Insider Threat Analyst

Apply Now ↗
🌍 Remote📍 San Antonio, TX, USOTHER

About this role

Overview

Abacus Technology is seeking an Insider Threat Analyst to provide technical support for the AFCENT Network Operations and Security Center (NOSC) at Lackland AFB.  This is a full-time position.

Responsibilities

  • Work with the AFCENT Insider Threat working group to establish a mature Insider Threat management capability, capable of detecting and reporting Insider Threats to relevant parties including (but not limited to) Commanders, Law Enforcement, Mental Health, Cybersecurity, Counter-Intelligence, Security, Civilian and Military personnel management, and Legal.
  • Support the AFCENT Insider Threat office and Office of Special Investigations (OSI) in their execution of the Command Insider Threat program.
  • Conduct Insider Threat Operations by leveraging available host, network, intelligence, and dynamic data acquisition technologies in order to identify, characterize, and counter Insider Threats.
  • Employ User Activity Monitoring (UAM) capabilities to detect anomalous insider activity.
  • Conduct auditing and data collection in support of Insider Threat cases and investigations.
  • Provide on-site support and on-call response to operate, maintain, and audit UAM tools for all network locations provided by the Authorizing Official (AO).
  • Perform analysis of findings developed by OSI and supporting organizations during insider threat operations.
  • Develop metrics and trends to identify internal cyber threat actors attempting to commit espionage or attempting to compromise IS located at all network locations under the AOs responsibility.
  • Conduct tuning of UAM tools IAW DoD, OSD, and Air Force guidance.
  • Work with Cybersecurity Engineering personnel to O&M of UAM tools.
  • Provide relevant data and briefing support to the Command Insider Threat office.
  • Participate and provide support to the AFCENT Insider Threat working group.
  • Work with the AFCENT Insider Threat Working Group to identify thresholds and create Insider Threat triggers.

Qualifications

5+ years experience in security.  Bachelor’s degree in a related field.  Additional years of experience may be substituted for degree requirements.  Must be Security+ certified.  Must hold the ITIL Foundations certification or be able to obtain the certification within 60 days of hire.  Experience configuring and validating network workstations and peripherals in accordance with approved standards and/or specifications.  Must possess experience and demonstrate an understanding with installation of Microsoft Windows Server in Host and Compute Environments, and Windows Server using server images.  Experience with implementation of storage solutions, high availability, Domain Name Systems (DNS), Dynamic Host Configuration Protocol (DHCP), network connectivity and remote access solutions, core and distributed network solutions, advance network infrastructure, and maintain and monitor server environments.  Must be able to provide support in a 24/7/365 environment including occasionally covering shifts outside of the assigned shift and/or providing after hours, weekend, or holiday support as needed on a rotational basis.  Must be able to travel to CONUS sites to provide TDY support.  Must be a US citizen and hold a current Top Secret clearance with SCI Access (TS/SCI).

 

Applicants selected will be subject to a U.S. government security investigation and must meet eligibility requirements for access to classified information.

 

EOE/M/F/Vet/Disabled

Frequently Asked Questions

Is the salary disclosed for the Insider Threat Analyst position at abacustech?
The salary for this Insider Threat Analyst role at abacustech is not publicly listed. Click "Apply Now" to learn more about the compensation package on their official careers page.
Is the Insider Threat Analyst job at abacustech remote?
Yes, this Insider Threat Analyst position at abacustech is remote, with team members based in San Antonio, TX, US. You can work from home or anywhere in the supported regions.
Is the Insider Threat Analyst role at abacustech full-time or part-time?
This is listed as a OTHER position. It is posted as a Insider Threat Analyst role at abacustech.
How do I apply for the Insider Threat Analyst position at abacustech?
Click the "Apply Now" button on this page. You will be redirected to abacustech's official application portal hosted on icims where you can submit your application directly.
When was the Insider Threat Analyst job at abacustech posted?
This Insider Threat Analyst position at abacustech was posted on Jul 9, 2026. Apply as soon as possible — early applications are often reviewed first.
Insider Threat Analyst
abacustech
Apply for this role ↗

You'll be redirected to abacustech's official application page on icims.