Cyber Focused Operations Insider Threat Specialist (Remote)

Remote, USA

Cyber Focused Operations Insider Threat Specialist (Remote)

Category: Cyber Security

Main location: United States, Remote

Position ID: J0124-0769

Employment Type: Full Time

Meet our professionals

U.S. - What we do matters

Position Description:

CGI is in the top 5 largest global IT companies spread across 40 countries with endless opportunities to expand and grow. As a CGI Member, you have the opportunity to be a shareholder at CGI and join a family of 75,000 members strong. CGI Federal is seeking a Cyber Focused Operations Insider Threat Specialist to join our dynamic team.

We’re a close-knit team that has access to global resources. You’ll have the opportunity to explore a wide range of industries, technologies, and geographies, all while enjoying the personal touch that our local operating approach offers. Growth at CGI is driven by your goals, so if you were looking for an inclusive place where you’re empowered to chart your own path, then we’d love to meet you.

Your future duties and responsibilities:

• Proactively identify potential insider threats by monitoring, analyzing, and correlating data between various data sources.

o Conduct comprehensive all-source analysis in support of the Insider Threat mission Triage anomalous event data.

• Develop a plan to investigate suspected insider threats, including interviews, evidence collection and digital forensics.

o Examine recovered data for information of relevance to the issue at hand.

o Investigate alleged crime, violation, or suspicious activity utilizing computers and the Internet.

o Fuse computer network attack analyses with criminal and counterintelligence investigations and operations.

• Conduct and execute incident response plans to address insider threats, working in collaboration with IT, legal, and HR departments as necessary.

o Identify and/or determine whether a security incident is indicative of a violation of law that requires specific legal action.

• Collect and preserve digital and physical evidence related to insider threat incidents, ensuring chain of custody, and maintaining strict confidentiality.

o Extract and organize data relating to network monitoring, data analytics, security alerts and employee behavior.

• Analyze data to uncover patterns and anomalies in user activities to build profiles of potential insider threats.

o Access network monitoring, data analytics, and other tools integrate available information, decipher underlying trends and anomalies, and discern obscure patterns found in the datasets.

• Prepare comprehensive reports summarizing investigative findings, recommendations for remediation, and legal documentation if necessary.

o Prepare reports to document the investigation following legal standards and requirements.

o Produce situational awareness and warning reports related to Insider Threat

• Provide recommendations related to training and awareness programs to educate employees and contractors about insider threat risks and prevention measures.

o Determine the extent of threats and recommend courses of action or countermeasures to mitigate risks.

o Provide editing and quality control of program products.

• Assist in the development and enhancement f insider threat detection and response policies and procedures.

o Provide recommendations to contractor and government leadership on ways to improve the Insider Threat program.

o Conduct risk assessments and present findings to a variety of audiences, including very senior decision makers; written and oral presentations.

Required qualifications to be successful in this role:

BA or BS degree from an accredited undergraduate program

• Minimum of 5 years of experience in a Cyber Operations roles.

• Knowledge of Insider Threat investigations, reporting, investigative tools and laws/regulations.

• Skill in preserving evidence integrity according to standard operating procedures or national standards.

• Ability to examine digital media on multiple operating system platforms.

• Examine recovered data for information of relevance to the issue at hand

• Demonstrated experience with UAM capabilities

• Experience with:

o TCP/IP, Packet Analysis

o SIEM Operation

o Intrusion Detection Technology

• Experience with analytical problem solving and familiarity with conducting operations relating to insider threat

• Familiar with data analytics tools used for Insider Threat information collection or computer networks or knowledge of other Insider Threat risk scoring data analytics tools/programs

• Strong written and verbal communication skills, and the ability to create complex technical reports on analytic findings

• Familiar with Splunk preferred but not required

Due to the nature of the government contracts this position requires US Citizenship

This position can be located remotely anywhere in the U.S.

Pay Transparency for ALL Open/Future Opening Requisitions

“CGI is required by law in some jurisdictions to include a reasonable estimate of the compensation range for this role. The determination of this range includes various factors not limited to skill set, level, experience, relevant training, and licensure and certifications. To support the ability to reward for merit-based performance, CGI typically does not hire individuals at or near the top of the range for their role. Compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range for this role in the U.S. is $118000- $190100

CGI Federal anticipates accepting applications for this position through 4/15/2024.


At CGI we call our professionals “members” to reinforce that all who join our team are, as owners, empowered to participate in the challenges and rewards that come from building a world-class company. CGI’s benefits include:

• Competitive compensation

• Comprehensive insurance options

• Matching contributions through the 401(k) plan and the share purchase plan

• Paid time off for vacation, holidays, and sick time

• Paid parental leave

• Learning opportunities and tuition assistance

Member assistance and wellness programs





  • Cyber

  • Operational Security

  • Threat Risk Assessment

What you can expect from us:

Insights you can act on

While technology is at the heart of our clients’ digital transformation, we understand that people are at the heart of business success.

When you join CGI, you become a trusted advisor, collaborating with colleagues and clients to bring forward actionable insights that deliver meaningful and sustainable outcomes. We call our employees “members” because they are CGI shareholders and owners and owners who enjoy working and growing together to build a company we are proud of. This has been our Dream since 1976, and it has brought us to where we are today — one of the world’s largest independent providers of IT and business consulting services.

At CGI, we recognize the richness that diversity brings. We strive to create a work culture where all belong and collaborate with clients in building more inclusive communities. As an equal-opportunity employer, we want to empower all our members to succeed and grow. If you require an accommodation at any point during the recruitment process, please let us know. We will be happy to assist.

Ready to become part of our success story? Join CGI — where your ideas and actions make a difference.

Qualified applicants will receive consideration for employment without regard to their race, ethnicity, ancestry, color, sex, religion, creed, age, national origin, citizenship status, disability, pregnancy, medical condition, military and veteran status, marital status, sexual orientation or perceived sexual orientation, gender, gender identity, and gender expression, familial status, political affiliation, genetic information, height, weight, or any other legally protected status or characteristics.

CGI provides reasonable accommodations to qualified individuals with disabilities. If you need an accommodation to apply for a job in the U.S., please email the CGI U.S. Employment Compliance mailbox at . You will need to reference the Position ID of the position in which you are interested. Your message will be routed to the appropriate recruiter who will assist you. Please note, this email address is only to be used for those individuals who need an accommodation to apply for a job. Emails for any other reason or those that do not include a Position ID will not be returned .

We make it easy to translate military experience and skills! Clickhere ( to be directed to our site that is dedicated to veterans and transitioning service members.

All CGI offers of employment in the U.S. are contingent upon the ability to successfully complete a background investigation. Background investigation components can vary dependent upon specific assignment and/or level of US government security clearance held. CGI will consider for employment qualified applicants with arrests and conviction records in accordance with all local regulations and ordinances.

CGI will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with CGI’s legal duty to furnish information.