The Insider Threat Analyst (Security Operations) will be part of a team that monitors for and investigates insider threat activity in a large federal agency. Discovered threat activity will be captured and documented in reports sent to cross organization leadership. The analyst will develop custom searches using a wide array of network and host-based security toolsets (Splunk, QRadar, Microsoft Defender etc.). The individual will need to possess the ability to work well both individually and as part of a team with a shared mission.
Veterans encouraged to apply.
- Review and analyze log files from various sources such as SIEM, EDR, packet captures, and host logs to report any unusual or suspect activities
- Provide targeted detection and analysis, including the development of custom signatures and log queries and analytics for the identification of insider threats
- Monitor User Activity Monitoring (UAM) and User Entity Behavioral Analytics (UEBA) tools
- Determine scope of intrusion and recommend remediation activities to secure the source or initial point of access of intrusion
- Characterize and analyze network traffic to identify anomalous activity and potential threats to network resources
- Coordinate with enterprise-wide cyber defense staff to validate network alerts
- Perform event correlation using information gathered from a variety of sources within the enterprise to gain situational awareness and determine the effectiveness of an observed threat
- Conduct research, analysis, and correlation across a wide variety of all source data sets (indications and warnings)
- Monitor external data sources (e.g., cyber defense vendor sites, Computer Emergency Response Teams, Security Focus) to maintain currency of cyber defense threat condition and determine which security issues may have an impact on the enterprise
- Provide recommendations and custom solutions to counter insider threat activity
- Provide technical summary of findings in accordance with established reporting procedures
- Identify insider threat use-cases for automation using a security orchestration and automation product
- Must possess a minimum of three years experience performing in Insider Threat analysis
- Candidate MUST be proficient with Splunk Query Language
- Experience with common threat hunting solutions including Splunk, packet analysis (e.g., Wireshark), NetFlow, QRadar or other SIEMs, etc.
- An understanding of the MITRE ATT&CK Framework and Cyber Kill Chain methodologies
- Understanding of NIST SP 800-61, US CERT, and Office of Management and Budget (OMB) standards
- Knowledge of and ability to apply cybersecurity and privacy principles to organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation)
- Knowledge of and ability to apply techniques for detecting host and network-based intrusions using intrusion detection technologies
- Experience using ticketing systems to include ServiceNow (SNOW) and BMC Remedy
- Knowledge of cyber attackers (e.g., script kiddies, insider threat, non-nation state sponsored, and nation sponsored)
- Scripting experience, such as Python, PowerShell, etc. is a plus
- Strong time management skills with attention to detail
- Strong critical thinking skills
- Strong interpersonal and collaborative skills, with the ability to work in a team environment
- Ability to develop content for cyber defense tools
- Ability to write insider threat reports to both technical and non-technical audiences; reports are evaluated for quality and clarity
Relevant certifications and training are a plus:
- GIAC Certified Incident Handler (GCIH)
- GIAC Certified Forensics Examiner (GCFE)
- GIAC Certified Intrusion Analyst (GCIA)
- GIAC Certified Forensic Analyst (GCFA)
- GIAC Certified Network Forensic Analyst (GNFA)
- GIAC Cyber Threat Intelligence (GCTI)
- GIAC Reverse Engineering Malware (GREM)
- Certified Information Systems Security Specialist (CISSP)
- Splunk Core Certified Power User
Maveris attracts and retains talent of the highest caliber by offering opportunities to work in exciting and challenging environments surrounded by bright minds. Our employees are our most prized asset and are rewarded with highly competitive compensation and a top-tier benefits package, including:
- 401(k) with company contribution
- Dental Insurance
- Health Insurance
- Vision Insurance
- Life Insurance
- Paid Time Off
Maveris offers exceptional, mission-focused solutions to organizations facing highly complex IT, digital, and cyber security challenges. Our success is achieved by maintaining an environment of trust where people are encouraged to reach their fullest potential. Every candidate that applies to Maveris brings something unique to the table, and because our team is diverse, we consistently meet our goals and exceed client expectations. If you are a highly-motivated person with a willingness to learn, we invite you to apply today to join our team!
To learn more about employee benefits visit www.maveris.com.
For company updates and the latest job postings check us out on LinkedIn.
If you’d like to read about some of our research and projects head over to Maveris Labs.
Want a more behind the scenes view? Check out our blog Maveris Insights to learn more about the team behind the solutions.
We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity or expression, pregnancy, age, national origin, disability status, genetic information, protected veteran status, or any other characteristic protected by law.