Search

Cyber Threat Investigator

PublishedPublished: 6/14/2022
Technology

Job Description

Redhawk Federal is looking for a Cyber Investigations Analyst to become part of our Federal Strategic Cyber Group.

\n


\n

Location: Rosslyn, VA; full-time, on-site role.

\n


\n

In this role, you will:

\n

    \n
  • Support the Cyber Threat Investigations & Analysis Division (CTAD) in conducting end-to-end insider threat and cyber investigations leveraging User Activity Monitoring (UAM) tools and data.
  • \n

  • Collect, analyze, and interpret log data to detect anomalous user behavior, policy violations, and potential insider threats across enterprise systems.
  • \n

  • Develop and refine detection rules, alerts, and behavioral baselines to improve threat detection capabilities.
  • \n

  • Conduct forensic analysis of user activity logs, endpoint telemetry, and network data to support investigations and produce actionable intelligence.
  • \n

  • Communicate complex investigative findings to both technical and non-technical stakeholders, including senior management.
  • \n

  • Collaborate with legal, HR, and security teams to ensure investigations are conducted in accordance with applicable laws, policies, and Department guidelines.
  • \n

  • Author detailed investigation reports, bulletins, and advisories documenting findings.
  • \n

  • Promote awareness of insider threat indicators and UAM best practices among customer stakeholders, coworkers, and Department users.
  • \n

  • Respond to escalated security incidents and provide expert guidance on user activity-related threat vectors.
  • \n

  • Manage case documentation and investigative records in SharePoint repositories.
  • \n

  • Provide guidance and mentorship to junior team members on investigative techniques and tool usage.
  • \n

  • Stay current on emerging insider threat tactics, techniques, and procedures (TTPs) and incorporate findings into detection strategies.
  • \n

\n


\n

QUALIFICATIONS

\n

Minimum requirements:

\n


\n

    \n
  • A Bachelor’s degree and 5 years of experience. An additional 4 years of experience may be substituted in lieu of the bachelors degree requirement.
  • \n

  • Minimum of 2 years experience in cybersecurity, digital forensics, or cyber investigations.
  • \n

  • Must either possess and maintain, or obtain prior to start date, one of the following professional certifications:
  • \n

  • CISSP-ISSAP; CISSP-ISSEP; CISSP; Security+ CE; CySA+; PPDA; Agile IC; SNOW App Dev
  • \n

  • Experience conducting insider threat or cyber misconduct investigations in an enterprise environment.
  • \n

  • Experience analyzing large datasets of user activity, log data, and endpoint telemetry.
  • \n

  • Strong analytical, problem-solving, and decision-making skills to support complex, sensitive investigations.
  • \n

  • Excellent written and verbal communication skills, including experience producing formal investigative reports.
  • \n

  • Must possess strong time management skills and the ability to complete assigned tasks with minimal supervision.
  • \n

  • U.S. citizenship required.
  • \n

  • Active Top Secret security clearance.
  • \n

  • Ability to obtain a final Top Secret/SCI security clearance.
  • \n

\n


\n

Desired:

\n

    \n
  • Experience with insider threat programs and familiarity with the National Insider Threat Policy.
  • \n

  • Familiarity with SIEM platforms (e.g., Splunk, Microsoft Sentinel) for correlating UAM data with broader security telemetry.
  • \n

  • Experience with digital forensics tools (e.g., EnCase, FTK, Magnet AXIOM).
  • \n

  • Knowledge of Active Directory and Azure AD for user account analysis.
  • \n

  • Experience working in a government or federal law enforcement investigative environment.
  • \n

  • Technical writing skills and experience producing materials for senior leadership audiences.
  • \n

  • Familiarity with chain of custody procedures, and eDiscovery processes.
  • \n

  • Experience with behavioral analytics platforms or UEBA (User and Entity Behavior Analytics) tools.
  • \n

\n


Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...