Defensive Cyber Operations Analyst

Leidos

Confirmed live today High trust
Hybrid

Quick summary

Work type
Hybrid
Location
Washington, DC
Salary
$87,100–$157,450 / yr
Employment
Full-time
Posted
51 days ago
Freshness
Confirmed live today

Market check

Salary context

Below market

How this pay compares to similar roles

Similar $147k
This role $122k
$76k most similar roles pay here $194k

This role pays less than 75% of similar roles. Most pay $122,275–$171,533 — the shaded band above. At the midpoint, this role pays about $122k versus about $147k for comparable roles.

Based on 240 similar postings.

Employer

About Leidos

Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations.

Leidos currently has 340 open roles on FindRole.

Listed pay typically runs $92,300–$166,850 across 294 roles with salary data.

Most-posted roles

View all roles at Leidos

At a glance

TL;DR · Defensive Cyber Operations Analyst

The Defensive Cyber Operations Analyst joins the Digital Modernization team to provide 24/7 operational support protecting federal networked systems and services from cyber threats impacting national security. In this role, you will perform incident detection and characterization by monitoring security tools for malicious activities, investigating alerts, and developing mitigation strategies. You will be responsible for technical writing, documenting events in ticketing systems, and providing senior-level briefings that translate complex security events into actionable intelligence. The position requires proficiency in networking protocols, firewalls, IDS/IPS, and analyzing packet captures and logs to identify malicious traffic. Key skills include experience with SIEM platforms like Splunk or Elastic, and familiarity with the Lockheed Martin Cyber Kill Chain and MITRE ATT&CK frameworks. You will provide detect, response, mitigation, and recovery capabilities within a high-tempo, collocated environment.

What you'll do

  • Detect, correlate, and characterize anomalous network activity indicative of enterprise threats.
  • Monitor security tools and applications to investigate alerts and develop mitigation strategies.
  • Follow Standard Operating Procedures to ensure accurate system checks and documentation.
  • Provide technical leadership by influencing solution designs and reviewing peer reports for accuracy.
  • Deliver technical briefings to senior management that translate complex events into actionable intelligence.
  • Document every event and analysis within the ticketing system according to high quality standards.
  • Monitor network, host, and application security devices to provide detection and recovery capabilities.
  • Analyze packet captures and logs to identify malicious traffic and verify security events.

What we're looking for

  • Must hold a current DoD TS/SCI security clearance and pass customer suitability screenings.
  • Bachelor's degree in a related discipline or equivalent professional/military experience.
  • Level II requires 2+ years of experience, Level III requires 4+ years, and Level IV requires 8+ years.
  • Must hold a DoD 8570 IAT Level II or higher certification (or obtain within 180 days).
  • Must hold a DoD 8570 CSSP Analyst or Infrastructure Support certification (or obtain within 180 days).
  • Strong knowledge of networking, communication protocols, and security elements like IDS/IPS and firewalls.
  • Experience evaluating packet captures (PCAP) and logs to identify malicious traffic and verify events.
  • Prior experience in a SOC environment, familiarity with MITRE ATT&CK, or SIEM platform experience (preferred).

More like this

Similar roles

Computer Network Defense Analyst

Leidos

Arlington, VA 9 days ago $69,550–$125,725
Network Defense SIEM Splunk Elastic AWS Azure IDS/IPS Firewalls Windows Red Hat Cloud Migration Incident Response Network Log Analysis Security+ DISA Disaster Recovery Business Continuity
2+ yrs exp

Senior Cyber Security Fusion Analyst

Leidos

Fort George G. Meade, MD 65 days ago $131,300–$237,350
SIEM Splunk Arcsight Wireshark TCP/IP Netflow PCAP OSINT Cyber Kill Chain Malware Analysis Virus Total Recorded Future Passive DNS Security+ IAM IAT Cyber Fusion Network Analysis
10+ yrs exp

Defensive Cyber Operations Analyst

Booz Allen Hamilton

Peterson AFB, CO 2 days ago $69,300–$158,000
Splunk HBSS Microsoft Defender Security Onion SIGACT RALLY Incident Response Threat Intelligence Network Security Cybersecurity Information Assurance NetOps AI
1+ yrs exp

Defensive Cybersecurity Analyst

Leidos

Shiloh, IL 33 days ago $69,550–$125,725
SIEM SOAR IDS/IPS NetFlow Packet Analysis MITRE ATT&CK Cyber Kill Chain AWS Azure GCP Scripting OSI Model Defense-in-Depth MDM MAM MTD
2+ yrs exp

Defensive Cybersecurity Analyst

Leidos

Whitehall, OH 33 days ago $69,550–$125,725
SIEM SOAR IDS/IPS NetFlow Packet Analysis Cyber Kill Chain AWS Azure GCP Scripting OSI Model Defense-in-Depth MDM MAM MTD
2+ yrs exp

Cyber Security Analyst

Leidos

Adelphi, MD 37 days ago $87,100–$157,450
SIEM IDS Incident Response NetFlow Packet Capture AWS Microsoft Azure Google Cloud Platform Oracle Cloud TCP/IP Unix Cyber Kill Chain SaaS Vulnerability Management Network Security Security+ CE CSSP-Infrastructure Support
4+ yrs exp Hybrid