Forensic Insider Threat Analyst
$100kThe Johns Hopkins University Applied Physics Laboratory
Are you interested in helping protect critical research, national security initiatives, and cutting-edge innovation from insider threats?
If so, join us at APL!
We are seeking a Forensic Insider Threat Analyst to help identify, investigate, and mitigate insider risk in a complex and highly collaborative research environment. In this role, you'll leverage user activity monitoring, endpoint and identity telemetry, and forensic analysis to detect suspicious behavior and support sensitive investigations.
You'll work across a large set of stakeholders-including IT, Information Security, Research Administration, Legal, HR, and leadership-to address potential risks with discretion and precision. Our team is focused on balancing strong security practices with privacy, mission needs, and the unique demands of sponsored research. If you're curious, analytical, and motivated to solve complex security challenges, you'll fit right in.
As a Forensic Insider Threat Analyst, you will...
- Monitor user activity and security telemetry to identify anomalous or high-risk behavior.
- Detect and investigate insider threat incidents, including data exfiltration, unauthorized access, credential misuse, intellectual property theft, and policy violations.
- Correlate data across sources such as SIEM, EDR, DLP, IAM, email, and endpoint logs to build comprehensive investigative timelines.
- Conduct digital forensic analysis while preserving evidence integrity and maintaining proper chain of custody.
- Document findings in clear, defensible reports to support investigations and decision-making.
- Leverage behavioral indicators and detection logic to enhance early identification of insider threats.
- Support containment and remediation efforts in coordination with IT security and incident response teams.
- Analyze access patterns involving sensitive research data, proprietary information, and regulated datasets.
- Provide case support for matters involving export-controlled research, sponsored programs, and sensitive personnel concerns.
- Recommend improvements to security controls, policies, and awareness efforts to reduce insider risk.
- Contribute to the growth and maturity of the Insider Threat Program, including workflows, case management, and metrics.
Qualifications
Minimum Qualifications
- Bachelor's degree in cybersecurity, digital forensics, computer science, information systems, criminal justice, or a related field, or equivalent experience.
- 2 or more years of experience in cybersecurity, digital forensics, insider threat analysis, or security investigations.
- Hands-on experience with user activity monitoring platforms and security analytics tools.
- Experience analyzing logs and data from SIEM, EDR, DLP, IAM, and endpoint systems.
- Strong understanding of forensic methods, evidence handling, and investigative documentation.
- Ability to analyze complex datasets, identify patterns, and communicate findings clearly.
- Experience working with confidential information and maintaining discretion.
- This position may require occasional after-hours support for active incidents or urgent investigations.
- Strong written and verbal communication skills.
- Are able to obtain Secret level security clearance. If selected, you will be subject to a government security clearance investigation and must meet the requirements for access to classified information. Eligibility requirements include U.S. citizenship.
Desired Qualifications
- Experience in higher education, research institutions, healthcare, life sciences, engineering, or similarly complex environments.
- Familiarity with protecting classified information, intellectual property, research data, and controlled or sensitive information.
- Knowledge of privacy, employment, monitoring, and data governance requirements in a private-sector academic environment.
- Certifications such as GCITP, GCFA, GCFE, CHFI, CISSP, CISM, or related credentials.
- Experience supporting investigations involving email abuse, cloud platforms, and collaboration tools.
- The research center seeks a detail-oriented security professional who can protect critical research assets while supporting a collaborative and national security mission-driven environment.
About Us
Why Work at APL?
The Johns Hopkins University Applied Physics Laboratory (APL) brings world-class expertise to our nation's most critical defense, security, space and science challenges. While we are dedicated to solving complex challenges and pioneering new technologies, what makes us truly outstanding is our culture. We offer a vibrant, welcoming atmosphere where you can bring your authentic self to work, continue to grow, and build strong connections with inspiring teammates.
At APL, we celebrate our differences of perspectives and encourage creativity and bold, new ideas. Our employees enjoy generous benefits, including a robust education assistance program, unparalleled retirement contributions, and a healthy work/life balance. APL's campus is located in the Baltimore-Washington metro area. Learn more about our career opportunities at
All qualified applicants will receive consideration for employment without regard to race, creed, color, religion, sex, gender identity or expression, sexual orientation, national origin, age, physical or mental disability, genetic information, veteran status, occupation, marital or familial status, political opinion, personal appearance, or any other characteristic protected by applicable law.APL is committed to providing reasonable accommodation to individuals of all abilities, including those with disabilities. If you require a reasonable accommodation to participate in any part of the hiring process, please View email address on click.appcast.io.
The referenced pay range is based on JHU APL's good faith belief at the time of posting. Actual compensation may vary based on factors such as geographic location, work experience, market conditions, education/training and skill level with consideration for internal parity. For salaried employees scheduled to work less than 40 hours per week, annual salary will be prorated based on the number of hours worked. APL may offer bonuses or other forms of compensation per internal policy and/or contractual designation. Additional compensation may be provided in the form of a sign-on bonus, relocation benefits, locality allowance or discretionary payments for exceptional performance. APL provides eligible staff with a comprehensive benefits package including retirement plans, paid time off, medical, dental, vision, life insurance, short-term disability, long-term disability, flexible spending accounts, education assistance, and training and development. Applications are accepted on a rolling basis.
Minimum Rate $100,000 AnnuallyMaximum Rate $245,000 Annually
Required
Preferred
Job Industries
- Other
$100k - $245k
Johns Hopkins Applied Physics Laboratory in Laurel, Maryland, seeks a Forensic Insider Threat Analyst to identify and mitigate insider risks. This position leverages user activity monitoring and forensic analysis across collaborative environments. Key qualifications include...Suggested- ...Exploitation Analyst (EA) We are seeking a highly analytical and detail-oriented Exploitation... ...to identify vulnerabilities, assess threats, and provide critical insights that... ...Exploitation Analyst, Threat Intelligence Analyst, Forensic Analyst, Cyber Operations Analyst,...SuggestedTemporary workFor contractorsImmediate startFlexible hours
- ...Risk Management Program (IRMP) by designing, implementing, and maintaining comprehensive insider threat detection and mitigation capabilities. The Insider Threat Program Analyst will develop and operationalize policies, systems, and practices to detect, deter, and respond...SuggestedContract workFor contractors
$86k - $138k
...program management professional to support the Senior PM Domain Analyst in defining requirements and validating analytical outputs for... ...operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The...SuggestedContract workWork at officeShift work- ...What You Will Do: At Independent Software, as an Intrusion Analyst Level 3, you will support mission-critical cybersecurity operations... ...SIGINT and computer network defense resources to detect threats, understand adversary behavior, and help protect critical systems...Suggested
- ...Exploitation Analyst-Mid Annapolis Junction, Maryland, United States NetSage's mission... ...vulnerabilities, intrusions, and threats in computer network systems. The ideal candidate... ...Engineering, Computer Science, Computer Forensics, Cyber Security, Software Engineering,...Contract work
- ...EOD Analyst Parra Consulting Group is seeking for an EOD Analyst who will perform Technical analysis and assist in the collection,... ...improvised weapons systems and incidents to identify emerging threats and commercial based technologies (CBT) to determine technical...Remote work
$100k
...someone like you to join our team at APL. We are seeking a missile effectiveness analyst to characterize and evaluate tactical missile system performance against complex and emergent threats. We are a hardworking team of analysts who support a wide range of government...Temporary workWork experience placementInterim roleRelocation packageFlexible hours$66k - $106k
...CIRT Tier 2 Analyst / Active Secret Job Locations US-MD-Beltsville Requisition... ...anomalous activity and potential threats. Protect against and prevent potential... ...threats and vulnerabilities. Perform forensic analysis of hosts artifacts, network traffic...Contract workLocal areaShift workAfternoon shift- ...identifying and responding to cyber risks and threats. Those supporting the DSCM program... ...stakeholders. Assist with training junior level analysts. Perform analysis of network and host... ...issues using computer host analysis, forensics, and reverse engineering. Ability to...Work experience placementInterim roleFlexible hoursShift work
$100k
...someone like you to join our team at APL. We are seeking a missile effectiveness analyst to characterize and evaluate tactical missile system performance against complex and emergent threats. We are a hardworking team of analysts who support a wide range of government...Interim role- A technology and cybersecurity company in Columbia, MD is seeking an experienced Exploitation Analyst to join their mission-critical contract. This role involves developing cyber exploitation plans and requires strong experience in systems design, network defenses, and...Contract work
$115.44k - $186.16k
...related to US Financial Crimes Prevention and Operations, focused on U.S. KYC operations, but may also include US Fraud Management, Insider Threat Management and Investigations, and Physical Security. Depth & Scope: Recognized as top level expert within the company...Local areaWork from homeFlexible hours$80k - $128k
...: Cyber Monitoring and Operations, Cyber Threat and Investigations, and Technology Innovation... ...2 Cyber Incident Response Team (CIRT) Analyst to join Peraton's Department of State (... ...security threats and vulnerabilities. Perform forensic analysis of hosts artifacts, network...Interim roleInternshipWork at officeWorldwideAfternoon shift$106.74k - $152k
...to defend our interests in cyberspace and anticipate emerging threats. Our capabilities in cybersecurity, network architecture, reverse... ...Technologies has a need for a Statistical Model Validation Analyst who will support Verification & Validation (V&V) activities by...Full timeWork at officeLocal areaWorldwide$31.44 - $43.26 per hour
...collaboration tools. Over 80 of the Fortune 100, 10,000 large enterprises, and millions of smaller organizations trust Proofpoint to stop threats, prevent data loss, and build resilience across their people and AI workflows. Our mission is simple: safeguard the digital world...Flexible hours$104k - $166k
...Responsibilities Peraton Labs is seeking an Agentic AI Business Analyst to help translate mission and business needs into operational... ...at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The...Contract workShift work- ...regulatory compliance, access controls, incident management, vulnerability management, and data protection. Understanding of cyber security threat modeling, risk management concepts, cyber security frameworks, secure coding principles, and security technologies....
$100k
...and innovate to further our capabilities against rapid proliferation of adversarial systems. As a Thermal and Infrared Signature Analyst, you will... Apply strong attention to detail to predict EO/IR signature phenomenologies of missiles, rocket motor plumes,...Temporary workWork experience placementInterim roleRelocation packageFlexible hours$100k
...physicists, mathematicians, and computer scientists are engaged in an extensive portfolio of projects with the U.S. military. Our analysts support the acquisition, maintenance, and assessment of various aircraft and weapon assets. We want you to join our team, and provide...Temporary workWork experience placementInterim roleRelocation packageFlexible hours- ...The Counterintelligence Analyst will play a key role in supporting the NOAA Research Security Program by identifying, assessing, and mitigating threats to NOAA's critical technologies, intellectual property, and research data. This position requires expertise in counterintelligence...
$100k
...strike weapons and platforms? If so, we're looking for someone like you to join our exceptional team of scientists, engineers, and analysts in the Air Combat and Strike Mission Analysis Group! We are a large team of 50+ engineers, physicists, mathematicians, and...Temporary workWork experience placementInterim roleRelocation packageFlexible hours$86.8k - $198k
...Naval Program Analyst The Opportunity: As a defense mission professional, you ask questions others don't. You understand the nuances of complex situations. You use your skills to think bigger and push further, solving complex problems. We're looking for an expert...Full timeContract workPart timeWork at officeLocal areaRemote work- ...Securetech Protocol Analysts Opportunities in Maryland and Hawaii! Let's make a positive impact on U.S. National Security! We are building a team to handle some of the Intelligence Community's most serious challenges – come be a part of it! SecureTech Protocol...For contractors
$61.13k - $134.48k
...Technology, or related field (e.g., General Engineering, Computer Engineering, Electrical Engineering, Computer Science, Computer Forensics, Cyber Security, Software Engineering, Information Assurance, or Computer Security) Relevant experience must be in computer or...Contract workWork experience placementLocal area$96.16 - $115.39 per hour
...Job Title CNO Analyst Overview EverWatch is a government solutions company providing advanced defense, intelligence, and... ...product security and resilience cryptographic solutions and anti-forensic measures ~ Experience with indigenous and vendor...Hourly payContract workLocal areaFlexible hours- ...Insight Global is hiring two Revenue Integrity Analysts to join Virtua's Revenue Cycle Operations team, which supports hospitals, hospice, home health, professional services, and all facets of the healthcare system. This position is responsible for optimizing the revenue...
- ...Athene is searching for a DCO Analyst to support a DoD customer in... ..., and respond to cyber threats targeting the DoD Information... ...for technical indicators of insider threat activity. Support monthly... ...response activities and forensic analysis as required. Qualifications...Full timeWorldwide
- ...now and into the future. Position Description:The Counterintelligence Analyst will support the NOAA Research Security Program by conducting specialized analyses to identify, assess, and mitigate threats to NOAA's critical technologies, intellectual property, and research...
- ...directly manage multiple specialized and various functional teams (e.g. Application Development, Solutions Designers, Business Systems Analysts, Support, Technology Project Management etc.) and be responsible for seamless management of ongoing infrastructure support shared...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Forensic Insider Threat Analyst. Be the first to apply!

