The Digital Modernization Sector at Leidos currently has an opening for a Hunt Analyst supporting the HEITS Contract as part of the Department of Homeland Security (DHS) Insider Threat Program (ITP) supporting the Cybersecurity and Infrastructure Security Agency (CISA). This is an exciting opportunity to use your experience to support, sustain, design and evolve the backbone of the ITP. The ITP mission is to identify insider threats to the department by utilizing advanced analytics, monitoring, and data correlation which in turn help address and eliminate potential threat actors from compromising the DHS and CISA missions in safeguarding the homeland.
The selected candidate will be responsible for the following:
Review, analyze, and search insider threat data to identify trends, patterns, and insights of potential insider threat indicators.
Provide analytical, program support services related to the operation of UAM/ UEBA tool. Monitor UAM platform to identify emerging requirements related to insider threat events and coordinate across the enterprise to ensure timely response.
Identify and triage critical/high risk UAM alerts related to a potential insider threat risk to the DHS enterprise.
Leverage methodologies and behavioral analytics to detect, investigate, and mitigate anomalous activity and policy violations indicative of malicious insider behavior.
Provide timely response to critical/high UAM alerts (within 4 hours during normal business hours and provide after-hour support). Normal business hours will be defined as 6am to 10pm Monday – Friday excluding weekends and scheduled holidays. Implement corrective actions to restore normal operations and prevent recurrence.
Will author and produce written analytical and threat reporting to address and mitigate insider threat matters
Will conduct routine liaison with DHS and CISA counterparts to deter, detect, and mitigate insider threat activity.
Basic Qualifications:
Bachelors degree and (12)+ years of prior relevant insider threat experience or Masters with (10)+ years of prior relevant experience. Additional years of experience with requisite certifications will be considered in lieu of degree.
Minimum of 10 years demonstrated knowledge of the intelligence cycle, processes, and organizations.
Minimum 10 years demonstrated knowledge of various research tools and procedures and methods of analyzing, compiling, reporting and disseminating intelligence data and information.
Minimum of 10 years demonstrated knowledge of research and analytical techniques as applied to difficult and complex assignments in security, law enforcement, and counterintelligence analysis.
Possess a strong analytical background.
Possess a strong critical thinking Skills
Have excellent written and verbal skills with ability to deliver briefings/written products and reports to a diverse group of audiences.
Possess the ability to plan, coordinate, research and analyze all-source intelligence information for accuracy, timeliness, and relevance to mission.
Possess knowledge of current domestic and international threats to U.S. national security interests. Be adept at establishing networks with relevant security, personnel, and prevention stakeholders to foster program utilization.
Be a self-starter capable of working independently to promote program goals.
Working knowledge of User Activity Monitoring Software (UAM) and solutions.
Working knowledge of Cybersecurity toolsets designed to support ITP mission activities.
Working Knowledge of Open-Source toolsets.
Working Knowledge of Insider Threat Frameworks; Pathway to Violence & Critical Pathway
Current TS/SCI and Must be a US Citizen
Ability to obtain DHS EOD SCI and willingness to undergo CI Polygraph
Preferred Qualifications:
Master’s degree from an accredited college or university in Criminal Justice, Homeland Security, Cyber Security, or related field
Proven experience (10+ years) in Intelligence Analysis
Experience with User Activity Monitoring products and platforms
Certified Counter-Insider Threat Professional - Fundamentals (CCITP-F)
Certified Counter-Insider Threat Professional - Analysis (CCITP-A)
Completion of Center for Development of Security Excellence (CDSE) Insider Threat Detection Analysis Course (ITDAC)
Completion of Workplace Assessment of Violence Risk (WAVR-21) Workshop
Completion of Center for Development of Security Excellence (CDSE) Curriculums; INT311.CU/INT312.CU/CI201.CU
If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares.
For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.
The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.