Cyber Security Analyst
About the role
Leidos is seeking a Cyber Security Analyst for the DISA GSMO‑II program in the Washington, DC area. The position provides 24 × 7 cybersecurity monitoring and analysis services for Department of Defense networks above the SECRET level, including real‑time cyber threat intelligence analysis, correlation of actionable security events, network traffic analysis using raw packet data, and coordination of resources during incident response. The role is fully on‑site in Arlington, VA.
Responsibilities
- Review DoD and open‑source intelligence for threats and identify Indicators of Compromise (IOCs) to integrate into sensors and SIEMs.
- Utilize alerts from endpoints, IDS/IPS, netflow, and custom sensors to identify compromises on customer networks/endpoints.
- Review massive log files, pivot between data sets, and correlate evidence for incident investigations.
- Triage alerts to identify malicious actors on customer networks.
- Report incidents to customers and USCYBERCOM.
- Develop, deploy, and maintain custom analytics and countermeasures.
Requirements
- Active DoD Top Secret security clearance with SCI eligibility.
- Bachelor’s degree and 4+ years of relevant experience (or equivalent work experience/cyber courses/certifications).
- Understanding of TCP/IP, common networking ports and protocols, traffic flow, system administration, OSI model, defense‑in‑depth, and common security elements.
- Strong written and verbal communication skills; ability to create complex technical reports.
- DoD 8570 IAT Level II or higher certification (e.g., CompTIA Security+ CE, ISC2 SSCP, SANS GSEC) prior to start.
- DoD 8570 CSSP‑A level certification (e.g., CEH, CySA+, GCIA) required within 180 days of hire.
- Commitment to continuous training and self‑study in cyber security.
- Strong analytical and troubleshooting skills.
- Willingness to perform shift work and be a U.S. citizen.
- Preferred: CND experience within a Computer Incident Response organization.
- Preferred: Advanced knowledge of network threat life cycle, attack vectors, and intrusion‑set TTPs.
- Preferred: Experience developing AI and automation tools for incident response.
- Preferred: Hands‑on analysis of high‑volume logs and network data (e.g., Splunk, Suricata, Zeek, Full Packet Capture).
- Preferred: In‑depth knowledge of at least one enterprise SIEM platform (e.g., Splunk ES, Elastic).
- Preferred: Proficiency with tools such as Splunk, Suricata, Zeek, Full Packet Capture, Network Forensics, Endpoint Detection and Response, Corelight, Elastic.
- Preferred: Malware analysis concepts and methods.
- Preferred: Unix/Linux command‑line experience.
- Preferred: Scripting or programming experience to write Suricata and Zeek rule sets.
- Preferred: Familiarity with Intelligence‑Driven Defense, MITRE ATT&CK, and Cyber Kill Chain methodologies.
Schedule
Shifts include Days (morning), Swings (evening) and Mids (night) and may require weekend and/or holiday hours. All new hires spend the initial 4–6 weeks on a weekday Day Shift for onboarding and training; shift availability may vary based on program needs and staffing levels.
Pay
Salary range: $87,100 – $157,450 per year. Compensation is based on responsibilities, education, experience, skills, internal equity, market data, and applicable agreements.
Benefits
Employment benefits include competitive compensation, health and wellness programs, income protection, paid leave, and retirement plans. More details are available at www.leidos.com/careers/pay-benefits.