Insider Threat Technical Lead

Job not on LinkedIn

🔥 2 hours ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of 9th Way Insignia

9th Way Insignia

51 - 200 employees

Founded 2018

💼 Consulting

🏥 Healthcare

📦 Logistics

Consulting • Healthcare • Logistics

9th Way Insignia is a Service-Disabled Veteran-Owned Small Business (SDVOSB) that serves the federal government by delivering modern technology solutions and thought leadership. The company specializes in cybersecurity, automation, and data science to streamline operations and reduce costs for Federal agencies. By leveraging automation and artificial intelligence, 9th Way Insignia helps optimize workflows, eliminate redundancies, and enhance mission-critical operations, ensuring efficiency and significant savings for clients.

📋 Description

• Serve as the insider-risk technical lead and trusted advisor to USPTO stakeholders: run regular customer syncs, deliver polished status reporting, and proactively bring emerging requirements (CISA directives, NIST guidance, AI policy) to the customer with an implementation path. • Own the technical direction of the insider-risk toolset in Microsoft Purview: Insider Risk Management policies, indicators, trigger events, sequence detection, privacy/anonymization settings, role groups and permissions, DLP, sensitivity labels and auto-labeling, eDiscovery/legal holds, and unified audit log analysis. • Design and maintain custom dashboards, workbooks, and playbooks in Microsoft Sentinel; work across the program’s additional SIEMs (QRadar, Splunk) and custom Microsoft UBA rule engines; investigate and triage insider-risk alerts alongside the analysts and guide them on findings. • Build, edit, and troubleshoot Power Automate flows that drive program automation (the program currently operates 50+ production flows), using KQL, JSON, and YAML. • Advise the customer on securing Microsoft 365 Copilot adoption: Purview Data Security Posture Management, permission and sharing remediation, restricted content discovery, acceptable-use and DLP policy alignment, and NIST AI RMF alignment. • Define, track, and brief insider-risk program KPIs to leadership (alert volume and fidelity, true/false positive rates, MTTD/MTTR, repeat offenders, exfiltration channels, departmental trends) and recommend program improvements. • Mentor and technically guide the program’s insider-risk analysts; answer their questions on data findings and investigation paths. • Operate effectively in an environment where backend administration is held by government teams: the program performs front-end policy configuration and monitoring, and works through USPTO administrators for backend changes. Patience and influence without direct admin access are essential.

🎯 Requirements

• Bachelor's degree from an accredited institution in Information Technology, Computer Science, Information Systems Management, Cybersecurity, or a related field. • Seven (7) years of specialized experience in one or more of the following: Cyberspace Operations, Network Security, Computer Forensics, Network Forensics, Computer Network Defense (CND), Attack Sensing & Warning (AS&W), Intelligence Analysis, Cyber Threat Hunting, Penetration Testing, Insider Threat Detection/Mitigation, or Incident Detection & Response. Candidates holding a Master's degree from an accredited institution in information technology, information assurance, information systems management, cybersecurity, or a related field may substitute that degree for two (2) years of experience, reducing the requirement to five (5) years of specialized experience. • Primary certification — must currently hold one (1) of: CISSP or GIAC Security Expert (GSE). • Secondary certification — in addition to the primary certification above, must currently hold one (1) or more of: GIAC Certified Detection Analyst (GCDA); GIAC Certified Intrusion Analyst (GCIA); GIAC Certified Forensic Analyst (GCFA); GIAC Cyber Threat Intelligence (GCTI); GIAC Network Forensic Analyst (GNFA); GIAC Penetration Tester (GPEN); GIAC Reverse Engineering Malware (GREM). • Active SECRET clearance, or the ability to obtain and maintain one.

🏖️ Benefits

• Medical • Dental • Vision • Voluntary Life Insurance • 401(k) • Basic Life A&D • STD • LTD • PTO • Telehealth • Paid holidays • FSA • HSA • Employee Assistance Program (EAP) • Traveling Assistance

Apply Now

Similar Jobs

🔥 2 hours ago

EducationSuperHighway

11 - 50

📚 Education

🤝 Non-profit

📡 Telecommunications

Senior Software Engineer building an API-first full-stack platform connecting employers and employees for a non-profit's education philanthropy initiative. Opportunity for conversion to full-time after contract.

🔥 5 hours ago

Verve

501 - 1000

📣 Marketing

📱 Media

☁️ SaaS

Senior iOS Engineer leading iOS SDK development for Verve, a privacy-focused advertising technology company. Responsible for architecture, feature development, and collaboration across teams.

🇺🇸 United States – Remote

💵 $40 - $70 / hour

💰 $38M Post-IPO Equity - Verve on 2025-06

⏳ Contract/Temporary

🟠 Senior

🧑‍💻 Full-stack Engineer

🔥 6 hours ago

REW Technology

51 - 200

💼 Consulting

🤝 B2B

🤖 Artificial Intelligence

Sr Palantir Foundry Full Stack Developer on the Palantir Foundry platform. Building applications with front-end and back-end skills to develop comprehensive data-driven solutions.

🔥 6 hours ago

Secret Level

11 - 50

📱 Media

🤖 Artificial Intelligence

📣 Marketing

Full Stack Engineer building next-gen cloud-based platform for Hollywood film production. Collaborating with engineers and product teams to deliver innovative web experiences.

🔥 8 hours ago

Diversified Services Network, Inc.

51 - 200

💼 Consulting

🏛️ Government

🏥 Healthcare

Full Stack Developer needed for a remote contract position with a federal client. Involves designing, developing, and maintaining web applications across the full stack.