Cyber Real-Time Analyst

Leidos

Confirmed live yesterday High trust

Quick summary

Work type
On-site
Location
Ford Island, HI
Salary
$69,550–$125,725 / yr
Posted
32 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Below market

How this pay compares to similar roles

Similar $140k
This role $98k
$58k most similar roles pay here $179k

This role pays less than 91% of similar roles. Most pay $120,200–$160,374 — the shaded band above. At the midpoint, this role pays about $98k versus about $140k for comparable roles.

Based on 239 similar postings.

Employer

About Leidos

Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations.

Leidos currently has 264 open roles on FindRole.

Listed pay typically runs $92,300–$166,850 across 245 roles with salary data.

Most-posted roles

View all roles at Leidos

At a glance

TL;DR · Cyber Real-Time Analyst

As a Cyber Real-Time Analyst on the Network Assurance Team, you will support the Security Operations Center for USPACOM and the broader Department of Defense Information Network. You will monitor, detect, and analyze intrusions across various access points while performing real-time triage of security events by correlating alerts, netflow, IDS/IPS output, and raw packet captures. Your daily work involves investigating "low and slow" activity to uncover unauthorized access and utilizing tools such as Splunk, Elastic, Microsoft Sentinel, and the ThunderDome suite. You will apply the MITRE ATT&CK framework to characterize adversary tactics and develop custom detection signatures. Additionally, you will support the Joint Fires Network by conducting Syslog reviews and using Corelight sensors. This role involves defending mission-critical infrastructure while building a new SOC capability for high-level sensor environments.

What you'll do

  • Monitor and analyze intrusions and threats across the DODIN/DISN boundary using network monitoring tools.
  • Perform real-time triage of security events by correlating alerts, netflow, IDS/IPS output, and raw packet captures.
  • Conduct deep-dive analysis of "low and slow" activity to identify unauthorized access missed by automated tools.
  • Utilize SIEM platforms like Splunk, Elastic, and Microsoft Sentinel to investigate and analyze security events.
  • Apply the MITRE ATT&CK framework to characterize adversary tactics and guide threat-hunting efforts.
  • Develop and tune custom detection signatures and countermeasures to mitigate emerging cyber threats.
  • Document findings in mandated reporting systems and issue situational awareness reports to mission partners.
  • Manage TS/SCI-level incidents and track them through JIRA using standardized SOC intake processes.

What we're looking for

  • Active Top Secret security clearance with eligibility to obtain SCI.
  • Bachelor's degree and 2+ years of experience for Level II, or Bachelor's degree and 4+ years of experience for Level III.
  • Equivalent work experience or military service may be substituted for a degree.
  • Qualifications must be compliant with DoD 8140 DCWF Code 531 at the Intermediate proficiency level.
  • Experience in Computer Network Defense duties including protecting, defending, responding, and sustaining networks.
  • Strong networking fundamentals including communication protocols and security tools like IDS/IPS and firewalls.
  • Ability to evaluate packet captures and analyze raw network traffic.
  • Willingness to work rotating shifts for 24/7/365 operations.
  • AI capability development and implementation to automate analysis (preferred).
  • Knowledge of adversary TTPs, MITRE ATT&CK, and the Cyber Kill Chain (preferred).
  • Experience with Splunk, Elastic, or similar SIEM platforms (preferred).
  • Familiarity with JIRA-based incident workflows and SOC intake processes (preferred).
  • Understanding of software exploits and experience analyzing packed or obfuscated code (preferred).

More like this

Similar roles

Cyber Security Analyst

Leidos

Adelphi, MD 17 days ago $87,100$157,450
SIEM IDS Incident Response NetFlow Packet Capture AWS Microsoft Azure Google Cloud Platform Oracle Cloud TCP/IP Unix Cyber Kill Chain SaaS Vulnerability Management Network Security Security+ CE CSSP-Infrastructure Support
4+ yrs exp Hybrid

Cyber Security Analyst

Leidos

Adelphi, MD 17 days ago $87,100$157,450
SIEM IDS Incident Response NetFlow Packet Capture AWS Microsoft Azure Google Cloud Platform Oracle Cloud TCP/IP Unix Cyber Kill Chain SaaS Vulnerability Management Network Security Security+ CE CSSP-Infrastructure Support
4+ yrs exp Hybrid

Cyber Security Analyst

Leidos

Adelphi, MD 17 days ago $87,100$157,450
SIEM IDS AWS Microsoft Azure Google Cloud Platform Oracle Cloud NetFlow Packet Capture TCP/IP Unix Incident Response Cyber Kill Chain SaaS Security+ CE CSSP-Infrastructure Support Vulnerability Management Network Security
4+ yrs exp Hybrid

Cyber Security Analyst

Leidos

Fort Belvoir, VA 17 days ago $87,100$157,450
SIEM IDS AWS Microsoft Azure Google Cloud Platform Oracle Cloud NetFlow Packet Capture TCP/IP Unix Incident Response Cyber Kill Chain SaaS Vulnerability Management Network Security Security+ CE CSSP-Infrastructure Support
4+ yrs exp

Cyber Threat Intelligence Analyst

Leidos

Washington, DC 59 days ago $107,900$195,050
Cyber Threat Intelligence MITRE ATT&CK Threat Intelligence Platforms (TIP Python PowerShell SIEM SOAR Firewalls IDS/IPS AWS Azure O365 KQL Elastic DSL SPL Cyber Kill Chain Diamond Model Data Correlation
8+ yrs exp Hybrid

Cyber Intelligence Fusion Analyst

Leidos

Alexandria, VA 8 days ago $107,900$195,050
SIEM EDR MITRE ATT&CK Cyber Kill Chain Splunk Microsoft Sentinel Microsoft Defender for Endpoint Wireshark Python PowerShell SQL KQL SPL Lucene Linux Unix PCAP NetFlow OSINT Cyber Threat Intelligence Incident Response Threat Hunting
8+ yrs exp