Standard Job Description
Cyber Intel Associate Analyst - Insider Threat / CIRT / Rockville MD
Lockheed Martin's Computer Incident Response Team (CIRT) Insider Threat Team is hiring a Cyber Intel Associate Analyst. This role will report to the Insider Threat Team Associate Manager within Corporate Information Security (CIS).
What You Will Be Doing:
This role will build on foundational knowledge rooted in Cyber Security, focusing on Insider Threat detection methodologies against various operating system, network, and security infrastructure logs to identify potential insider threats within the organization. You will leverage native analytics tools in conjunction with internal and commercial AI/ML models to uncover, surface, and mitigate insider‑threat activity. The role is hands‑on, collaborative, and will provide exposure to the full CIRT lifecycle—from data collection through detection design, automation, and reporting. You will also work with various teams within CIRT, CIS, and across the Enterprise to advance the LM-CIRT missions. Your key responsibilities will include the following:
- Support Complex Problem Investigation. You will be collaborating with senior analysts to explore insider threat scenarios that lack existing detection coverage, executing hypothesis driven searches, aggregating relevant log data, and documenting preliminary findings. Under senior guidance, you will be prototyping a simple detection rule or automation script, testing it on sandbox data, and updating team documentation with the validated solution. This iterative process builds foundational analytical skills while contributing to the evolution of LM CIRT’s detection capabilities.
- Detection Development. You will create Splunk alerts, reports, and simple correlation searches, and be exposed to building YARA rules.
- Log & Data Analysis. You will parse operating system, network, endpoint, and security infrastructure logs (Windows, Linux, cloud) to identify patterns indicative of insider threat behavior.
- Automation & Workflow Enablement. You will identify routine analytic steps that can be automated and create scripts or automation playbooks to reduce manual effort.
- AI assisted Detection Development. You will assist senior analysts in building and refining detection content that incorporates leveraging AI models, Splunk, and automation capabilities.
- Threat Hunting Support. You will participate in structured threat hunting cycles, executing hypothesis driven queries and documenting findings for senior review.
- Reporting & Knowledge Sharing. You will produce concise detection tuning notes, dashboards, and fused intelligence briefings for internal stakeholders (CIRT, Counterintelligence, leadership).
- Agile Collaboration. You will work within the team’s Agile development process (Scrum/Kanban) using JIRA, Git Lab, and Confluence to track work, version control detection code, and maintain documentation.
- Continuous Learning. You will be able to stay current on emerging insider threat tactics, AI/ML advances, and relevant regulatory requirements (e.g., NIST 800 53, DFARS).
This is a highly hands-on technical role that will require you to be comfortable working in a dynamic and fast-paced operational environment, which occasionally can require the flexibility to work off hours.
Further Information About This Opportunity:
This is a hybrid role based out of Rockville MD. US Citizenship is required with eligibility for Secret clearance.
Basic Qualifications
- Bachelor’s degree (or equivalent experience) in Computer Science, Information Technology, Cyber‑Security, Data Science, or a related technical field
- Basic knowledge of Splunk (search language, dashboard creation)
- Familiarity with at least one scripting language (Python, PowerShell, Bash)
- Experience working in a Unix/Linux command‑line environment
- Demonstrated ability to interpret raw log data, draw logical conclusions, and document findings
- Strong written and verbal communication and ability to present technical material to both technical and non‑technical audiences
- Proven ability to work collaboratively within a team and follow defined processes
- Willingness to work flexible hours or on‑call rotations as required by mission needs
- US Citizenship with eligibility for Secret Clearance or higher
Desired Skills
- Familiarity with basic forensic concepts (memory/image capture, timeline creation) or participation in a cyber‑incident response exercise.
- Understanding of insider‑threat lifecycle, misuse cases, and behavioral analytics.
- Hands‑on experience with Splunk Machine Learning Toolkit, Jupyter notebooks, or other low‑code AI platforms; basic understanding of supervised vs. unsupervised learning.
- Experience using JIRA, Git Lab, or similar version‑control and ticketing systems.
- Splunk Core Certified User, CompTIA Security+, EC‑Council CEH, or a foundational AI/ML certification (e.g., Coursera “AI for Everyone”).
- Prior exposure to IT operations, system administration, network security, or intelligence analysis.
Pay Information
Full-Time Salary Range: $75400.00 - $140000.00
At Lockheed Martin, we know mission success starts with taking care of our people. Our Total Rewards program is designed to attract top talent, support your well-being, and help you grow—both professionally and personally.
The salary range for this position is as listed on the requisition. Please note that the salary information listed is a general guideline only. Lockheed Martin considers factors such as (but not limited to) scope and responsibilities of the position, candidate's work experience, education/ training, key skills as well as market(work location) and business considerations when extending an offer.
Benefits offered: Medical, Dental, Vision, Flexible work arrangements and schedules (e.g., 4x10), 401(k) match, Paid time off, Holidays, Parental Leave, EAP, Flexible Spending Accounts, Education Assistance, Life Insurance, Short-Term Disability, and Long-Term Disability.
- Annual short-term and/or long-term incentive compensation programs may be offered depending on the position. Payments under these annual programs are not guaranteed and can vary from year to year and are tied to a range of performance metrics.
- For (Washington state applicants only) Non-represented full-time employees: accrue at least 10 hours per month of Paid Time Off (PTO) to be used for incidental absences and other reasons; receive at least 90 hours for holidays. Represented full time employees accrue 6.67 hours of Vacation per month; accrue up to 52 hours of sick leave annually; receive at least 96 hours for holidays. PTO, Vacation, sick leave, and holiday hours are prorated based on start date during the calendar year.