User and Entity Behavior Analytics Engineer
Booz Allen Hamilton
- Location
- McLean, VA
- Work model
- On-Site
- Level
- Entry
- H-1B history
- 9 approvals (FY2023)
- Posted
- Sep 16, 2026
Skills
About this role
User and Entity Behavior Analytics Engineer The Opportunity: As an Enterprise Cybersecurity User and Entity Behavior Analytics (UEBA) Engineer , you will help strengthen Booz Allen's identity, security, and insider risk programs by improving visibility into user and entity behavior. Your work will support the detection, investigation, and response to anomalous activity, account compromise, insider risk, and other cybersecurity threats. By developing actionable behavioral analytics and risk indicators, you will help enable effective threat detection and coordinated response across the enterprise. In this role, you will analyze user, device, application, network, cloud, and security telemetry to identify deviations from expected behavior and uncover indicators of compromise, insider risk, account compromise, and other cyber threats. You will collaborate closely with cyber operators, threat analysts, incident responders, data scientists, and AI engineers to develop and operationalize behavioral analytics that support real-time situational awareness, automated triage, and semi-autonomous cybersecurity workflows across the enterprise. Due to the nature of work performed within this facility, U.S. citizenship is required. How You’ll Contribute : Develop, tune, and maintain UEBA detections, behavioral baselines, anomaly detection rules, and risk-based analytics across users, devices, applications, and cloud entities Deploy, configure, and maintain UEBA software Partner with cyber operators, threat analysts, incident responders, and security stakeholders to define requirements, validate detections, and integrate UEBA analytics into SOC workflows Develop dashboards, reports, and risk indicators that communicate behavioral trends, high-risk activity, and investigation findings to technical and executive audiences Continuously assess and improve detection logic by evaluating alert quality, reducing false positives, and incorporating analyst feedback and lessons learned from security incidents Join us. The world can’t wait. You Have: 3+ years of experience in cybersecurity analytics, security operations, threat detection, threat hunting, insider risk, or user and entity behavior analytics 1+ years of experience with a UEBA tool, including EverFox , CrowdStrike, or Splunk Experience developing, tuning, and operationalizing behavioral analytics, anomaly detection rules, risk scores, or correlation logic Experience using SIEM, UEBA, EDR, identity, or cybersecurity platforms Ability to document analytical methods, investigation findings, detection logic, and recommended actions clearly and accurately Ability to work independently and collaboratively in a team environment Ability to be self-motivated, pay close attention to detail, and manage multiple priorities Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or Data Analytics or 5+ years of experience in cybersecurity, information technology, or analytics in lieu of a degree Nice If You Have: Experience supporting insider threat, data loss prevention, fraud detection, account takeover, or privileged-user monitoring programs Knowledge of cybersecurity domain Possession of strong analytical, problem-solving, and critical thinking skills Possession of strong written and verbal communication skills, including presenting complex information in a clear and concise manner Compensation At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees