Insider Threat Analyst

Insider Threat Analyst

25 Jan 2024
Virginia, Alexandria, 22301 Alexandria USA

Insider Threat Analyst

Vacancy expired!

Job Description

Mandiantis a recognized leader in cyber security expertise and has earned the trust of security professionals and company executives around the world. Our unique combination of renowned frontline experience, nation-state grade threat intelligence, machine intelligence, and the industry's best security validation ensures that FireEye knows more about today's advanced threats than anyone. Mandiant partners with Federal Governments across the globe to protect their national security interests, guarding nation-state secrets, and defending critical infrastructure from cyber-attacks. Our experience has provided us with a unique understanding of the challenges Federal Governments face, and we systematically align our solution and product development cycles to meet their needs. FireEye Mandiant isn’t just focused on one threat vector or adversary type. We counter all evolving cyber threats facing public and private sector organizations around the globe.

The Insider Threat Analyst will provide day-to-day insider threat subject matter expert services for federal and commercial clients. Focus will be on insider threat program build out, tool deployments, investigations, using strong problem-solving skills, and able to communicate effectively to people at various layers to assist leadership to make timely and well thought out decisions. This role will work cross-functionally with their peers on other teams such as intelligence and SOC analysts. This role is considered a subject matter expert for insider threat analysis.

What You Will Do:

  • Provide guidance on building and/or maturing insider threat programs, detecting and responding to computer security incidents, and implementation of tools and technologies used for enterprise security
  • Evaluate client needs, coordinate design for an insider threat solution, and clearly communicate the value proposition of implementation
  • Implement and/or assess existing security controls
  • Provide expert level knowledge of tools and technologies used for enterprise insider threat
  • Hands on analysis and insider threat investigations to include intelligence collection and forensics activities leveraging DLP, UBA, SIEM, EDR, and Mandiant proprietary tools
  • Maintain all client technology and Mandiant test labs, as appropriate
  • Primary work location: Reston, VA (Remote)

Qualifications

  • Excellent written and verbal communication skills
  • Bachelor’s degree in an IT-related field or equivalent experience
  • Provide expert experience building security programs to include hands-on implementation and/or assessment of security controls
  • Provide expert in-depth knowledge in collecting, analyzing, and escalating security events; responding to insider incidents, and/or collecting, analyzing, and disseminating insider threat intelligence
  • Interaction with C-level executives
  • Quickly master, simplify, and communicate the value proposition of complex subjects to clients
  • Use formal project management skills in planning, tracking, and reporting on project progress
  • Evaluate customer needs, coordinate design for an insider threat solution, and clearly communicate solutions
  • Thorough understanding of cyber security operations, event monitoring, backup tooling, and SIEM tools
  • Familiarity with security bypasses and backdoors to security controls as investigation points
  • Familiarity with cloud technologies such as Microsoft Azure and Amazon Web Services
  • Minimum of six years relevant in cybersecurity
  • Minimum of three years in use and system administration of insider threat tools such as SIEM, DLP, and UBA

Additional Qualifications:

  • Provide expert level knowledge of insider threat tools and technologies used for enterprise security
  • Bi-/Multi-lingual (languages of highest need include Spanish, Russian, Chinese, and Arabic)
  • Law Enforcement (LE) background is preferred
  • Intelligence background within DoD or equivalent is preferred

Additional Information

At FireEye we are committed to our #OneTeam approach combining diversity, collaboration, and excellence. All qualified applicants will receive consideration for employment without regard to race, sex, color, religion, sexual orientation, gender identity, national origin, protected veteran status, or on the basis of disability.

Related jobs

  • Description We are in search of a skilled Help Desk Analyst II in the Higher Education sector, based in Alexandria, Virginia. In this role, you will become an integral part of our technology team, dedicating your expertise to ensure that our users can effectively utilize our systems and tools to achieve their objectives. This role offers a contract to hire employment opportunity and requires proficiency in Citrix Technologies, Database, and EO/IR systems.

  • Summary This position is in the National Science Foundation (NSF), Office of the Director (OD), Office of Integrative Activities (OIA). The incumbent serves as a senior expert and advisor to the highest levels of NSF leadership for the use of technology in knowledge management and responds to NSF leadership, staff, and external stakeholders regarding NSF\'s most complex knowledge management challenges. Responsibilities As a Management & Program Analyst (Knowledge Management Technical Advisor), GS-0343-14, you will perform the following duties: Leads the establishment and oversight of NSF institutional vocabulary and data model (ontology) to be used for organizing and tagging knowledge artifacts to prepare the agency for smart search and retrieval and for the implementation of artificial intelligence and data-as-a-service. Serves as the agency authority to create and own the NSF policies and procedures relating to knowledge management & knowledge management technology. Represents top level leadership on complex matters involving knowledge management technology policies and procedures, involving both written and oral presentations. Serves as the project leader for Knowledge Management Technology and advises on technology architecture that accommodates NSF\'s knowledge management needs. The incumbent serves as a senior expert and advisor to the highest levels of NSF leadership for the use of technology in knowledge management and responds to NSF leadership, staff, and external stakeholders regarding NSF\'s most complex knowledge management challenges. Leads cross-functional, NSF-wide teams to build partnerships and develops business rules and requirements for NSF\'s knowledge management program needs. Serves as Contracting Officer Representative and key decision maker overseeing complex contracts critical to knowledge management technology at NSF. Acts as the NSF Liaison and facilitates workflow between subject matter experts, information technology experts, and data analysts of many varieties. Collaborates widely to build a clean, internal, NSF-wide policy database by adding historical and current policies with metadata to the current NSF document repository. Requirements Conditions of Employment You must be a US citizen. Selectee will be required to have a background investigation prior to onboarding. Selectee may be required to serve a 1-year trial/probationary period. Additional Requirements: Time in Grade Requirement: Applicants who have held a General Schedule (GS) position within the last 52 weeks must have 52 weeks of Federal service at the next lower grade/equivalent. You must meet eligibility & qualification requirements within 30 days of the closing date. You must answer all job-related questions in the NSF eRecruit questionnaire & any external assessment that is included. All online applicants must provide a valid email address. If your email address is inaccurate or your mailbox is full/blocked, you may not receive important communication that could affect your consideration for this position. Qualifications To qualify at the GS-14 level, you must have one year of specialized experience equivalent to the GS-13 Level in the federal service performing knowledge management activities for an organization. Examples of relevant knowledge management activities include: developing and implementing knowledge management policies or procedures; defining an organizational knowledge management strategy; researching and recommending technology to support knowledge management activities; defining institutional vocabulary; and providing recommendations to organizational leadership and staff regarding knowledge management tasks and functions. In addition to meeting the specialized experience above. Applicant must also meet the following selective placement factor below: Must possess a current FAC-COR Level II certification or, have completed the FAC-COR Level II (40-hour) training course, and possess one year of experience in order to be certified. One year of relevant experience would include the following: Performing market research, writing statements of work or statements of objectives, drafting independent government cost estimates, reviewing contract deliverables, participating as a subject matter expert on a technical evaluation team. You must submit documentation to confirm that you meet this requirement. Experience refers to paid/unpaid experience, including volunteer work done through National Service programs (e.g., Peace Corps, AmeriCorps) & other organizations (e.g., professional; philanthropic; religious; spiritual; community, student, social). Volunteer work helps build critical competencies, knowledge, & skills & can provide valuable training/experience that translates directly to paid work. You will receive credit for all qualifying experience, including volunteer experience. Education Education may enhance skills required for this position; however, no substitution of education for specialized experience may be made at this level. Additional Information Relocation Expenses will not be paid. This is a non-bargaining unit position. It is NSF policy that NSF personnel employed at or IPAs detailed to NSF are not permitted to participate in foreign government talent recruitment programs. Failure to comply with this NSF policy could result in disciplinary action up to & including removal from Federal Service or termination of an IPA assignment & referral to the Office of Inspector General. Foreign Talent Definitions Interagency Career Transition Assistance Program (ICTAP) ICTAP and CTAP provide eligible displaced Federal competitive service employees with selection priority over other candidates for competitive service vacancies. If your agency has notified you in writing that you are a displaced employee eligible for ICTAP or CTAP consideration, you may receive selection priority if: 1) this vacancy is within your ICTAP or CTAP eligibility; 2) you apply under the instructions in this announcement; and 3) you are found well-qualified for this vacancy. To be well-qualified you must meet the following: OPM qualification requirements for the position, all selective factors, where applicable; special OPM approved qualifying conditions for the position; is physically qualified with reasonable accommodation, where appropriate, to satisfactorily perform the duties of the position upon entry; and receives a rating of at least \"Very Good\" on the questionnaire. You must provide proof of eligibility with your application to receive selection priority. Such proof may include a copy of your written notification of ICTAP or CTAP eligibility, or a copy of your separation personnel action form. Additional information regarding ICTAP or CTAP eligibility is available from OPM\'s Career Transition Resources Veteran\'s Preference: If you are entitled to veterans\' preference, you should indicate the type of veterans\' preference you are claiming on your resume. Your veterans\' preference entitlement will be verified by the employing agency. For 5-point veterans\' preference, please provide your DD-214 (Certificate of Release or Discharge from Active Duty), official statement of service from your command if you are currently on active duty, or other official documentation (e.g., documentation of receipt of a campaign badge or expeditionary medal) that proves your military service was performed under honorable conditions. For 10-point veterans\' preference, please submit a Standard Form (SF) 15, Application for 10-Point Veteran Preference, DD-214, and the VA letter or other required documentation as specified on the SF-15. NSF has determined that all of its positions are eligible for telework. Work suitable for telework depends on job duties; therefore, employees must receive approval from their supervisor for telework and have a telework agreement in place. Entering into a telework agreement is voluntary. This announcement may be used to fill like positions in other organizations within the National Science Foundation.

  • Description

  • Description

  • Description

  • Description

  • Operations Analyst I / II - Alexandria

Job Details

  • ID
    JC8579971
  • State
  • City
  • Job type
    Full-time
  • Salary
    N/A
  • Hiring Company
    FireEye, Inc.
  • Date
    2021-01-18
  • Deadline
    2021-03-19
  • Category

Jocancy Online Job Portal by jobSearchi.