior Analytics) platforms and techniques to baseline user activity and detect deviations.
- Provide timely response to critical/high UAM alerts (within 4 hours during normal business hours).
Basic Qualifications:
- Bachelors degree and (12)+ years of prior relevant insider threat experience or Masters with (10)+ years of prior relevant experience. Additional years of experience with requisite certifications will be considered in leu of degree.
- Minimum of 4 years demonstrated knowledge of the intelligence cycle, analytic techniques, systems, processes, and organizations.
- Minimum of 4 years demonstrated knowledge of Threat Assessment & Mitigation Strategies.
- Have excellent written and verbal skills with ability to deliver briefings to a diverse group of audiences.
- Possess knowledge of current domestic and international threats to U.S. national security interests.
Be adept at establishing networks with relevant security, personnel, and prevention stakeholders to foster program utilization.
Be a self-starter capable of working independently to promote program goals.
- Working knowledge of User Activity Monitoring Software (UAM) and solutions.
- Working knowledge of Cybersecurity toolsets designed to support ITP mission activities.
- Working Knowledge of Open-Source toolsets.
- Working Knowledge of Insider Threat Frameworks; Pathway to Violence & Critical Pathway.
- Current TS/SCI and Must be a US Citizen.
- Ability to obtain DHS EOD SCI and willingness to undergo CI Polygraph.
Preferred Qualifications:
- Master's degree from an accredited college or university in Criminal Justice, Homeland security, Cyber Security, or related field
- Proven experience (10+ years) in Intelligence Analysis
- Experience with User Activity Monitoring products and platforms
- Proven experience (4+ years) in Threat Assessment & Mitigation
- Certified Counter-Insider Threat Professional - Fundamentals (CCITP-F)
- Certified Counter-Insider Threat Professional - Analysis (CCITP-A)
- Completion of Center for Development of Security Excellence (CDSE) Insider Threat Detection Analysis Course (ITDAC)
- Completion of Workplace Assessment of Violence Risk (WAVR-21) Workshop
- Completion of Center for Development of Security Excellence (CDSE) Curriculums; INT311.CU/INT312.CU/CI201.CU
At Leidos, we don't want someone who "fits the mold"—we want someone who melts it down and builds something better. This is a role for the restless, the over-caffeinated, the ones who ask, "what's next?" before the dust settles on "what's now."
If you're already scheming step 20 while everyone else is still debating step 2… good. You'll fit right in.
Original Posting:October 27, 2025
For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.
Pay Range:Pay Range $101, $183,300.00
The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.
-
Threat Analyst
3 days ago
Washington, Washington, D.C., United States Dentons Full time $83,850 - $111,850Dentons US LLP is currently recruiting for a Threat Analyst. The Information Security Threat Analyst is responsible for proactively hunting for threats within client environments, developing and tuning SIEM use cases, and conducting in-depth investigations of security events. The role involves monitoring and operationalizing threat intelligence,...
-
Lead Cyber Threat Analyst
1 day ago
Washington, Washington, D.C., United States DirectViz Solutions, LLC Full time $120,000 - $180,000 per yearDirectViz Solutions, (DVS) is a rapidly growing government contractor that provides strategic services that meet mission IT needs for government customers. DVS provides innovative information technology solutions to government clients through the knowledge and expertise of our dedicated employees. DVS is an employee-centric employer that provides competitive...
-
Cyber Threat Intelligence Analyst
1 day ago
Washington, Washington, D.C., United States Tyto Athene, LLC Full time $80,000 - $120,000 per yearTyto Athene is searching for a Cyber Threat Intelligence Analyst to support multiple cybersecurity workstreams within the Department of Health and Human Services (HHS). The individual will contribute to research, analysis, and operational support activities as part of HHS's Cybersecurity Operations (CSO) division. The role is instrumental in assisting with...
-
Senior Threat Intelligence Analyst, SEAR
4 days ago
Washington, Washington, D.C., United States Apple Full time $120,000 - $180,000 per yearAs part of our efforts to protect our users, Apple is looking for a world-class senior threat intelligence analyst to join a team of security researchers and threat intelligence analysts. This team works together and cross-functionally to drive efforts to solve security engineering challenges, with an emphasis on supporting decisions that provide the...
-
Sr. Cyber Threat Intelligence Analyst
4 days ago
Washington, Washington, D.C., United States cFocus Software Incorporated Full time $120,000 - $180,000 per yearcFocus Software seeks a Senior Cyber Threat Intelligence Analyst to join our program supporting AOUSC. This position is fully remote. This position requires active Public Trust clearance.Qualifications:8 years' experience in conducting in-depth analysis of cyber threats, including malware, phishing campaigns, and other attack vectors. This involves...
-
Senior Cyber Threat Intelligence Analyst
3 days ago
Washington, Washington, D.C., United States Valiant Solutions Full time $135,000 - $149,000 per yearPosition DescriptionValiant Solutions is seeking aSenior Cyber Threat Intelligence Analystto join our rapidly growing and innovative cybersecurity teamNamed one of theBest Places to Work in the Washington DC area for 11 consecutive years, Valiant is proud of our employee-centric culture and commitment to excellence. If you are interested in learning more...
-
Washington, Washington, D.C., United States Sony Full time $85,000 - $105,000Sony Corporation of America, located in New York, NY, is the U.S. headquarters of Sony Group Corporation, based in Tokyo, Japan. Sony's principal U.S. businesses include Sony Electronics Inc., Sony Interactive Entertainment LLC, Sony Music Entertainment, Sony Music Publishing and Sony Pictures Entertainment Inc. With some 900 million Sony devices in hands...
-
Russian Language Intern
4 days ago
Washington, Washington, D.C., United States CSIS Middle East Program Full time $40,000 - $60,000 per yearJob SummaryThe Center for Strategic and International Studies (CSIS) is a non-profit, bipartisan public policy organization established in 1962 to provide strategic insights and practical policy solutions to decision makers concerned with global security and prosperity. Over the years, it has grown to be one of the largest organizations of its kind, with a...
-
Washington, Washington, D.C., United States American Enterprise Institute Full time $50,000 - $54,000 per yearOverviewThe Critical Threats Project (CTP) at the American Enterprise Institute (AEI) is seeking a full-time, in-person program assistant. The person in this role should have a strong interest in advancing American national security and deterring threats to the US from Iran, the Salafi-jihadi movement, and great-power competition in the Middle East and...
-
Incident Response Analyst
3 days ago
Washington, Washington, D.C., United States Tyto Athene Full time $80,000 - $120,000 per year:Tyto Athene is searching for an Incident Response Analyst to support swing shift activities. We believe our Security Operations Center (SOC) analysts form the backbone of our cybersecurity services. Take your career to the next level and join us as a Tier 2 SOC Analyst. You will play a critical role in conducting in-depth analyses and responding to...