Insider Threat Technical Lead

49 minutes ago
Full-time
Senior
Cybersecurity
9th Way Insignia

9th Way Insignia

9th Way Insignia is a service disabled veteran owned small business (SDVOSB) that provides results oriented technical solutions to federal government customers. Our team offers 30+ years of experience delivering next generation technology solutions. We...

Internet Software & Services
51-250
Founded 2018

Description

  • Serve as the technical lead and trusted advisor to USPTO stakeholders, including regular customer syncs and status reporting.
  • Own the technical direction of the insider-risk toolset in Microsoft Purview.
  • Design and maintain dashboards, workbooks, and playbooks in Microsoft Sentinel.
  • Work across additional SIEMs including QRadar and Splunk, and custom Microsoft UBA rule engines.
  • Investigate and triage insider-risk alerts alongside analysts and guide findings.
  • Build, edit, and troubleshoot Power Automate flows for program automation.
  • Advise on Microsoft 365 Copilot security adoption, including DSPM, permission remediation, DLP, and AI policy alignment.
  • Define, track, and brief insider-risk program KPIs to leadership and recommend improvements.
  • Mentor and technically guide insider-risk analysts on investigations and data findings.
  • Coordinate through USPTO administrators for backend changes in a front-end configuration and monitoring model.

Requirements

  • Bachelor's degree in Information Technology, Computer Science, Information Systems Management, Cybersecurity, or a related field.
  • 7 years of specialized experience in one or more areas such as cyberspace operations, network security, computer/network forensics, CND, AS&W, intelligence analysis, cyber threat hunting, penetration testing, insider threat detection/mitigation, or incident detection and response.
  • Master's degree in a related field may substitute for 2 years of experience, reducing the requirement to 5 years of specialized experience.
  • Must currently hold CISSP or GIAC Security Expert (GSE).
  • Must currently hold at least one secondary certification: GCDA, GCIA, GCFA, GCTI, GNFA, GPEN, or GREM.
  • Active SECRET clearance or the ability to obtain and maintain one.
  • Experience with Microsoft Purview, Microsoft Sentinel, Microsoft 365 Copilot, Power Automate, KQL, JSON, and YAML.
  • Ability to work remotely and operate effectively without direct backend admin access.
  • Experience communicating with government stakeholders and briefing leadership on program metrics.
  • Applicants selected must be able to pass a security investigation and meet classified-information eligibility requirements.

Benefits

  • Salary range of $155,000 to $185,000 USD.
  • Medical, dental, and vision coverage.
  • 401(k) retirement plan.
  • PTO and paid holidays.
  • Telehealth access.
  • FSA and HSA options.
  • Basic Life and AD&D, STD, LTD, and voluntary life insurance.
  • Employee Assistance Program (EAP) and traveling assistance.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Principal Cloud Security Engineer

LastPass 251-1K IT Services

LastPass is hiring a Principal Cloud Security Engineer to embed cloud security best practices across its product and infrastructure development with DevOps, CI/CD, and architecture teams.

AWS AWS CDK CI/CD CloudFormation Docker GitLab GitLab CI Kubernetes LLM TCP/IP Terraform TLS
19 minutes ago

AP - IT Manager (Remote)

D2B Professional Services

IT Manager at a remote company supporting internal IT operations and managed services, responsible for maintaining secure systems and overseeing Microsoft-focused infrastructure and cybersecurity.

Active Directory Azure Cybersecurity Windows Server
34 minutes ago

Senior Cybersecurity Engineer

Super Technologies Pvt Ltd 1-10 aviation & aerospace

Super is seeking a Senior Cybersecurity Defense Specialist to protect its cloud and traditional environments by strengthening security architecture, detection, and incident response across a global entertainment platform.

AWS Azure CI/CD Cybersecurity GCP Network Security
34 minutes ago

Incident Responder

LastPass 251-1K IT Services

LastPass is hiring an Incident Responder to lead security investigations and incident response across its cloud environments, customers, and platform while strengthening detection and response capabilities.

Active Directory AWS Azure SIEM Wireshark
49 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers