Find Jobs
Find Jobs Near You – Available Work in Your Location
Insider Threat Support Analyst
Career Insights for Vulnerability Analyst / Penetration Tester
See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.
Scorecard
Based on Maryland data
Review key factors to help you decide if this role fits your goals. How is this calculated?
What they do
A Vulnerability Analyst or Penetration Tester probes for and exploits security vulnerabilities in web-based applications, networks and systems. Penetration Tests are designed to achieve a specific, attacker-simulated goal and should be requested by customers who are already at their desired security posture. A typical goal could be to access the contents of the prized customer database on the internal network, or to modify a record in an HR system. Vulnerability Assessments are designed to yield a prioritized list of vulnerabilities and are generally for clients who already understand they are not where they want to be in terms of security. The customer already knows they have issues and simply need help identifying and prioritizing them.
$121,766 / year median in Maryland
+3% projected growth
Job Description
DLP, SIEM
(Splunk), EDR/NDR, cloud storage, email, VPN/web, UAM (Teramind), and IAM logs. You will maintain prioritized insider use-case catalogs, apply defensible risk scoring, and collaborate with cross-functional teams to define requirements for automation-first playbooks, all while ensuring strict alignment with policy, privacy, civil liberties, and inspection requirements.Responsibilities:
Independently run daily operations, proactively identifying and triaging indicators of malicious, negligent, or coerced insider risk across multiple telemetry sources (DLP, SIEM, EDR/NDR, UAM, IAM). Conduct end-to-end, self-directed risk scoring and categorization of user activity. Document notable cases, gather evidence, and recommend containment actions without requiring step-by-step guidance. Work closely and dynamically within a small, specialized unit to share insights, cover operational gaps, and contribute insider updates to internal briefs and situational awareness (e.g., standups/shift changes). Proactively maintain and refine a prioritized insider use-case catalog. Take ownership of weekly coordination with Applied Intelligence and platform owners to adjust playbooks and update risk-scoring thresholds. Author Monthly InT Summaries focusing on insider-specific metrics, false positive trends, and emerging risk patterns. Act as the self-directed lead for designated case reviews to identify detection, process, and monitoring gaps. Independently utilize SPLUNK architecture and UI/GUI development skills to optimize data analysis workflows. Oversee User Activity Monitoring (UAM) tools like Teramind to support robust incident reporting.Basic Qualifications:
Must possess and maintain at least one active certification: Security+ orISC2 CISSP
(or other comparable certification approved in advance by the SOC PM). Bachelor's degree in Computer Science, Information Security, or a related field, OR a minimum of two (2) years of dedicated experience in insider threat detection, APT mitigation, and User Activity Monitoring (e.g., Teramind). 2+ years of experience with SPLUNK architecture (indexer, forwarder, search heads, etc.), including UI/GUI development and operational roles. Familiarity with DLP, EDR/NDR, and IAM logging. Must be a U.S. Citizen with an active Top Secret Clearance. Must meet SCI eligibility (ICD 704) with no waivers or conditions.Preferred Qualifications:
Proven track record as a self-starter with a demonstrated ability to establish task priorities, manage workflows, and deliver high-quality analytical products with minimal supervision. Experience working effectively in small, fast-paced team environments where cross-training, adaptability, and direct communication are critical. 3+ years of experience with SPLUNK architecture, UI/GUI development, and automation-first SOAR integrations. 3+ years of specific experience in insider threat detection, behavioral analytics, and mitigation techniques. Strong analytical and problem-solving skills, with the ability to dissect complex security incidents, assign defensible risk scores, and communicate findings effectively to technical and non-technical stakeholders. Proven ability to develop tactical metrics, monthly trend summaries, and strategic intelligence reports. Familiarity with privacy, civil liberties, and HR compliance considerations regarding insider threat monitoring. Evolver is an equal opportunity employer and welcomes all job seekers. It is the policy of Evolver not to discriminate based on race, color, ancestry, religion, gender, age, national origin, gender identity or expression, sexual orientation, genetic factors, pregnancy, physical or mental disability, military/veteran status, or any other factor protected by law. Actual salary will depend on factors such as skills, qualifications, experience, market and work location. Evolver offers competitive benefits, including health, dental and vision insurance, 401(k), flexible spending account, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies.Benefits
- Paid Time Off (PTO)
- 401(k) Plans
- Health Insurance
- Dental Insurance