The Digital Modernization Sector at Leidos currently has an opening for a Hunt Analyst supporting the HEITS Contract as part of the Department of Homeland Security (DHS) Insider Threat Program (ITP). This is an exciting opportunity to use your experience to support sustain design and evolve the database backbone of the ITP. The ITP mission is to identify insider threats to the department by utilizing advanced analytics monitoring and data correlation which in turn help address and eliminate potential threat actors from compromising the DHS mission in safeguarding the homeland.
The selected candidate will be responsible for the following:
Examine analyze and search insider threat data to identify trends patterns and insights of potential insider threat indicators.
Provide analytical program support services related to the operation of UAM/ UEBA tool.
Monitor UAM platform to identify emerging requirements related to insider threat events and coordinate across the enterprise to ensure timely response.
Conduct further research on the UAM platform to identify patterns of concerning behavior related to a potential insider threat risk to the DHS enterprise.
Provide proactive insider threat-based hunting across the DHS enterprise network leveraging methodologies and behavioral analytics to detect investigate and mitigate anomalous activity and policy violations indicative of malicious insider behavior.
Conduct continuous hunt operations across data and log sources DHS platforms EDR tools and network traffic to identify patterns of insider threat behavior.
Identify mitigation strategies to assist the investigative team in effectively reducing insider threat risk.
Utilize UEBA (User and Entity Behavior Analytics) platforms and techniques to baseline user activity and detect deviations. Provide timely response to critical/high UAM alerts (within 4 hours during normal business hours).
Basic Qualifications:
Bachelors degree and (15) years of prior relevant insider threat experience or Masters with (13) years of prior relevant experience. Additional years of experience with requisite certifications will be considered in leu of degree.
Minimum of 4 years demonstrated knowledge of the intelligence cycle analytic techniques systems processes and organizations.
Minimum of 4 years demonstrated knowledge of Threat Assessment & Mitigation Strategies.
Have excellent written and verbal skills with ability to deliver briefings to a diverse group of audiences.
Possess knowledge of current domestic and international threats to U.S. national security interests.
Be adept at establishing networks with relevant security personnel and prevention stakeholders to foster program utilization.
Be a self-starter capable of working independently to promote program goals.
Working knowledge of User Activity Monitoring Software (UAM) and solutions.
Working knowledge of Cybersecurity toolsets designed to support ITP mission activities.
Working Knowledge of Open-Source toolsets.
Working Knowledge of Insider Threat Frameworks; Pathway to Violence & Critical Pathway.
Current TS/SCI and Must be a US Citizen.
Ability to obtain DHS EOD SCI and willingness to undergo CI Polygraph.
Preferred Qualifications:
Masters degree from an accredited college or university in Criminal Justice Homeland security Cyber Security or related field
Proven experience (10 years) in Intelligence Analysis
Experience with User Activity Monitoring products and platforms
Proven experience (4 years) in Threat Assessment & Mitigation
Certified Counter-Insider Threat Professional - Fundamentals (CCITP-F)
Certified Counter-Insider Threat Professional - Analysis (CCITP-A)
Completion of Center for Development of Security Excellence (CDSE) Insider Threat Detection Analysis Course (ITDAC)
Completion of Workplace Assessment of Violence Risk (WAVR-21) Workshop
Completion of Center for Development of Security Excellence (CDSE) Curriculums; break things (in a good way). Then build them smarter.
Were the tech company everyone calls when things get weird. We dont wear capes (theyre a safety hazard) but we do solve high-stakes problems with code caffeine and a healthy disregard for how its always been done.
For U.S. Positions: While subject to change based on business needs Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.
The Leidos pay range for this job level is a general guideline onlyand not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job education experience knowledge skills and abilities as well as internal equity alignment with market data applicable bargaining agreement (if any) or other law.
Required Experience:
IC
Leidos is an innovation company rapidly addressing the world's most vexing challenges in national security and health. Our 47,000 employees collaborate to create smarter technology solutions for customers in these critical markets.