Jobs and Careers
IT

Senior Insider Threat Analyst

IT Concepts Inc.
United Statesfull_timeVerifiedPosted 17 May 2024

About the role

Founded in 2003, IT Concepts’ core values – customer-centricity, teamwork, driven to deliver, innovation, and integrity – ensure we work together to be the best, realize objectives, and make a positive impact in our communities. We intentionally created and sustain our ITC culture that embraces change, experimentation, continuous learning, and improvement. We bring our design thinking problem solving approach that challenges assumptions, prioritizes curiosity, and invites complexity to deliver innovative, efficient, and effective solutions. As we continue to grow in the support of our government customers, we are looking for driven and innovative individuals to join our team.

IT Concepts is seeking a highly skilled and experienced Insider Threat Senior Analyst Support to join our team supporting our Federal client Social Security Administration (SSA). The ideal candidate will have a strong background and expertise in Insider Threat and will undertake an agile approach to provide strategic planning support, iterative program improvements, Operations & Maintenance (O&M), and overall programmatic support services for the Office of Information Security (OIS) and its Insider Threat Program Management Officer (PMO). The candidate will collaborate with stakeholders to prioritize data sources for onboarding into risk models and gathering requirements for dashboards to provide a holistic view on operations. Services include supporting and advising the OIS insider threat PMO in the ongoing development of the insider threat products and program roadmap(s), using analytical methods to understand insider risk patterns and establish models for forecasting insider risk scenarios, and providing services to implement, execute, and maintain necessary activities in support of an OIS-wide counter insider threat program.

The candidate will provide following services to support and maintain an agency-wide plan and program for insider threat awareness, response consultation, policy enhancement, continuous monitoring, and reporting requirements. During execution of their duties the candidate may be required to deliver and receive sensitive briefings within SSA secured spaces such as the SCIF at SSA or an approved alternate secured location.

Responsibilities

Support Insider Threat policy and procedure updates for agency, interagency, or federal intelligence community-wide support. Focus on standardization of referral language/templates, triage and escalation, and case management.

Assist with the development and implementation of new insider threat alerts to help drive operational maturity and enhance detection and mitigation of events and/or incidents indicative of an insider threat.

Provide technical expertise in cyber and insider adversary capabilities and provide assessments of the intentions of adversary groups to conduct computer network exploitation and computer network attack against U.S. private sector and government networks and information systems.

Develop methods and procedures to extract data from existing SSA IT systems that may identify potential insider threats.  Identify vulnerabilities in SSA IT assets that are susceptible to being used by insider threats.

Provide recommendations on new or amended technical indicators for implementation in insider threat detection systems (SIEM, UBA, UAM, etc.) in accordance with approved SSA policies and procedures.

Identify, implement, and prioritize new potential risk indicators (PRI) into DLP, SIEM, and UBA.

Collaborate with the insider threat team in the enhancement of enterprise-level Standard Operating Procedures for automation and orchestration.

Provide cyber intelligence support activities as functions with other OIS intelligence partners such as supply chain and cyber threat analysis units, as analytical functions in collaboration with the SOC, or both.

Oversee and initiate reach back support to other federal government insider threat programs to enhance information sharing and collaboration.

Assist in the development of counterintelligence/foreign nexus related efforts, to include but not limited to, tailed alerts and policies and drafting of reports.

Provide technical expertise in cyber and insider adversary capabilities and provide assessments of the intentions of adversary groups to conduct computer network exploitation and computer network attack against U.S. private sector and government networks and information systems.

Conduct analysis of over 4,000 alerts a month across DLP, UBA, and SIEM.

Review and disseminate information from cyber news feeds, incident reports, threat briefs, and vulnerability alerts from the intelligence community, law enforcement agencies and other external sources to determine its applicability and impact to the SSA environment.

Develop and test new trigger policies within tight timelines to meet

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

IT Concepts Inc.

View company profile →