Role Overview
Agile Defense is hiring a Insider Threat Analyst (TS). This is a full-time role in Washington, D.C.. posted 6 days ago. Full responsibilities, required qualifications, and the apply link are listed in the description below.
Resume Keywords to Include
Make sure these keywords appear in your resume to improve ATS scoring
Job description
About Agile Defense
At Agile Defense we know that action defines the outcome and new challenges require new solutions. That’s why we always look to the future and embrace change with an unmovable spirit and the courage to build for what comes next.
Our vision is to bring adaptive innovation to support our nation's most important missions through the seamless integration of advanced technologies, elite minds, and unparalleled agility—leveraging a foundation of speed, flexibility, and ingenuity to strengthen and protect our nation’s vital interests.
Requisition #:
Job Title: Insider Threat Analyst
Location: Onsite, Washington, DC
Clearance: Top Secret
DESCRIPTION
The Insider Threat Analyst supports the Insider Threat Program Detection and Prevention (ITPDP) effort, performing day-to-day detection, analysis, and triage of potential insider threat activity under the direction of the Senior Insider Threat Analyst. The analyst monitors and investigates alerts across multiple enterprise applications, distinguishing genuine insider threat incidents from false positives, and documents findings in accordance with established procedures. Working within an established program, the analyst applies both the technical and human dimensions of insider threat analysis while ensuring activities are conducted in accordance with applicable federal insider threat guidelines and with careful attention to employee privacy and civil liberties.
ESSENTIAL FUNCTIONS
· Monitor and analyze logs and alerts from multiple applications via dashboards and other means to determine whether activity represents an actual insider threat incident or a false positive.
· Triage and investigate potential insider threat indicators, escalating confirmed or ambiguous incidents to the Senior Insider Threat Analyst as appropriate.
· Support the configuration, tuning, and troubleshooting of application triggers used for insider threat detection in an enterprise environment.
· Assist with the deployment, operation, and maintenance of enterprise tools supporting insider threat detection.
· Document findings, produce clear analytical write-ups, and maintain case records in accordance with established reporting procedures.
· Correlate data across multiple sources to build a complete picture of potential insider threat activity.
· Support the development and refinement of workflows, playbooks, and program documentation.
· Conduct all activities in a manner that protects employee privacy and civil liberties and meets the legal requirements of an insider threat program.
· Coordinate with SOC, investigative, and other stakeholders as directed to support program objectives.
QUALIFICATIONS
· U.S. citizenship and ability to receive and maintain a security clearance at the Tier 5 level or higher.
· BS or BA degree, or additional related experience in lieu of a degree.
· Approximately 6 years of combined experience across cybersecurity, security operations, investigations, or insider threat analysis.
· Hands-on experience with one or more enterprise insider threat, DLP, SIEM, or UEBA/UAM tools (e.g., Splunk, DTEX, Proofpoint/ObserveIT, Microsoft Purview, Exabeam, or similar).
· Demonstrated ability to analyze logs and dashboards to differentiate real incidents from false positives.
· Working knowledge of Windows, Unix, and Linux environments and common insider threat indicators and behaviors.
· Familiarity with log analysis, event correlation, and basic investigative techniques, including awareness of digital forensics concepts.
· Understanding of the legal and ethical requirements of an insider threat program as they relate to privacy and civil liberties.
· Strong written communication for documenting findings, and the ability to work under the direction of senior analysts within an established program.
· Ability to obtain the Counter-Insider Threat Fundamentals Certification if required.
About Agile Defense
Agile Defense
agiledefense.com
86 other open roles at Agile Defense on TryApplyNow.
Frequently Asked Questions
How do I apply for the Insider Threat Analyst (TS) position at Agile Defense?
Use the Apply button above to submit your application directly to Agile Defense. Most applications take less than 5 minutes if your resume and contact details are ready, and you'll be routed to the employer's official application system to finish.
Where is the Insider Threat Analyst (TS) position at Agile Defense located?
This position is based in Washington, D.C.. Agile Defense has not indicated remote or hybrid options for this role, so candidates should plan for on-site work.
What does a Insider Threat Analyst (TS) at Agile Defense earn?
Agile Defense has not disclosed a salary range in this posting. Many employers share specifics later in the interview process; you can also ask during a recruiter screen if compensation transparency is important to you.
When was the Insider Threat Analyst (TS) role at Agile Defense posted?
This role was posted on July 15, 2026 (6 days ago). It's still listed as actively hiring; we re-confirm openings against the source system multiple times per day and remove closed roles.
More Jobs at Agile Defense
View all →AI-powered job search
Get every job scored to your resume
Upload your resume and get jobs ranked, your resume tailored, and employee contacts found automatically.
Get started freeNo credit card to start