Cyber Intel Analyst

Leidos

Confirmed live today High trust
Hybrid

Quick summary

Work type
Hybrid
Location
Washington, DC
Salary
$87,100–$157,450 / yr
Employment
Full-time
Posted
12 days ago
Freshness
Confirmed live today

Market check

Salary context

Below market

How this pay compares to similar roles

Similar $142k
This role $122k
$77k most similar roles pay here $182k

This role pays less than 68% of similar roles. Most pay $117,442–$165,750 — the shaded band above. At the midpoint, this role pays about $122k versus about $142k for comparable roles.

Based on 240 similar postings.

Employer

About Leidos

Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations.

Leidos currently has 251 open roles on FindRole.

Listed pay typically runs $92,300–$166,850 across 235 roles with salary data.

Most-posted roles

View all roles at Leidos

At a glance

TL;DR · Cyber Intel Analyst

The Cyber Intel Analyst joins the Defensive Cyber Operations team to protect federal networked systems and services from national security threats. This role involves executing hypothesis-driven hunt campaigns based on adversary TTPs, querying telemetry across cloud, identity, and network infrastructure to identify "low and slow" attacks, and developing automated detection rules for SIEM and EDR platforms. The analyst will produce strategic, operational, and tactical intelligence reports while managing the full intelligence lifecycle, including collection plans and indicator fidelity within a Threat Intelligence Platform. Key technical requirements include proficiency in MITRE ATT&CK, networking protocols like TCP/IP and DNS, and query languages such as SPL, KQL, or Elastic DSL. Candidates may also utilize Python, PowerShell, or Bash for automation while leveraging tools like Anomali, ThreatConnect, or Recorded Future to synthesize data into a unified operational picture.

What you'll do

  • Execute hypothesis-driven hunt campaigns based on adversary TTPs to identify "low and slow" attacks.
  • Query and correlate telemetry across cloud, identity, and network infrastructure to surface threats.
  • Convert threat hunting findings into automated SIEM/EDR detection rules with the engineering team.
  • Produce strategic, operational, and tactical intelligence reports on emerging threats and actor motivations.
  • Manage the intelligence lifecycle including collection plans, dissemination, and indicator fidelity within a TIP.
  • Synthesize external threat intelligence with internal hunt telemetry to create a unified operational picture.
  • Pair vulnerability data with active threat reporting to prioritize remediation efforts.
  • Author technical reports and metrics regarding findings, gaps, and posture improvements for leadership.

What we're looking for

  • Current DoD TS/SCI clearance and ability to pass customer suitability screening.
  • Level III: Bachelor’s degree and 4+ years of experience, or Master’s degree and 2+ years of experience.
  • Level IV: Bachelor’s degree and 8+ years of experience, or Master’s degree and 6+ years of experience.
  • DoD 8570 IAT Level II or higher certification (e.g., Security+, CySA+, GSEC, SSCP, CASP+ CE, CCNP Security, CISA, GCED, GCIH, or CISSP).
  • DoD 8570 CSSP Analyst certification required within 180 days of onboarding (e.g., CySA+, Cloud+, GCIA, CEH).
  • DoD 8570 CSSP Infrastructure Support certification required within 180 days of onboarding (e.g., CySA+, Cloud+, CEH, CND, CHFI, GICSP, SSCP).
  • Strong knowledge of networking protocols and security controls like IDS/IPS and next-generation firewalls.
  • Proficiency in query languages (SPL, KQL, Elastic DSL), scripting (Python, PowerShell, Bash), or cloud platforms (preferred).

More like this

Similar roles

Cyber Intelligence Fusion Analyst

Leidos

Alexandria, VA 24 days ago $107,900–$195,050
SIEM EDR MITRE ATT&CK Cyber Kill Chain Splunk Microsoft Sentinel Microsoft Defender for Endpoint Wireshark Python PowerShell SQL KQL SPL Lucene Linux Unix PCAP NetFlow OSINT Cyber Threat Intelligence Incident Response Threat Hunting
8+ yrs exp

Cyber Real-Time Analyst

Leidos

Ford Island, HI 48 days ago $69,550–$125,725
Splunk Elastic Microsoft Sentinel ThunderDome MITRE ATT&CK JIRA Corelight IDS/IPS Firewalls Netflow Packet Capture SIEM Cyber Kill Chain Incident Response
2+ yrs exp

Cyber Security Analyst

Leidos

Adelphi, MD 33 days ago $87,100–$157,450
SIEM IDS Incident Response NetFlow Packet Capture AWS Microsoft Azure Google Cloud Platform Oracle Cloud TCP/IP Unix Cyber Kill Chain SaaS Vulnerability Management Network Security Security+ CE CSSP-Infrastructure Support
4+ yrs exp Hybrid

Cyber Security Analyst

Leidos

Adelphi, MD 33 days ago $87,100–$157,450
SIEM IDS AWS Microsoft Azure Google Cloud Platform Oracle Cloud NetFlow Packet Capture TCP/IP Unix Incident Response Cyber Kill Chain SaaS Security+ CE CSSP-Infrastructure Support Vulnerability Management Network Security
4+ yrs exp Hybrid

Cyber Security Analyst

Leidos

Adelphi, MD 33 days ago $87,100–$157,450
SIEM IDS Incident Response NetFlow Packet Capture AWS Microsoft Azure Google Cloud Platform Oracle Cloud TCP/IP Unix Cyber Kill Chain SaaS Vulnerability Management Network Security Security+ CE CSSP-Infrastructure Support
4+ yrs exp Hybrid

Cyber Security Analyst

Leidos

Fort Belvoir, VA 33 days ago $87,100–$157,450
SIEM IDS AWS Microsoft Azure Google Cloud Platform Oracle Cloud NetFlow Packet Capture TCP/IP Unix Incident Response Cyber Kill Chain SaaS Vulnerability Management Network Security Security+ CE CSSP-Infrastructure Support
4+ yrs exp