Talent.com
Insider Threat Engineer

Insider Threat Engineer

Leidos IncBaltimore, MD, United States
job_description.job_card.variable_hours_ago
serp_jobs.job_preview.job_type
  • serp_jobs.job_card.full_time
job_description.job_card.job_description

Description

Leidos is seeking a highly skilled and experienced Insider Threat Engineer to support and maintain an enterprise-wide insider threat detection and response program at the Social Security Administration (SSA) . This position focuses on advancing the agency's capabilities in user activity monitoring (UAM), automation, data loss prevention (DLP-Trellix), automation, and technical threat detection to prevent unauthorized disclosures, fraud, and abuse.. The candidate will be instrumental in delivering analytical and engineering support to the Insider Threat Program Management Office (PMO) and may be required to deliver and receive sensitive briefings within SSA secured spaces such as the SCIF or approved alternate secure locations.

Join a high-performing cybersecurity team responsible for safeguarding the agency's data and supporting the SSA's mission to serve over 65 million Americans monthly.

If this sounds like a mission you want to be a part of, keep reading!

TEAM CULTURE

Your passion and values might be a good fit for our teams if you answer "yes" to the following questions :

Are you looking for a company that puts employees first, with a focus on career, flexibility, and well-being?

Do you enjoy collaborating with colleagues and teammates and believe that the best ideas are fostered in an inclusive environment?

Are you searching for a team with a strong sense of ownership, urgency, and drive for daily mission success?

Are you comfortable with proactive outward communication and technical leadership?

Do you enjoy being a catalyst, solving complex problems, and providing innovative solutions?

Do you have the flexibility, creativity, and resilience to pivot the mission for success?

Do you have the courage to make tough ethical decisions with pride, transparency, and respect?

MENTORSHIP & CAREER GROWTH

Our teams are dedicated to supporting new team members in an environment that celebrates knowledge sharing and mentorship. Experienced team members will be assigned to new hires for one-on-one mentoring, collaborative reviews, and coaching on customer engagement to help each new hire successfully onboard and demonstrate their skills. Projects and tasks are assigned in a way that leverages your strengths and will help you further develop your skillset.

KEY RESPONSIBILITIES

Every position we take is more rewarding when you know the why behind it.Know your work makes a difference to support those who need it most. If your passion is enabling life changing service to those around, you this is the place for you. Find you passion in a team environment where all members are valued regardless of contractor or employee status. Find your "Why" with us and take your place in our Leidos Family!!

Technical Engineering and Automation

Engineer, implement, and maintain User Activity Monitoring (UAM) and Data Loss Prevention (DLP) solutions, ensuring continuous visibility into user behavior and sensitive data usage.

Configure, maintain, and optimize Trellix endpoint security and DLP capabilities for insider threat use cases.

Experience leveraging Trellix DLP to detect and investigate insider threat behaviors, including sensitive data exfiltration, unauthorized file transfers, and anomalous user activity.

Automate detection, alerting, and reporting processes using Python, Ansible, or JSON to increase efficiency and accuracy.

Integrate UAM and DLP solutions with other enterprise cybersecurity tools (e.g., SIEM, SOAR, EDR, Trellix platform).

Develop dashboards and reports that highlight key insider threat indicators, anomalous activity, and program performance metrics.

Perform SOC related activities including monitoring, triaging, and investigating insider threat and DLP alerts to support timely detection and response.

Basic understanding in networking, cybersecurity principles, and experience with common security tools (e.g., firewalls, SIEM, DLP, endpoint security, vulnerability scanners).

Experience with Splunk for log analysis and developing use cases to support insider threat detection and reporting.

Demonstrated adaptability with an open mind toward learning new technologies and taking on challenging responsibilities in a dynamic environment.

Cyber Threat Detection & Analysis

Develop and refine methods to extract, analyze, and correlate data from SSA IT systems to proactively detect potential insider threats.

Monitor and analyze trends in cyber activity and anomalous behavior to assess risks to SSA's confidentiality, availability, and integrity.

Leverage feeds, incident reports, and threat briefs to assess relevance to SSA's environment and enhance the program's threat modeling capability.

Policy, SOP Development & Reporting

Prepare and present insider threat briefings to program leadership and executives, following agency writing and presentation standards.

Contribute to Insider Threat Work Status Reports with detailed analytics, visuals (charts / dashboards), and recommendations.

FOUNDATION FOR SUCCESS ( Basic Qualifications )

Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field.

Proven experience in cybersecurity, DLP - Trellix or Palo altos, or a related area.

Hands-on experience with Trellix Data Loss Prevention (DLP) for monitoring, detecting, and controlling sensitive data movement across endpoints, email, and network channels.

Good understanding of networking and firewall fundamentals , including how monitoring tools interact across segmented architectures.

Familiarity with Palo Alto Networks firewalls and their logging capabilities (useful for correlating user activity across layers).

Strong analytical and problem-solving skills; ability to make data-driven recommendations.

Excellent written and verbal communication skills, particularly in conveying technical insights to leadership.

Must be able to obtain and maintain a Public Trust. Contract requirement.

  • Selected candidate must be willing to work on-site in Woodlawn, MD 5 days a week.

FACTORS TO HELP YOU SHINE ( Required Skills )

Experience in using Splunk ES or enterprise Splunk is a plus.

Ability to make decisions based upon analysis of documentation.

Experience with endpoint monitoring tools , SIEM / SOAR integrations , and identity-based risk scoring .

Working knowledge of DLP , EDR , or behavioral analytics platforms in support of insider threat detection.

Experience working in a classified environment and delivering briefings in SCIF settings.

Understanding of NIST 800-53 and related to Insider Threat Programs.

HOW TO STAND OUT FROM THE CROWD (Desired Skills)

Showcase your knowledge of modern development through the following experience or skills :

Experience with federal regulatory requirements and compliance standards related to cybersecurity.

Knowledge of programing, Splunk automation, network and firewall operations.

Familiarity with security tools and technologies used for threat detection and analysis.

Security certifications (e.g., CISSP, CISM, CEH, CompTIA Security+) are a plus.

At Leidos, we deliver innovative solutions through the efforts of our diverse and talented people who are dedicated to our customers' success. We empower our teams and contribute to our communities. Everything we do is built on a commitment to do the right thing for our customers, our people, and our community. Our Mission, Vision, and Values guide the way we do business. Every position we take is more rewarding when you know the why behind it.Know your work makes a difference to support those who need it most. If your passion is enabling life changing service to those around, you this is the place for you. Find your passion in a team environment where all members are valued regardless of contractor or employee status. We are excited for you to take your place in our Leidos Family.

Are you an US citizen, US resident, or Visa candidate and think you might fit? We recommend you apply and start the conversation today! Join us in supporting our SSA contracts in Woodlawn, Maryland.

At Leidos, we don't want someone who "fits the mold"-we want someone who melts it down and builds something better. This is a role for the restless, the over-caffeinated, the ones who ask, "what's next?" before the dust settles on "what's now."

If you're already scheming step 20 while everyone else is still debating step 2... good. You'll fit right in.

Original Posting : September 9, 2025

For U.S. Positions : While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

Pay Range :

Pay Range $85,150.00 - $153,925.00

The Leidos pay range for this job level is a general guideline onlyand not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

serp_jobs.job_alerts.create_a_job

Insider Threat Engineer • Baltimore, MD, United States

Job_description.internal_linking.related_jobs
  • serp_jobs.job_card.promoted
Threat Analyst

Threat Analyst

Independent SoftwareFort Meade, MD, US
serp_jobs.job_card.full_time
As a Threat Analyst at Independent Software, you will analyze and assess potential risks to missions, personnel, and facilities by leveraging data from multiple systems and information sources.You ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
Computer Network Defense (CND) Analyst

Computer Network Defense (CND) Analyst

CTC GroupFort Meade, MD, US
serp_jobs.job_card.full_time
serp_jobs.filters_job_card.quick_apply
Summary CTC Group is seeking Computer Network Defense (CND) Analysts, levels 1-4, to use information collected from a variety of computer network defense resources (including, but not limited...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
Vulnerability Management Team Lead - NIH

Vulnerability Management Team Lead - NIH

cFocus Software IncorporatedRockville, MD, US
serp_jobs.job_card.full_time
serp_jobs.filters_job_card.quick_apply
Vulnerability Management Team Lead Overview cFocus Software is seeking an experienced Vulnerability Management Team Lead to oversee the development, execution, and continuous improvement of a compr...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
  • serp_jobs.job_card.promoted
FIPS Security Engineer

FIPS Security Engineer

LeidosColumbia, MD, US
serp_jobs.job_card.full_time
A FIPS Security Engineer is a technical position within Leidos’ Cryptographic and Security Testing Lab (CSTL) which is part of the Leidos’ Accredited Testing & Evaluation (AT&E)...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
  • serp_jobs.job_card.promoted
Senior Cyber Security Engineer

Senior Cyber Security Engineer

Chenega CorporationWashington, DC, United States
serp_jobs.job_card.full_time
Hybrid, must reside in the Washington D.Chenega Services & Federal Solutions, LLC,.Senior Cyber Security Engineer.Power Apps, Power BI, and Power Automate experience. IT experts supporting a federal...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
  • serp_jobs.job_card.promoted
Mid Cyber Counterintelligence Desk Officer

Mid Cyber Counterintelligence Desk Officer

Clearance JobsFort George G Meade, MD, US
serp_jobs.job_card.full_time
Mid Cyber Counterintelligence Desk Officer.Prescient Edge is seeking a Mid Cyber Counterintelligence Desk Officer to support a Federal government client. As a Mid Cyber Counterintelligence Desk Offi...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
  • serp_jobs.job_card.promoted
Senior Security Architect

Senior Security Architect

TradeJobsWorkForce22243 Arlington, VA, US
serp_jobs.job_card.full_time
Senior Security Architect Job Duties : Enhances security team accomplishments and competence by planning deliver...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
Security Architect

Security Architect

TriTech Enterprise Systems, Inc.lanham, MD, US
serp_jobs.job_card.full_time
serp_jobs.filters_job_card.quick_apply
ACTIVE IRS MBI OR DoD Top Secret CLEARANCE IS REQUIRED TO BE SUBMITTED FOR CONSIDERATION FOR THIS POSITION TriTech Enterprise Systems, Inc. TriTech) is seeking a 'Security Architect' to support a Fe...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_1_day
  • serp_jobs.job_card.promoted
Cyber Security Engineer

Cyber Security Engineer

Via Logic LLCBethesda, MD, United States
serp_jobs.job_card.full_time
Leidos has an exciting opening for you, our next.TS / SCI Cyber Security Engineer.Task Orders under the DOMEX Technology Platform (DTP) contract supporting NMEC. Have impact as part of a mission focus...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
  • serp_jobs.job_card.promoted
  • serp_jobs.job_card.new
Senior Cyber Capabilities Integrator

Senior Cyber Capabilities Integrator

Leidos IncOdenton, MD, United States
serp_jobs.job_card.full_time
Looking for an opportunity to make an impact?.At Leidos, we deliver innovative solutions through the efforts of our diverse and talented people who are dedicated to our customers' success.We empowe...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours
  • serp_jobs.job_card.promoted
  • serp_jobs.job_card.new
Cyber Capabilities SME

Cyber Capabilities SME

Leidos IncOdenton, MD, United States
serp_jobs.job_card.full_time
The Cybersecurity Capabilities and Innovations SME shall provide support across the entire command.All SMEs will be centrally managed but may be assigned to work in separate directorates within the...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours
  • serp_jobs.job_card.promoted
Cyber Technical Lead - Security Clearance Required

Cyber Technical Lead - Security Clearance Required

MaximusAnnapolis Junction, MD, United States
serp_jobs.job_card.full_time
Maximus is seeking a highly skilled Cyber Technical Lead to support a contract with a Homeland Security customer.The successful candidate will provide strategic and technical leadership in cybersec...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
  • serp_jobs.job_card.promoted
  • serp_jobs.job_card.new
Splunk Security Engineer

Splunk Security Engineer

Leidos IncSuitland, MD, United States
serp_jobs.job_card.full_time
Are you ready to turn your skills into real-world impact? Join.Suitland, MD and be at the forefront of mission-critical cybersecurity. From defending networks to building scalable automation, your w...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours
  • serp_jobs.job_card.promoted
Enterprise Security Architect

Enterprise Security Architect

OktaWashington, DC, United States
serp_jobs.job_card.full_time
Okta is The World's Identity Company.We free everyone to safely use any technology, anywhere, on any device or app.Our flexible and neutral products, Okta Platform and Auth0 Platform, provide secur...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_1_day
Senior Security Architect

Senior Security Architect

DirectViz Solutions, LLCRemote, VA, USA
serp_jobs.filters.remote
serp_jobs.job_card.full_time
serp_jobs.filters_job_card.quick_apply
DirectViz Solutions, (DVS) is a rapidly growing government contractor that provides strategic services that meet mission IT needs for government customers. DVS provides innovative information techno...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
  • serp_jobs.job_card.promoted
  • serp_jobs.job_card.new
Project Manager - Cybersecurity

Project Manager - Cybersecurity

ASSYSTAnnapolis, MD, US
serp_jobs.job_card.full_time
The Project Manager will lead and coordinate cybersecurity assessment initiatives across state agencies to strengthen and standardize security maturity. This role oversees the execution of NIST Cybe...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours
  • serp_jobs.job_card.promoted
Global Threat Analyst

Global Threat Analyst

GoogleWashington, DC, US
serp_jobs.job_card.full_time
Security is at the core of Google's design and development process : it is built into the DNA of our products.The same is true of our offices. You're an expert who shares our seriousness about securi...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
  • serp_jobs.job_card.promoted
  • serp_jobs.job_card.new
FIPS Security Engineer

FIPS Security Engineer

Leidos IncColumbia, MD, United States
serp_jobs.job_card.full_time
A FIPS Security Engineer is a technical position within Leidos' Cryptographic and Security Testing Lab (CSTL) which is part of the Leidos' Accredited Testing & Evaluation (AT&E) Lab providing valid...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours