User Access Management (UAM) Analyst
IT Concepts Inc.About the role
Founded in 2003, IT Concepts’ core values – customer-centricity, teamwork, driven to deliver, innovation, and integrity – ensure we work together to be the best, realize objectives, and make a positive impact in our communities. We intentionally created and sustain our ITC culture that embraces change, experimentation, continuous learning, and improvement. We bring our design thinking problem-solving approach that challenges assumptions, prioritizes curiosity, and invites complexity to deliver innovative, efficient, and effective solutions. As we continue to grow in the support of our government customers, we are looking for driven and innovative individuals to join our team.
IT Concepts is looking for an experienced User Access Management (UAM) Analyst to support the Social Security Administration under Call Order 3 – OIS. The UAM Analyst is responsible for conducting detailed data triage on anomalous events identified by User Activity Monitoring (UAM), Data Loss Prevention (DLP), and other client network and endpoint monitoring tools. This role involves investigating and escalating events of concern, monitoring network activity using UAM and User Behavior Analytics (UBA) tools, and providing viable response options. The analyst will perform initial discovery and analysis of UAM alerts, draft comprehensive reports, and notify designated personnel of potential insider threats. Key responsibilities include preserving activity logs, ensuring compliance with data privacy and security regulations, and collaborating with the Security Operations Center to resolve insider threat incidents.
Location: Remote
Job Responsibilities:
- Conduct data triage of anomalous events collected by approved User Activity Monitoring (UAM), Data Loss Prevention (DLP) and other client network and endpoint monitoring tools. Elevate and investigate anomalous events of concern.
- Within the boundaries of agency policies, monitor all types of network activity using the agency provided UAM and User Behavior Analytics (UBA) tools to identify and report on viable response options ranging from administrative actions, security violations or infractions, and referrals to the OIS Insider Threat Team Lead.
- Provide the initial discovery and analysis of UAM alerts applying intelligence community analytic standards and critical thinking prior to submitting to the Insider Threat Project Lead for the purpose of determining the potential referral decisions/actions
- Provide timely notification to designated personnel if a potential insider anomaly is detected. Draft comprehensive analytical and investigative reports and referrals that highlight activity or behavior that may be indicative of an insider threat/risk to SSA.
- Process Insider Threat UAM alerts and preserve the activity logs for potential future investigational viability and/or operational capability and ensuring the availability, compliance with data privacy and security regulations, while preserving the privacy and civil liberties of the SSA workforce
- Perform after action reviews of past system alerts, to determine scope, urgency, and potential impact, identifying the specific vulnerability, and making recommendations that enable development of future remediation and mitigation efforts.
- Collaborate with and provide expert technical support to the agency Security Operations Center defense technicians to resolve insider threat incidents and provide recommendations to address and assist with resolution of any issues identified.
Requirements
- Minimum 8 years of relevant experience is required with a Bachelor’s Degree.
- 2 years of experience is required with Forcepoint.
- Proficiency in UAM, DLP, UBA tools, SIEM systems, and network monitoring; strong analytical skills for triaging and investigating anomalous events.
- Excellent written and verbal communication skills for drafting reports, providing notifications, and collaborating with team members.
- Familiarity with data privacy regulations, civil liberties, and security compliance; experience in incident management and documentation.
- Proven ability to perform initial discovery, analyze alerts, and draft detailed investigative reports.
- Experience in managing highly complex IT projects, including coordinating with multiple stakeholders and ensuring timely and effective resolution of issues.
- Demonstrated ability to perform after-action reviews, make recommendations for remediation, and support the development of future mitigation strategies.
Clearance:
- Active DOD Secret Clearance required to be considered for the position.
Preferred Certifications:
- Ability to obtain certifications in ForcePoint policy writing, extensive scri
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s