Insider Threat Signature Developer
Job Description
Job Description
OVERVIEW:
A specialized security professional responsible for designing, implementing, and maintaining behavioral and rule-based signatures to detect insider threats. Collaborates with threat intelligence, security operations, and engineering teams to translate risk insights into actionable rules and automated responses. Works closely with business and IT stakeholders to identify critical assets and potential threat vectors and evaluate and recommend security technologies to improve the organization's insider threat posture.
GENERAL DUTIES:
- Design, implement, and maintain insider threat detection signatures tailored to organization data, user behavior, and access patterns.
- Translate threat intelligence and incident learnings into practical, testable signatures; continuously refine signals to reduce false positives.
- Collaborate with Insider Threat Program (ITP) stakeholders to align signatures with policies, acceptable use, and incident response playbooks.
- Validate and test signatures in controlled environments, document detection logic, data sources, and tuning parameters.
- Monitor performance and effectiveness of signatures; propose and implement improvements.
- Contribute to threat modeling exercises by mapping insider risk scenarios to measurable signals.
- Maintain versioned signature libraries, track changes and rollback plans.
- Participate in incident response, providing signature-based evidence and analytics to support investigations.
- Ensure signatures comply with privacy, legal, and data protection requirements.
- Regulatory Adherence: Ensure that all insider threat detection activities comply with relevant regulations, such as CNSS, ICDs, and industry-specific standards.
- Audits and Reviews: Participate in internal and external audits, providing evidence of compliance and effectiveness of insider threat triggers.
- Incident Investigation: Assist in the investigation of incidents related to insider threats, providing insights derived from triggers and alert analysis.
- Root Cause Analysis: Conduct root cause analysis to identify underlying issues and recommend corrective actions to prevent future occurrences.
- Remediation: Support the implementation of remediation measures based on the findings of incident investigations.
- Regular Reporting: Generate regular reports on the performance and effectiveness of insider threat triggers, highlighting key trends and insights.
- Metrics Development: Develop and track key performance indicators (KPIs) to measure the success of insider threat detection efforts.
REQUIRED QUALIFICATIONS:
- 8 years of experience in DoD/IC insider threat programs developing and testing signatures and rules to detect anomalous user and entity behaviors and validating those detections against real or simulated insider‑risk scenarios.
- Demonstrated application of ICS 500‑27 and CNSSD 504 requirements in the design and operation of insider threat capabilities.
- Proven program building experience, advanced detection strategies (including behavior analytics), and enterprise‑level governance of insider threat detection and response activities.
- Degree Requirements Masters Degree in related field or an additional 6 years of experience
- Certification Requirements: Must be DoD 8570 IAT Level III Certified
- Highly Desired: Certified Counter Insider Threat Professional (CCITPF/CCITPA)
CLEARANCE:
- TS/SCI
Recommended Jobs
Advanced Manufacturing Technical Specialist (Hiring Immediately)
Job Family : Technology Consulting Travel Required : Up to 25% Clearance Required : Ability to Obtain Secret What You Will Do: Join a high-performing consulting team tackling o…
Senior Web Application / Python Developer - DoD Program, Fort Belvior, VA
Job Description Job Description Salary: This is a Senior Web Application / Python Developer position for supporting a DoD program located in Fort Belvior, Virginia. Overview: We are …
Final Expense & Medicare Supplement Sales Agent
Location: Remote or In Person / Nationwide Employment Type: Full-time or Part-time About Us Team Nexa Insurance Solutions partners with some of the largest life insurance companies in the…
Developer - Integration/API Development - Contingent
About Aretum Aretum is a mission-driven organization committed to delivering innovative, technology-enabled solutions to our customers across defense, civilian, and homeland security sectors. Our …
Cleaners
Job Description Job Description Benefits: Competitive salary Opportunity for advancement Training & development Job Description: Office Pride Commercial Cleaning Services, one of…
Incident Manager III
Job Description Job Description About ARSIEM Corporation At ARSIEM Corporation we are committed to fostering a proven and trusted partnership with our government clients. We provide support t…
Licensed Veterinary Technician (LVT)
Seven Bends Veterinary Hospital seeking a Licensed Veterinary Technician (LVT) to join our team! We are willing to consider part-time and full-time applicants. If you are passionate about animals …
Mental Health Nurse Practitioner
Job Description Job Description Description: Valor Healthcare is looking for a passionate Mental Health Nurse Practitioner to join our team at the Community Based Outpatient Clinic (CBOC) in Dan…
Automotive Title Clerk
Loyalty Automotive is seeking an experienced title clerk to join our team Qualifications: Strong organizational skills and attention to detail Ability to work efficiently in a fast paced env…
Cooking Instructor (Part Time, After School, In-Person)
Schedule: Typically 1 hour per week for 10 weeks (after school); exact days/times vary by assignment Location: On-site at a partner school or community site; varies by assignment Start Date: …