Cyber Focused Operations Insider Threat Specialist (Remote)



Posted on Wednesday, January 17, 2024

Position Description:

CGI is in the top 5 largest global IT companies spread across 40 countries with endless opportunities to expand and grow. As a CGI Member, you have the opportunity to be a shareholder at CGI and join a family of 75,000 members strong. CGI Federal is seeking a Cyber Focused Operations Insider Threat Specialist to join our dynamic team.

We’re a close-knit team that has access to global resources. You’ll have the opportunity to explore a wide range of industries, technologies, and geographies, all while enjoying the personal touch that our local operating approach offers. Growth at CGI is driven by your goals, so if you were looking for an inclusive place where you’re empowered to chart your own path, then we’d love to meet you.

Your future duties and responsibilities:

• Proactively identify potential insider threats by monitoring, analyzing, and correlating data between various data sources.
o Conduct comprehensive all-source analysis in support of the Insider Threat mission Triage anomalous event data.

• Develop a plan to investigate suspected insider threats, including interviews, evidence collection and digital forensics.
o Examine recovered data for information of relevance to the issue at hand.
o Investigate alleged crime, violation, or suspicious activity utilizing computers and the Internet.
o Fuse computer network attack analyses with criminal and counterintelligence investigations and operations.

• Conduct and execute incident response plans to address insider threats, working in collaboration with IT, legal, and HR departments as necessary.
o Identify and/or determine whether a security incident is indicative of a violation of law that requires specific legal action.

• Collect and preserve digital and physical evidence related to insider threat incidents, ensuring chain of custody, and maintaining strict confidentiality.
o Extract and organize data relating to network monitoring, data analytics, security alerts and employee behavior.

• Analyze data to uncover patterns and anomalies in user activities to build profiles of potential insider threats.
o Access network monitoring, data analytics, and other tools integrate available information, decipher underlying trends and anomalies, and discern obscure patterns found in the datasets.

• Prepare comprehensive reports summarizing investigative findings, recommendations for remediation, and legal documentation if necessary.
o Prepare reports to document the investigation following legal standards and requirements.
o Produce situational awareness and warning reports related to Insider Threat

• Provide recommendations related to training and awareness programs to educate employees and contractors about insider threat risks and prevention measures.
o Determine the extent of threats and recommend courses of action or countermeasures to mitigate risks.
o Provide editing and quality control of program products.

• Assist in the development and enhancement f insider threat detection and response policies and procedures.
o Provide recommendations to contractor and government leadership on ways to improve the Insider Threat program.
o Conduct risk assessments and present findings to a variety of audiences, including very senior decision makers; written and oral presentations.

Required qualifications to be successful in this role:

BA or BS degree from an accredited undergraduate program
• Minimum of 5 years of experience in a Cyber Operations roles.
• Knowledge of Insider Threat investigations, reporting, investigative tools and laws/regulations.
• Skill in preserving evidence integrity according to standard operating procedures or national standards.
• Ability to examine digital media on multiple operating system platforms.
• Examine recovered data for information of relevance to the issue at hand
• Demonstrated experience with UAM capabilities
• Experience with:
o TCP/IP, Packet Analysis
o SIEM Operation
o Intrusion Detection Technology
• Experience with analytical problem solving and familiarity with conducting operations relating to insider threat
• Familiar with data analytics tools used for Insider Threat information collection or computer networks or knowledge of other Insider Threat risk scoring data analytics tools/programs
• Strong written and verbal communication skills, and the ability to create complex technical reports on analytic findings

• Familiar with Splunk preferred but not required

Due to the nature of the government contracts this position requires US Citizenship

This position can be located remotely anywhere in the U.S.

