Tallo logoTallo logo

Insider Threat Monitoring Lead

Job

SOSi

Ashburn, VA (In Person)

Full-Time

Posted 02/27/2026 (Updated 7 weeks ago) • Actively hiring

Expires 5/27/2026

Apply for this opportunity

This job application is on an outside website. Be sure to review the job posting there to verify it's the same.

Review key factors to help you decide if the role fits your goals.
Pay Growth
?
out of 5
Not enough data
Not enough info to score pay or growth
Job Security
?
out of 5
Not enough data
Calculating job security score...
Total Score
78
out of 100
Average of individual scores

Were these scores useful?

Skill Insights

Compare your current skills to what this opportunity needs—we'll show you what you already have and what could strengthen your application.

Job Description

Company DescriptionFounded in 1989, SOSi is among the largest private, founder-owned technology and services integrators in the defense and government services industry. We deliver tailored solutions, tested leadership, and trusted results to enable national security missions worldwide.

Job Description•This position is contingent upon contract award•SOSi is seeking highly qualified Insider Threat Monitoring Lead to support a DHS enterprise cybersecurity program providing 24/7 Security Operations Center (SOC) services. These roles deliver leadership, operational oversight, and technical expertise across cyber defense, incident response, intelligence, engineering, and modernization activities.

Job DescriptionLeads insider-threat detection and user activity monitoring; integrates behavioral analytics and investigative workflows to identify and mitigate internal risks to CBP systems and data.

ResponsibilitiesConduct user activity monitoring and behavioral analysis to detect insider threats.

Correlate endpoint, network, and identity data to identify anomalous behavior.

Support investigative workflows in coordination with forensics, CI, and OPR stakeholders.

Develop insider-threat dashboards, alerts, and analytic use cases.

Provide reporting and briefings on insider-threat trends and incidents.
QualificationsExperience:
8+ years supporting insider threat, user activity monitoring, or behavioral analytics in SOC or CI environments.
Tools:
Insider-threat platforms, UEBA, SIEM, DLP, EDR, and case management systems.
Certifications:
CISSP, GCIH, GCFA, or insider-threat-related certification preferred.
Clearance:
TS, SCI-eligible.

Additional InformationWork EnvironmentNormal office conditions with potential to perform duties in various CONUS locations.

Core hours of operation are Monday through Friday, 0600 - 1700.May be requested to work evenings and weekends to meet program and contract needs.

Working at SOSiAll interested individuals will receive consideration and will not be discriminated against for any reason.

Similar remote jobs

Similar jobs in Ashburn, VA

Similar jobs in Virginia