1

Threat Monitoring Analyst Jobs (NOW HIRING)

Customs and Border Protection (CBP), you will be responsible for leading user activity monitoring activities, foreign service national monitoring, insider threat analysis, and investigating policy ...

Customs and Border Protection (CBP), you will be responsible for leading user activity monitoring activities, foreign service national monitoring, insider threat analysis, and investigating policy ...

Leidos is seeking a ConMon Analyst to be responsible for overseeing and monitoring authorized ... Create alerts that trigger on anomalous activities, threat detections, or configured settings to ...

Leidos is seeking a ConMon Analyst to be responsible for overseeing and monitoring authorized ... Create alerts that trigger on anomalous activities, threat detections, or configured settings to ...

Leidos is seeking a ConMon Analyst to be responsible for overseeing and monitoring authorized ... Create alerts that trigger on anomalous activities, threat detections, or configured settings to ...

Continuously monitor global threat landscapes, focusing on civil unrest, geopolitical instability ... Strong analytical and writing skills with the ability to create concise, decision-ready reports.

Insider Threat Monitoring and DetectionMonitor logs, dashboards, and alerts across multiple enterprise security applications to identify potential insider threat activity.Analyze user activity and ...

next page

Showing results 1-20

Threat Monitoring Analyst information

See salary details

$47

$60

$72

How much do threat monitoring analyst jobs pay per hour?

As of Sep 9, 2026, the average hourly pay for threat monitoring analyst in the United States is $60.46, according to ZipRecruiter salary data. Most workers in this role earn between $55.77 and $65.87 per hour, depending on experience, location, and employer.

What is a threat monitoring analyst?

Threat Monitoring Analysts are cybersecurity professionals responsible for identifying, assessing, and responding to security threats within an organization's IT environment. They monitor network activity, analyze security alerts, and investigate suspicious behavior to detect potential cyberattacks or breaches. Their role is crucial in maintaining the security of sensitive data and ensuring compliance with industry regulations, often working as part of a larger security operations team. By utilizing specialized tools and threat intelligence, they help prevent, mitigate, and respond to security incidents in real time.

What are the key skills and qualifications needed to thrive as a threat monitoring analyst?

To thrive as a Threat Monitoring Analyst, you need a strong understanding of cybersecurity principles, network protocols, and incident response, often supported by a degree in information security or a related field. Familiarity with security information and event management (SIEM) tools, intrusion detection/prevention systems (IDS/IPS), and certifications such as Security+ or CISSP are typically required. Attention to detail, analytical thinking, and effective communication help analysts identify threats and collaborate with teams. These skills are vital for rapidly detecting and mitigating cyber threats to protect organizational assets and data.

What are the typical challenges a threat monitoring analyst faces when identifying and escalating security incidents?

Threat Monitoring Analysts often face challenges such as distinguishing real threats from false positives, prioritizing alerts based on potential impact, and keeping up with rapidly evolving attack techniques. The high volume of alerts generated by security tools can be overwhelming, requiring strong analytical skills and attention to detail. Collaboration with IT and incident response teams is essential to ensure timely communication and effective mitigation of risks, making teamwork and clear documentation vital components of the role.

What is the difference between Threat Monitoring Analyst vs Security Analyst?

AspectThreat Monitoring AnalystSecurity Analyst
CertificationsCompTIA Security+, CEH, CISSP (preferred)CompTIA Security+, CISSP, CISA (common)
Work EnvironmentMonitoring security alerts, analyzing threats, using SIEM toolsAssessing security systems, incident response, policy development
Employer & Industry UsageCybersecurity firms, IT departments, government agenciesCorporate, government, financial institutions

Threat Monitoring Analysts focus on real-time threat detection and analysis using SIEM tools, while Security Analysts have a broader role including incident response and security policy management. Both roles require similar certifications and often work in similar environments, but their core responsibilities differ in scope and focus.

What cities are hiring for Threat Monitoring Analyst jobs?

Cities with the most Threat Monitoring Analyst job openings:

What states have the most Threat Monitoring Analyst jobs?

States with the most job openings for Threat Monitoring Analyst jobs include:

What are popular job titles related to Threat Monitoring Analyst jobs?

For Threat Monitoring Analyst jobs, the most frequently searched job titles are:

Infographic showing various Threat Monitoring Analyst job openings in the United States as of September 2026, with employment types broken down into 1% As Needed, 85% Full Time, 10% Part Time, and 4% Contract. Highlights an 91% Physical, 2% Hybrid, and 7% Remote job distribution, with an average salary of $125,752 per year, or $60.5 per hour.

Insider Threat Monitoring Analyst

Ashburn, VA • On-site

Other

Posted 8 days ago


Job description

Overview

The Department of Homeland Security (DHS), Customs and Border Protection (CBP) Cyber Security Directorate (CSD) Security Operations Center (SOC) is a US Government program responsible for preventing, identifying, containing, and eradicating cyber threats to CBP networks through monitoring, intrusion detection, and protective security services. The CBP SOC secures CBP Enterprise-wide information systems (LAN/WAN, cloud, mobile, wireless, websites, and devices) and collects, investigates, and reports suspected and confirmed security violations. Leidos is seeking an experienced Insider Threat Expert to join our team to lead user activity monitoring, FSN monitoring, insider threat analysis, and investigations of policy violations, data loss prevention (DLP) events, and sensitive data spillages in support of CBP.

Primary Responsibilities
  • Lead investigations and support for insider threat and forensics activities, including near real-time monitoring of DLP tools for potential data exfiltration of CBP mission data or employee PII/SPII.
  • Support investigations with the Office of Professional Responsibility (OPR), Office of Intelligence (OI), Office of the Inspector General (OIG), and other government agencies when CBP personnel may be malicious or have alleged criminal intent.
  • Actively monitor Foreign Service National (FSN) network activity for misuse and policy violations.
  • Support User Activity Monitoring (UAM) activities.
  • Recommend insider threat alert triggers and detections across various security tools and logging sources.
  • Monitor CBP laptops and mobile devices traveling OCONUS for suspicious activity and policy violations.
  • Provide investigative support for CBP’s OPR-Cyber Investigations related to media leak investigations by identifying all users who accessed, sent, printed, copied, downloaded/uploaded, or received leaked documents.
  • Provide recommendations for Information Spillage Incident Response, following industry best practices, NIST 800-88, and federal guidelines.
Qualifications
  • BS degree with a minimum of 8 years of directly relevant experience.
  • Active and current CISSP certification.
  • Degree in computer science, IT, Information/Cyber Security from an accredited college or university; additional experience or applicable certifications may be accepted in lieu of a degree.
  • Working knowledge of defense-in-depth principles, security architecture (network/HW/SW), IT device integrity, and common security elements.
  • Effective communication skills with attention to detail, ability to document technical remediation details, and ability to brief stakeholders on incident statuses, recovery, and root causes.
  • Experience performing forensic and digital media analysis, and in-depth system and network log analysis to support investigations.
  • Ability to generate forensically sound cyber analysis reports detailing procedures, findings, and recommendations.
  • Strong problem-solving abilities with analytical reasoning under pressure.
  • Experience with User Activity Monitoring products and platforms.
  • Experience with Endpoint Detection and Response (EDR) tools.
  • Ability to report to the Ashburn, VA office up to 5 days per week.
  • U.S. citizenship is required.
  • Active Top Secret clearance and ability to obtain and maintain a CBP BI clearance.
Preferred Qualifications
  • Master’s degree in IT Management, Engineering, or a related field.
  • SANS GREM certification.
  • Experience contributing to or leading insider threat investigations in Federal Government, DOD, or Law Enforcement environments.
  • Experience performing computer forensics in Federal Government, DOD, or Law Enforcement environments.

All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, disability, genetic information, pregnancy, family structure, marital status, or any other Basis prohibited by law. Leidos will also consider qualified applicants with criminal histories consistent with relevant laws.

#J-18808-Ljbffr