Hiring.Camp

Insider Threat Analyst

MartinFed (Formerly MartinFederal Consulting)

Location
Washington, DC
Type
Full-time
Department
Human Resources
Education
Bachelor
Source
ApplicantPro

Description

COMPANY OVERVIEW

Founded in 2007 in Huntsville, AL, MartinFed provides the U.S. government with customer-focused, performance-based solutions using technology and an empowered workforce as an engine to drive its customers' missions. Our goal is to attract the best and brightest within their field.

We invest in our people because they are our greatest asset. They cultivate our purpose, embody and reflect our core values, and define our culture. MartinFed's core values that set us apart are the following:

  • Be Driven - We are fueled by the hunger to learn more and do more.
  • Be Curious - We engage in continuous improvement - never accepting the status quo.
  • Be Humble - We seek honest feedback to strengthen our relationships.
  • Pursue Excellence - We strive to achieve extraordinary results and do not settle for mediocrity.

Strive for excellence and consider joining our growing team today!

JOB OVERVIEW

The Insider Threat Analyst supports the Insider Threat Program Detection and Prevention (ITPDP) by performing day-to-day monitoring, detection, analysis, and triage of potential insider threat activity across enterprise environments. This role analyzes alerts and user activity from multiple security platforms to distinguish legitimate insider threat incidents from false positives, documents findings, and escalates cases as appropriate. Working under the direction of the Senior Insider Threat Analyst, the analyst supports the operation and continuous improvement of the insider threat program while ensuring all activities comply with federal insider threat policies, employee privacy protections, and civil liberties requirements.

Essential Functions:

Insider Threat Monitoring and Detection

  • Monitor logs, dashboards, and alerts across multiple enterprise security applications to identify potential insider threat activity.
  • Analyze user activity and system events to distinguish legitimate insider threat incidents from false positives.
  • Continuously monitor enterprise environments for indicators of malicious, negligent, or compromised insider behavior.

Incident Triage and Investigation

  • Perform initial triage and investigation of potential insider threat alerts.
  • Correlate information from multiple data sources to develop a complete understanding of potential insider threat activity.
  • Escalate confirmed or ambiguous incidents to the Senior Insider Threat Analyst in accordance with established procedures.
  • Maintain complete case documentation throughout the investigative lifecycle.

Detection Engineering Support

  • Assist with configuring, tuning, and troubleshooting detection rules, triggers, and analytics used by insider threat platforms.
  • Support the deployment, maintenance, and day-to-day operation of enterprise insider threat detection technologies.
  • Help improve detection fidelity by reducing false positives and refining alert logic.

Analysis and Reporting

  • Document investigative findings through clear analytical reports and case summaries.
  • Maintain accurate records in accordance with program reporting requirements.
  • Assist in developing workflows, playbooks, standard operating procedures, and other program documentation.

Collaboration and Program Support

  • Coordinate with Security Operations Center (SOC), investigative teams, Human Resources, Legal, and other stakeholders as directed.
  • Support continuous improvement initiatives for the Insider Threat Program.
  • Conduct all investigative activities in accordance with federal insider threat guidance while protecting employee privacy and civil liberties.

Qualifications:

  • U.S. Citizen with the ability to obtain and maintain a Tier 5 security clearance or higher.
  • Bachelor's degree in Cybersecurity, Information Technology, Criminal Justice, Intelligence Studies, or a related field (additional relevant experience may be substituted for education).
  • Approximately 6 years of combined experience in cybersecurity, security operations, investigations, digital forensics, insider threat, or related disciplines.
  • Hands-on experience with one or more enterprise Insider Threat, DLP, SIEM, UEBA, or User Activity Monitoring (UAM) platforms such as Splunk, DTEX, Microsoft Purview, Proofpoint/ObserveIT, Exabeam, or similar technologies.
  • Experience analyzing logs, alerts, dashboards, and user activity to differentiate true security incidents from false positives.
  • Working knowledge of Windows, Linux, and Unix operating systems.
  • Understanding of insider threat methodologies, user behavior analytics, event correlation, and investigative techniques.
  • Familiarity with digital forensics concepts, log analysis, and security investigations.
  • Knowledge of privacy, legal, and civil liberties considerations associated with federal Insider Threat Programs.
  • Excellent analytical, documentation, and written communication skills.
  • Ability to work effectively within an established insider threat program under the guidance of senior analysts.
  • Ability to obtain the Counter-Insider Threat Fundamentals Certification, if required.

Desired:

  • Experience supporting formal Federal Insider Threat Programs.
  • Experience with SIEM, UEBA, UAM, DLP, and behavioral analytics platforms.
  • Familiarity with Splunk Enterprise Security, Microsoft Purview, DTEX, Exabeam, Proofpoint/ObserveIT, or similar solutions.
  • Experience correlating events across multiple enterprise security tools.
  • Knowledge of security operations center (SOC) workflows and incident response processes.
  • Understanding of insider threat indicators, behavioral analytics, and risk scoring methodologies.
  • Experience developing or improving detection rules, workflows, and investigative playbooks.
  • Basic scripting experience (PowerShell, Python, or Bash) for automation or analysis.
  • Familiarity with NIST, CNSSD, or other federal insider threat guidance and best practices.
  • Strong collaboration skills when working with cybersecurity, investigative, legal, and human resources stakeholders.

PHYSICAL REQUIREMENTS & ENVIRONMENTAL CONDITIONS

  • Inside office environment.
  • Working on a computer for long periods of time.
  • May involve long period of sitting at a desk.
  • The work environment is fast-paced and sometimes involves extreme deadline pressures.

OTHER DUTIES

This job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities, and activities may change at any time with or without notice.


MartinFed is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regards to race, color, religion, religious creed, gender, sexual orientation, gender identity, gender expression, transgender, pregnancy, marital status, national origin, ancestry, citizenship status, age, disability, protected Veteran Status, genetics or any other characteristics protected by applicable federal, state or local law. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. In addition to federal law requirements, MartinFed complies with all applicable state and local laws governing nondiscrimination in all locations.

If you are a qualified individual with a disability or disabled veteran, you have the right to request a reasonable accommodation if you are unable or limited in your ability to use or access MartinFed's current openings as a result of your disability. You can request reasonable accommodations by calling 855.212.1810. Thank you for your interest in MartinFed.

Please Note: All positions at MartinFed are contingent upon passing a background check prior to a start date and are subject to random drug screenings during the employment period. In addition, MartinFed is an E-Verify employer.

Skills

PythonLinuxCybersecuritySIEMSOCSplunk

Similar Jobs

30

Insider Threat Analyst

Agile Defense · Washington, D.C. +1 · Onsite

1 week ago

Insider Threat Analyst

Statestreet · Quincy, Massachusetts, United States of America +1

2 weeks ago

Insider Threat Analyst

Abacus Technology · San Antonio, TX, US · Onsite

2 weeks ago

Insider Threat Analyst

Spacex · Hawthorne, CA +1

1 month ago

Insider Threat Analyst

MirLogic Solutions · Alexandria, VA

2 months ago

Insider Threat Analyst

Uobgroup · The Gardens North Tower, Malaysia · Hybrid

8 months ago

Specialized Security All Source Analyst (Insider Threat)

Core One · Quantico, VA

1 week ago

AOUSC - Insider Threat Analyst

cFocus Software Incorporated · Washington, DC · Hybrid, Onsite

1 week ago

Senior Cyber Security Analyst (Insider Threat)

RBA Economic and Finance · Head Office, Australia · Remote, Hybrid

1 month ago

Insider Threat Analyst Lead

Gunnison Consulting Group, Inc. · Washington, DC

1 month ago

AOUSC - Insider Threat Analyst Lead

cFocus Software Incorporated · Washington, DC

2 months ago

Cyber Insider Threat Analyst III

Agile Defense · Springfield, VA · Hybrid

2 months ago

Cyber Security / Insider Threat Analyst (DAYS Mon-Fri) -TS/SCI with Polygraph

GDIT · USA MD Riverdale - 4700 River Rd (MDC142), United States of America +3

2 months ago

Cyber Security / Insider Threat Analyst (DAYS Mon-Fri) -TS/SCI with Polygraph

Gdit · USA MD Riverdale - 4700 River Rd (MDC142), United States of America +3

2 months ago

Security Operations Center Insider Threat Analyst - Assistant Vice President

Citi Bank · 3 CHANGI BUSINESS PARK CRESCENT CHANGI BUSINESS PARK SINGAPORE · Hybrid

2 months ago

Security Operations Center Insider Threat Analyst - Assistant Vice President

citibank · SG

2 months ago

Principal Insider Threat Analyst

Salesforce · Virginia - Mclean, United States of America +2 · Onsite

2 months ago

Insider Threat Analyst III

Abacus Technology · San Antonio, TX, US · Onsite

4 months ago

Staff Security Analyst, Insider Threat

Anduril · Seattle, Washington, United States +1

4 months ago

Staff Security Analyst, Insider Threat

Anduril · Costa Mesa, California, United States

8 months ago

Insider Threat Analyst (ITA) - Analyst | Counterintelligence and Insider Threat

ProSidian Consulting · Charlotte, NC, United States

1+ year ago

Insider Threat Investigative Analyst

Pae · US-VA-Chantilly-1 Parks (VA193), United States of America · Onsite

1 week ago

Insider Threat Monitoring Analyst

Leidos · 5612 Ashburn VA, United States of America

1 week ago

Insider Threat Intelligence Analyst

Barclays · Knutsford, Radbroke Hall, United Kingdom +2

1 month ago

Insider Threat Investigative Analyst

Pae · US-DC-Washington-DOECI (DC090), United States of America · Onsite

1 month ago

Senior Insider Threat Liaison Analyst

EnProVera · Camp Lejeune, NC

1 month ago

Insider Threat Policy Analyst

QED Systems · Arlington, VA

1 month ago

Insider Threat / UAM Analyst

Leidos · 2113 The Mark Ctr Alexandria VA, United States of America

1 month ago

Cyber & Insider Threat Senior Analyst

Fedex · FXE-EU/POL/KRKDK/KRKDK/Kraków, Poland

2 months ago

Mid Insider Threat Investigative Analyst

Pae · US-DC-Washington-DOECI (DC090), United States of America · Onsite

2 months ago