Insider Threat Technical Lead
9th Way Insignia
$155,000–$185,000
Jul 26, 2026
—
Jul 27, 2026
What this job asks for AI summary
A senior individual-contributor role leading the technical side of an insider risk program for a federal agency. Day-to-day work centers on configuring and tuning Microsoft Purview and Sentinel tooling, building and maintaining Power Automate flows, analyzing alerts alongside junior analysts, and advising government stakeholders on policy and emerging guidance. Suits an experienced cybersecurity practitioner holding a CISSP or GSE plus a qualifying GIAC secondary certification, with a SECRET clearance or the ability to obtain one.
Senior level · 7+ years · Remote · Bachelor's required · Secret clearance
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Rare in this occupation — lead with these, and say what you built with them.
What the occupation pays Median $132,021 (middle half $99,961–$167,095).
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (7)
The role is explicitly described as an individual-contributor technical leadership position, not a management role — 11-3021 was ruled out on that basis. The primary day-to-day work is insider-threat detection, SIEM/Purview policy configuration, alert triage, and security analysis, which maps to 15-1212; however, the heavy tooling-build component (Sentinel workbooks/playbooks, Power Automate flows, KQL rule engines) creates some ambiguity with 15-1252, noted as the alt SOC.
The 7-year experience requirement can be reduced to 5 years with a Master's degree per the posting; 7 years is captured as the baseline minimum.
A Bachelor's degree is hard-required; a Master's degree is offered as a partial experience substitute, not as a standalone requirement above Bachelor's level.
The primary certification requirement (CISSP or GIAC Security Expert/GSE) is a hard gate; both options are captured as alternatives on a single skill. The secondary GIAC certification requirement (one of GCDA, GCIA, GCFA, GCTI, GNFA, GPEN, or GREM) is also a hard gate but involves many interchangeable options — it is omitted from the skills list as the schema's alternatives array is not well-suited to a 7-way 'pick one' gate; hiring managers should note this requirement directly from the posting.
QRadar, Splunk, DLP, and eDiscovery appear in the narrative description of the program's existing toolset rather than in a formal requirements section, so they are marked as preferred.
The posting states 'Location: Remote' with no geographic restriction mentioned; no CBSA is applicable.
Requires a Secret clearance — the cleared population is a small fraction of this occupation, so the real candidate pool is materially smaller than the estimate below, which does not model clearance.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.