Back to Jobs
United States
Development Just now
Insider Threat Technical Lead
United StatesFull-time
$155,000 — $185,000 USD
Senior-Level
Be the first applicant! 🚀
Job Description
Key Skills Required
Master these to land this role
DevOpsBestseller 🔥
Learn in 63 HoursQA EngineerBestseller 🔥
Learn in 10 HoursBackendBestseller 🔥
Learn in 18 HoursCybersecurityAutomation Engineer
Want to know if you're a match for this job?
Position Overview
9th Way Insignia is seeking a hands-on Insider Threat Technical Lead to serve as the technical lead for an established Insider Risk program supporting the United States Patent and Trademark Office (USPTO). This is an individual-contributor technical leadership role — not a management position. You will be the senior technical voice on a small delivery team, guiding insider-risk analysts, advising government data owners and program leadership, and personally building and tuning the Microsoft security tooling the program runs on.
What You Will Do
- Serve as the insider-risk technical lead and trusted advisor to USPTO stakeholders: run regular customer syncs, deliver polished status reporting, and proactively bring emerging requirements (CISA directives, NIST guidance, AI policy) to the customer with an implementation path.
- Own the technical direction of the insider-risk toolset in Microsoft Purview: Insider Risk Management policies, indicators, trigger events, sequence detection, privacy/anonymization settings, role groups and permissions, DLP, sensitivity labels and auto-labeling, eDiscovery/legal holds, and unified audit log analysis.
- Design and maintain custom dashboards, workbooks, and playbooks in Microsoft Sentinel; work across the program’s additional SIEMs (QRadar, Splunk) and custom Microsoft UBA rule engines; investigate and triage insider-risk alerts alongside the analysts and guide them on findings.
- Build, edit, and troubleshoot Power Automate flows that drive program automation (the program currently operates 50+ production flows), using KQL, JSON, and YAML.
- Advise the customer on securing Microsoft 365 Copilot adoption: Purview Data Security Posture Management, permission and sharing remediation, restricted content discovery, acceptable-use and DLP policy alignment, and NIST AI RMF alignment.
- Define, track, and brief insider-risk program KPIs to leadership (alert volume and fidelity, true/false positive rates, MTTD/MTTR, repeat offenders, exfiltration channels, departmental trends) and recommend program improvements.
- Mentor and technically guide the program’s insider-risk analysts; answer their questions on data findings and investigation paths.
- Operate effectively in an environment where backend administration is held by government teams: the program performs front-end policy configuration and monitoring, and works through USPTO administrators for backend changes. Patience and influence without direct admin access are essential.
Required Qualifications
- Bachelor's degree from an accredited institution in Information Technology, Computer Science, Information Systems Management, Cybersecurity, or a related field.
- Seven (7) years of specialized experience in one or more of the following: Cyberspace Operations, Network Security, Computer Forensics, Network Forensics, Computer Network Defense (CND), Attack Sensing & Warning (AS&W), Intelligence Analysis, Cyber Threat Hunting, Penetration Testing, Insider Threat Detection/Mitigation, or Incident Detection & Response. Candidates holding a Master's degree from an accredited institution in information technology, information assurance, information systems management, cybersecurity, or a related field may substitute that degree for two (2) years of experience, reducing the requirement to five (5) years of specialized experience.
- Primary certification — must currently hold one (1) of: CISSP or GIAC Security Expert (GSE).
- Secondary certification — in addition to the primary certification above, must currently hold one (1) or more of: GIAC Certified Detection Analyst (GCDA); GIAC Certified Intrusion Analyst (GCIA); GIAC Certified Forensic Analyst (GCFA); GIAC Cyber Threat Intelligence (GCTI); GIAC Network Forensic Analyst (GNFA); GIAC Penetration Tester (GPEN); GIAC Reverse Engineering Malware (GREM).
- Active SECRET clearance, or the ability to obtain and maintain one.
How would you rate this job post?
See what other professionals think about this role.
Safety First
- Never pay for a job application.
- Do not share sensitive bank info.
- Verify the client before starting work.