Job Requirements
Stuttgart, Germany
Top Secret/SCI Polygraph Unspecified
Career Level not specified
Salary not specified
Join Premium to unlock estimated salaries
Job Description
DESCRIPTION
Job Title: User Activity Monitoring (UAM) Analyst
Location: Patch Barracks Stuttgart, Germany
Clearance: TS/SCI
Job Description:
Mission Essential is seeking a skilled User Activity Monitoring Analyst in Germany to play a key role in safeguarding our digital environment by detecting risks, analyzing user behavior, and supporting a strong security culture. The UAM Analyst will provide near real time detection and analysis of User Activity on both USEUCOM NIPRNet, and SIPRNet, supporting command action, investigations, and operational security. The UAM Analyst is critical to the detection and mitigation of insider threats, behavioral risks, and users who misuse the IT systems. The UAM Analytical Cell will triage data of anomalous events collected by the UAM tool and produce Report of Issue (ROI) and Analytical Findings that document issues on behaviors, computer misuse and violations of polices. Duties and responsibilities include but are not limited to:
REQUIREMENTS
Minimum Qualifications:
Desired Qualifications:
#CJ
Job Title: User Activity Monitoring (UAM) Analyst
Location: Patch Barracks Stuttgart, Germany
Clearance: TS/SCI
Job Description:
Mission Essential is seeking a skilled User Activity Monitoring Analyst in Germany to play a key role in safeguarding our digital environment by detecting risks, analyzing user behavior, and supporting a strong security culture. The UAM Analyst will provide near real time detection and analysis of User Activity on both USEUCOM NIPRNet, and SIPRNet, supporting command action, investigations, and operational security. The UAM Analyst is critical to the detection and mitigation of insider threats, behavioral risks, and users who misuse the IT systems. The UAM Analytical Cell will triage data of anomalous events collected by the UAM tool and produce Report of Issue (ROI) and Analytical Findings that document issues on behaviors, computer misuse and violations of polices. Duties and responsibilities include but are not limited to:
- Continuously monitor user activity logs, alerts, and dashboards from UAM tool, identify anomalous behavior, high-risk actions, or deviations from established baselines, correlate user activity with system, network, and application events to detect potential threats, ensure user activity aligns with acceptable use policies, regulatory requirements, and internal controls.
- Continuously monitor user activity logs, alerts, and dashboards from UAM tool, identify anomalous behavior, high-risk actions, or deviations from established baselines, correlate user activity with system, network, and application events to detect potential threats, ensure user activity aligns with acceptable use policies, regulatory requirements, and internal controls.
- Escalate confirmed incidents to Insider Threat Program Manager and/or the Insider Threat Deputy Program Manager.
- Assist and/or lead training events and development of products related to Insider Threat Hub Workgroup.
- Attend, participate, and furnish input to scheduled and unscheduled meetings, conferences, and briefings that relate to the functions and services herein as required by the Government. The UAM shall participate in command wide Insider Threat Awareness events.
- Produce regular reports, ROI and Analytical Findings that document issues that meet an Insider Threat Potential Risk Indicator and Threshold.
- Produce regular reports summarizing user activity trends, incidents, and risk indicators, maintain detailed investigation records and audit-ready documentation, assist with log ingestion, rule creation, and behavioral model updates.
- Maintain close working relationship with the Insider Threat Hub, USEUCOM SSO, and Cyber Security.
REQUIREMENTS
Minimum Qualifications:
- Thirteen (13) years of specialized experience, OR Bachelor's degree in a related field and nine (9) years of specialized experience, OR Master's degree in a related field and six (6) years of specialized experience
- Bachelor's degree in information technology, computer science, cybersecurity, or a related discipline; equivalent experience may be accepted in lieu of a degree, subject to Government approval.
- Minimum of three years of experience in systems administration, network management, or IT support, preferably within a security, intelligence, or insider threat environment.
- Demonstrate proficiency in monitoring, analyzing, and investigating user behavior across enterprise systems to identify potential emerging insider threats to HQ USEUCOM information networks, personnel, and infrastructure.
- Strong understanding of cybersecurity principles, federal regulations, and standards related to insider threat programs, including but not limited to the National Industrial Security Program Operating Manual (NISPOM), DoD Directive 5205.16, and Executive Order 13587.
- Possess strong analytical, communication, and organizational skills, demonstrate the ability to work independently and as part of a team, and be proficient in the use of relevant IT management tools and software.
- Experience in implementing or supporting insider threat detection and mitigation programs, including the use of technical tools for monitoring user activity, analyzing behavioral indicators, and responding to potential threats.
- Must have relevant certifications, such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or other security and insider threat-related credentials, as required by the Government.
- Experience developing and delivering insider threat training and awareness programs, supporting investigations, and collaborating with law enforcement or counterintelligence activities as needed.
- All Contractor employees should, at a minimum, possess at least four years of professional experience within the law enforcement, security, counterintelligence, cyber security, mental health/behavioral science, human resources, or legal fields in the capacity of deterring, detecting, and mitigating insider threats/risks.
- TS/SCI clearance required
Desired Qualifications:
- Past Insider Threat, anti-terrorism, or military-related experience are preferred but not required, as is experience related to information assurance, privacy, and civil liberties within military departments and other government agencies. Education is not a substitute for experience but will be considered holistically within the employee's career.
- Completion of Insider Threat courses through Center for Development of Security Excellence (CDSE) under Defense Counterintelligence and Security Agency (DCSA); Defense Intelligence Agency (DIA); or National Insider Threat Task Force (NITTF) under Director of National Intelligence (DNI) is recommended but not required. Counter Insider Threat Professional (CICITP) Certification is recommended but not required.
- Knowledge of computer security principles and DoD security protocols; understanding of core current cybersecurity technologies as well as emerging capabilities; computer science or programming experience, network security experience, and computer-related degrees.
#CJ
group id: 10309996