Description
The Insider Threat Program Lead will design, mature, and oversee insider threat detection, analysis, and investigative support for a federal enterprise environment. The role integrates user activity monitoring, behavioral analytics, threat intelligence, and investigative workflows to identify and mitigate malicious, negligent, or compromised insider activity, while coordinating with SOC, CTI, HR, legal, counterintelligence, and security stakeholders. Responsibilities include developing detection methodologies, leading investigations, establishing reporting and case-management procedures, conducting risk assessments, supporting dashboards and executive briefings, and contributing to policy and governance initiatives. The position requires at least 10 years of relevant cybersecurity, counterintelligence, investigations, or insider threat experience, 5+ years supporting insider threat or behavioral analytics programs, federal or classified-environment experience, and expertise with UEBA, SIEM, DLP, identity analytics, and investigative workflows.
