Insider Threat Monitoring Analyst
$107.9k - $195.05kJobleads-US
The Department of Homeland Security (DHS), Customs and Border Protection (CBP) Cyber Security Directorate (CSD) Security Operations Center (SOC) is a US Government program responsible to prevent, identify, contain and eradicate cyber threats to CBP networks through monitoring, intrusion detection and protective security services to CBP information systems including local area networks/wide area networks (LAN/WAN), commercial Internet connection, public facing websites, wireless, mobile/cellular, cloud, security devices, servers and workstations. The CBP SOC is responsible for the overall security of CBP Enterprise-wide information systems, and collects, investigates, and reports any suspected and confirmed security violations. Leidos is seeking an experienced Insider Threat Expert to join our team. As a member of this highly technical digital forensics team supporting U.S. Customs and Border Protection (CBP), you will be responsible for leading user activity monitoring activities, foreign service national monitoring, insider threat analysis, and investigating policy violations, data loss prevention (DLP) events, and sensitive data spillages.
Primary Responsibilities
- Supporting the Cyber Defense Forensics and Insider Threat investigations using near real- time (when possible, based on tools) monitoring of DLP tools for potential data exfiltration attempts of CBP mission data or employee PII/SPII Support Office of Professional Responsibility (OPR), Office of Intelligence (OI), Office of the Inspector General (OIG) and Other Government Agencies in the investigation of CBP personnel operating with potentially malicious or alleged criminal intent.
- Actively monitor Foreign Service National (FSN) network activity for network misuse and policy violations.
- Support User Activity Monitoring (UAM) activities.
- Make recommendations for insider threat alert triggers and detections across various security tools and logging sources.
- Monitor CBP laptops and mobile devices traveling OCONUS for suspicious activity and policy violations.
- Provide investigative support for CBP's OPR-Cyber Investigations for media leak investigations by identifying all users who have received/sent, printed, copied, downloaded/uploaded, or accessed the leaked document.
- Provide recommendations for Information Spillage Incident Response efforts on handling and sanitization methods pursuant to industry best practices, NIST 800-88 recommendations, and Federal guidelines.
Basic Qualifications
- Requires BS degree and a minimum of 8 or more years of direct relevant experience.
- Requires an active and current CISSP certification
- Degree in computer science, IT, Information/Cyber Security field from an accredited college or university.
- Additional experience or applicable certifications acceptable in lieu of degree.
- Working knowledge of defense-in-depth principles, network/HW/SW security architecture, network topology, IT device integrity, and common security elements
- Effective communication skills with emphasis on attention to detail, ability to accurately capture and document technical remediation details, and ability to brief stakeholders on incident statuses, recovery and root causes.
- Demonstrable experience performing forensic analysis, digital media analysis, and in-depth system & network log analysis in support of forensic investigations.
- Ability to generate forensically sound cyber analysis reports detailing forensically sound analysis procedures, findings, and recommendations from incident investigations.
- Strong problem-solving abilities with an analytic and qualitative eye for reasoning under pressure.
- Experience with User Activity Monitoring products and platforms
- Experience with Endpoint Detection and Response (EDR) tools
- Must be able to report to the Ashburn VA office up to 5 days per week
- Must be have a US Citizenship
- Must have a Top Secret clearance
- Must be able to obtain and maintain a CBP BI clearance.
Preferred Qualifications
- Master’s degree from an accredited college or university in IT Management, Engineering, or related field
- SANS GREM certification
- Previous experience contributing to or leading insider threat investigations in support of Federal Government, DOD, or Law Enforcement environments.
- Experience performing computer forensics in Federal Government, DOD or Law Enforcement environments.
Original Posting: July 13, 2026 For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.
Pay Range: Pay Range $107,900.00 - $195,050.00 The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.
Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $17.2 billion for the fiscal year ended January 2, 2026. For more information, visit
Pay and Benefits Pay and benefits are fundamental to any career decision. That's why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available here.
Securing Your Data Leidos will never ask you to provide payment-related information at any part of the employment application process. And Leidos will communicate with you only through emails that are sent from a Leidos.com email address. If you receive an email purporting to be from Leidos that asks for payment-related information or any other personal information, please report the email to View email address on click.appcast.io.
Commitment and Diversity All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.
#J-18808-Ljbffr Jobleads-US$106k - $126k
...experience Join Via Logic supporting U.S. Customs and Border Protection cybersecurity operations. As a Mid-Level Insider Threat Monitoring Analyst, you'll support insider threat monitoring activities by analyzing user behavior, access patterns, and security events...SuggestedFull timeContract workLocal areaWeekday work$160k - $185k
...strengthen and protect our nation’s vital interests. Title : Insider Threat Monitoring Lead (CBP) Clearance : Active Top Secret with SCI... ...before they become an incident rather than after. Analysts working under you can explain why a case escalated in terms...SuggestedTemporary workImmediate startRelocation package- ...Leidos is recruiting an Insider Threat Expert to join the CBP Cyber Security team. You will lead forensics investigations, monitor user activity, and assess insider threats across CBP networks and devices. The role requires a BS in IT/Cyber Security, CISSP, and active...Suggested
$120.8k - $265.8k
Job Title: Enterprise Monitoring Observability Lead (SME)Job Category: Information TechnologyTime Type: Full timeMinimum Clearance Required... ...evolving technology landscapes, emerging cybersecurity threats, and capability gapsEstablish enterprise monitoring solution strategy...SuggestedContract workWork experience placementLocal areaFlexible hours$15 - $39.14 per hour
...The Unified Mental Health Team (UMHT) Student Check-In Monitor will contact students that have been identified by school staff... ...with summer and other program staff. Suicide Screenings, threat Assessments, CPS reporting guidance. Supervision of students...SuggestedHourly payContract workPart timeSummer workWork at officeRemote work$82.1k - $172.4k
...(EVMS), maintaining the program’s Integrated Master Schedule, monitoring invoices and projecting expenditures, proposing and executing... ...from the program’s Control Account Managers- Support senior EV Analysts as they brief Government personnel regarding EVM and schedule...Contract workWork experience placementFlexible hours$143.91k
...$187,093.00 (GS-14, Step 10). In this Operations Research Analyst position you will become a key team member of Homeland Security... ...involved in cost estimating and analysis, planning, developing, monitoring, and coordinating cost analysis matters; serving as an advisor...Work at office$104k - $166k
Senior Incident Response Analyst Job Locations: US Requisition ID... ...own detection engineering and threat hunting, and serve as backup... ...early, contained fast, reported inside contractual and regulatory... ...functional drills. Own detection and monitoring. Drive SIEM and SOAR content...Contract workShift work$100k - $150k
...Reliability Monitoring Engineer – Remote Bright Vision Technologies is a technology consulting and software development company delivering cloud, AI, data, and enterprise solutions across the United States. This is a fantastic opportunity to join an established...Full timeH1bLocal areaImmediate startRemote workVisa sponsorship$80k - $85k
...dynamic role where you'll provide critical security support and risk monitoring for global clients. Interact directly with clients, offering... ...disseminate open-source and proprietary information; prepare threat intelligence reports and risk assessments. Crisis Management...Shift workNight shiftDay shift- Part-Time School Lunchroom EmployeeThis is a part-time employee working in the school lunchroom in an elementary school.Roles and ResponsibilitiesAn employee in this class is responsible for overseeing students from the time they enter the lunchroom until the time they...Part time
$25 per hour
...Security MonitorAmentum has opportunities for Security Monitors that have an active Top Secret/SCI clearance to join our team in Springfield, VA location.The position pays $25.00 an hour on an SCA contract.Responsibilities Include:Monitor and escort uncleared persons...Hourly payContract workLocal areaLong distance$36 per hour
...Alarm Monitor PositionThe Alarm Monitor position provides physical security, by monitoring a detection, intrusion monitoring system. Close Circuit TV (CCTV) monitoring; dispatch; visitor processing; and administrative services.PAY TRANSPARENCY: $36.00 PER HOURRESPONSIBILITIES...Work at officeFlexible hours$79.6k - $172.4k
Business Process Improvement Analyst TS/SCI with Poly REQUIRED Position Description CGI Federal is seeking... ...with operational Al mission needs. • Mature threat analysis, response and continuous monitoring functions through the development of repeatable assessment...Local area- ...and mission critical facilities are under more pressure than ever to run reliably and efficiently, which means demand for power monitoring expertise has never been higher. At our company, every employee's work has a direct impact on the level of service we deliver to...Full timeRemote work
- ...Job Description Job Description JOB DESCRIPTION : Applications Engineer – Power Monitoring Solutions LOCATION: Hybrid onsite in Ashburn, VA, or fully remote if you're based in the Northeast, Mid-Atlantic, or Southeast U.S., east of the Mississippi. SALARY...Full timeWork at officeRemote work
$85.5k - $158.7k
...TRSS) is looking for you! About the Role In this opportunity as an Analyst, you will be responsible for performing a wide range of work, from due diligence assessments to threat management reports. We leverage openly available data and our own proprietary...Full timeContract workWork experience placementWork at officeLocal areaRemote workFlexible hours- ...LLC (Valencor) is seeking a Cybersecurity Analyst with expertise in Risk Management... ...processes, security controls, and continuous monitoring to achieve and maintain ATO. • Lead Zero... ...with Zero Trust architecture. • Enhance threat detection and response using SIEM, SOAR,...
- ...Job Title: Microsoft Power Platform Quality Assurance (QA) Analyst Location: Remote work authorized, with occasional travel... ...maintenance, licensing updates, mobile integrations, health monitoring capabilities, and system enhancements. Assist with validation...Full timeTemporary workRemote work
- ...GDIT is seeking a Program Analyst to provide advanced analytical, operational, and business support to the National Intelligence Sector... .... Develop plans, including budgets and schedules, and monitor tasks to meet contractual/project requirements for assigned program...
- ...management processes, effectively guide incident triage calls from a technical perspective, share technical details obtained from monitoring tools and dashboards to aid troubleshooting, outline details of resolution activities, recommend and implement improved processes...Work experience placement
$216.75k - $293.25k
...Job Description PROGRAM ANALYST SME Oversee various programs that drive impactful mission outcomes for our customers as a Program... ...biweekly Sprint planning and retrospective meetings as well as monitoring Jira tickets and schedules. Updating, as needed, the Risk...Contract workTemporary workFor contractorsCasual workImmediate startRemote workWorldwideFlexible hours- Title: Business System Analyst (Governance & Operations Automation Analyst) Location: Chantilly, VA 20151 Hybrid: 3 days onsite Notes... ..., ensuring secure access to provisioning and usage monitoring. Key Responsibilities Analyze governance and operations processes...
- Continuous Monitoring Cyber Systems Engineer Chantilly, VA Position Description: The ConMon Cyber Engineer provides support to the customer in the area of Cyber Security. Daily tasks include, but are not limited to: ~Support the Information Security Continuous Monitoring...
- DescriptionSAIC is seeking a motivated and dedicated Program Control Analyst within the Army Business Group.This position requires proven... ...requisitions for subcontractors, consultants, and materials; monitoring subcontractor’s cost and review/approve of invoices.Review,...Contract workFor subcontractorRemote work
$23.18 per hour
...impacts the communities and customers we serve. Job Description As a Security Officer Full Time Unarmed Patrol Alarm Panel Monitoring in Sterling, VA , you will serve and safeguard clients in a range of industries such as Tech/Media/Telecom, and more. As an...Full timeFor contractorsWork at officeLocal areaShift work$18.87 per hour
...positively impacts the communities and customers we serve. Job Description As a Security Officer Part Time Unarmed Patrol Monitoring in Ashburn, VA , you will serve and safeguard clients in a range of industries such as Government, and more. Join a leading team...Part timeWork at officeLocal areaShift work- Business Analyst Assistant PURPOSE: Assists Business Analysts in ensuring that the business need for changes to processes, policies and... ...and processes. Collaborates with appropriate stakeholders to monitor, report and resolve issues. Assists in the development of solutions...Work experience placementWork at officeImmediate start
$39.5 - $44 per hour
...Sign-on Bonus! Job Responsibilities The responsibilities of this job include, but are not limited to the following: Monitoring test analyses and specimen examinations to ensure that acceptable levels of analytic performance are maintained and reporting any...Work at officeImmediate startRelocation packageFlexible hoursWeekend work2 days per week- ...Description Job Description Job Title: Application Engineer / QA Analyst – Microsoft Intune & Mobile Device Management Location:... ...integrating endpoint-management platforms with SIEM/security-monitoring solutions. Previous experience supporting federal civilian...Full timeTemporary workRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Insider Threat Monitoring Analyst. Be the first to apply!
- nonprofit analyst Ashburn, VA
- law enforcement response team analyst Ashburn, VA
- analyst sales operations Ashburn, VA
- development analyst Ashburn, VA
- military analyst Ashburn, VA
- chargeback analyst Ashburn, VA
- research and development analyst Ashburn, VA
- analyst market research Ashburn, VA
- targeting analyst Ashburn, VA
- sustainability analyst Ashburn, VA




