Back to Jobs
Development Just now

Insider Threat Technical Lead

United StatesUnited States
Full-time
$155,000 — $185,000 USD
Senior-Level

Job Description

Key Skills Required

Master these to land this role

DevOpsBestseller 🔥
Learn in 63 Hours
QA EngineerBestseller 🔥
Learn in 10 Hours
BackendBestseller 🔥
Learn in 18 Hours
CybersecurityAutomation Engineer

Want to know if you're a match for this job?

Calculate My Match Score

Position Overview

9th Way Insignia is seeking a hands-on Insider Threat Technical Lead to serve as the technical lead for an established Insider Risk program supporting the United States Patent and Trademark Office (USPTO). This is an individual-contributor technical leadership role — not a management position. You will be the senior technical voice on a small delivery team, guiding insider-risk analysts, advising government data owners and program leadership, and personally building and tuning the Microsoft security tooling the program runs on.

What You Will Do

  • Serve as the insider-risk technical lead and trusted advisor to USPTO stakeholders: run regular customer syncs, deliver polished status reporting, and proactively bring emerging requirements (CISA directives, NIST guidance, AI policy) to the customer with an implementation path.
  • Own the technical direction of the insider-risk toolset in Microsoft Purview: Insider Risk Management policies, indicators, trigger events, sequence detection, privacy/anonymization settings, role groups and permissions, DLP, sensitivity labels and auto-labeling, eDiscovery/legal holds, and unified audit log analysis.
  • Design and maintain custom dashboards, workbooks, and playbooks in Microsoft Sentinel; work across the program’s additional SIEMs (QRadar, Splunk) and custom Microsoft UBA rule engines; investigate and triage insider-risk alerts alongside the analysts and guide them on findings.
  • Build, edit, and troubleshoot Power Automate flows that drive program automation (the program currently operates 50+ production flows), using KQL, JSON, and YAML.
  • Advise the customer on securing Microsoft 365 Copilot adoption: Purview Data Security Posture Management, permission and sharing remediation, restricted content discovery, acceptable-use and DLP policy alignment, and NIST AI RMF alignment.
  • Define, track, and brief insider-risk program KPIs to leadership (alert volume and fidelity, true/false positive rates, MTTD/MTTR, repeat offenders, exfiltration channels, departmental trends) and recommend program improvements.
  • Mentor and technically guide the program’s insider-risk analysts; answer their questions on data findings and investigation paths.
  • Operate effectively in an environment where backend administration is held by government teams: the program performs front-end policy configuration and monitoring, and works through USPTO administrators for backend changes. Patience and influence without direct admin access are essential.

Required Qualifications

  • Bachelor's degree from an accredited institution in Information Technology, Computer Science, Information Systems Management, Cybersecurity, or a related field.
  • Seven (7) years of specialized experience in one or more of the following: Cyberspace Operations, Network Security, Computer Forensics, Network Forensics, Computer Network Defense (CND), Attack Sensing & Warning (AS&W), Intelligence Analysis, Cyber Threat Hunting, Penetration Testing, Insider Threat Detection/Mitigation, or Incident Detection & Response. Candidates holding a Master's degree from an accredited institution in information technology, information assurance, information systems management, cybersecurity, or a related field may substitute that degree for two (2) years of experience, reducing the requirement to five (5) years of specialized experience.
  • Primary certification — must currently hold one (1) of: CISSP or GIAC Security Expert (GSE).
  • Secondary certification — in addition to the primary certification above, must currently hold one (1) or more of: GIAC Certified Detection Analyst (GCDA); GIAC Certified Intrusion Analyst (GCIA); GIAC Certified Forensic Analyst (GCFA); GIAC Cyber Threat Intelligence (GCTI); GIAC Network Forensic Analyst (GNFA); GIAC Penetration Tester (GPEN); GIAC Reverse Engineering Malware (GREM).
  • Active SECRET clearance, or the ability to obtain and maintain one.

How would you rate this job post?

See what other professionals think about this role.

Safety First

  • Never pay for a job application.
  • Do not share sensitive bank info.
  • Verify the client before starting work.
Learn More