· U.S. citizenship and ability to receive and maintain a security clearance at the Tier 5 level or higher.
· BS or BA degree, or additional related experience in lieu of a degree.
· Approximately 6 years of combined experience across cybersecurity, security operations, investigations, or insider threat analysis.
· Hands-on experience with one or more enterprise insider threat, DLP, SIEM, or UEBA/UAM tools (e.g., Splunk, DTEX, Proofpoint/ObserveIT, Microsoft Purview, Exabeam, or similar).
· Demonstrated ability to analyze logs and dashboards to differentiate real incidents from false positives.
· Working knowledge of Windows, Unix, and Linux environments and common insider threat indicators and behaviors.
· Familiarity with log analysis, event correlation, and basic investigative techniques, including awareness of digital forensics concepts.
· Understanding of the legal and ethical requirements of an insider threat program as they relate to privacy and civil liberties.
· Strong written communication for documenting findings, and the ability to work under the direction of senior analysts within an established program.
· Ability to obtain the Counter-Insider Threat Fundamentals Certification if required.