About The Position

Join Via Logic supporting U.S. Customs and Border Protection cybersecurity operations. As a Mid-Level Insider Threat Monitoring Analyst, you'll support insider threat monitoring activities by analyzing user behavior, access patterns, and security events to identify potential insider threat indicators. You'll use insider threat monitoring and security tools to identify anomalous activity, investigate alerts, and determine whether activity may represent an insider threat, data loss, or security policy concern. You'll also support security investigations and help document findings that protect sensitive information and government systems.

Requirements

  • 3+ years of relevant professional experience in cybersecurity operations, insider threat monitoring, security investigations, incident detection and response, cyber forensics, or a related area.
  • Experience analyzing user activity, security events, alerts, logs, or similar technical data to identify suspicious or anomalous behavior.
  • Experience investigating or supporting investigations involving security incidents, policy violations, data loss, or potentially unauthorized activity.
  • Knowledge of Data Loss Prevention (DLP), User Activity Monitoring (UAM), or similar security monitoring concepts and capabilities.
  • Ability to analyze information from multiple sources, identify relevant patterns or concerns, and document investigative findings clearly.
  • Ability to communicate technical findings and collaborate effectively with security analysts, investigators, government personnel, and other stakeholders.
  • Be a U.S. citizen.
  • Be able to obtain and maintain the required CBP background investigation and suitability determination for access to government facilities and systems.

Nice To Haves

  • Experience working within or closely alongside a Security Operations Center or insider threat program.
  • Hands-on experience with DLP or UAM tools and workflows.
  • Experience supporting cyber forensic or security investigations.
  • Experience investigating potential data exfiltration, sensitive-data spillages, or misuse of enterprise systems.
  • Experience developing or refining security alerting or detection logic based on investigative findings.

Responsibilities

  • Support insider threat monitoring activities by analyzing user behavior, access patterns, security events, and other relevant activity for potential insider threat indicators.
  • Monitor Data Loss Prevention (DLP) solutions and other applicable security tools to support insider threat and security operations investigations.
  • Investigate DLP alerts involving potential data exfiltration of CBP mission data or sensitive employee information.
  • Support User Activity Monitoring (UAM) activities and investigative tasks as directed by government staff.
  • Monitor network activity for potential misuse and security policy violations.
  • Analyze alerts and investigative information to identify suspicious or anomalous activity and support appropriate investigative action.
  • Support investigations involving potential malicious activity, alleged criminal activity, or unauthorized disclosure of information.
  • Support sensitive-data spillage response by helping assess incidents and recommending appropriate handling and sanitization methods in accordance with applicable guidance and procedures.
  • Monitor government laptops and mobile devices associated with foreign travel for suspicious activity and policy violations.
  • Recommend improvements to insider threat alert triggers and detections across security tools and logging sources.
  • Document investigative activity and contribute to incident notifications, case analysis, reports, and other required work products.

Benefits

  • Healthcare coverage
  • Paid time off
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service