Defensive Cybersecurity Analyst

Leidos

Confirmed live today High trust

Quick summary

Work type
On-site
Location
Shiloh, IL
Salary
$69,550–$125,725 / yr
Employment
Full-time
Posted
33 days ago
Freshness
Confirmed live today

Market check

Salary context

Below market

How this pay compares to similar roles

Similar $150k
This role $98k
$56k most similar roles pay here $198k

This role pays less than 95% of similar roles. Most pay $122,275–$177,250 — the shaded band above. At the midpoint, this role pays about $98k versus about $150k for comparable roles.

Based on 240 similar postings.

Employer

About Leidos

Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations.

Leidos currently has 340 open roles on FindRole.

Listed pay typically runs $92,300–$166,850 across 294 roles with salary data.

Most-posted roles

View all roles at Leidos

At a glance

TL;DR · Defensive Cybersecurity Analyst

As a Defensive Cybersecurity Analyst, you will join a 24x7 front-line security operations team dedicated to protecting Department of Defense networks from sophisticated and rapidly evolving cyber threats. You will be responsible for investigating and triaging security alerts from endpoints, IDS/IPS, NetFlow data, and custom sensors while analyzing extensive log files to identify suspicious activity. Your daily work involves correlating diverse datasets to produce technical findings, integrating threat intelligence feeds into SIEM platforms, and collaborating with incident response teams. To succeed, you must possess a strong understanding of networking principles, packet analysis, and defense-in-depth architecture. You will utilize tools such as SIEM/SOAR platforms and potentially manage cloud environments or mobile security. The role requires an adversary mindset to uncover malicious activity while navigating the complexities of high-tempo defense operations within a government infrastructure context.

What you'll do

  • Investigate and triage security alerts from endpoints, IDS/IPS, NetFlow data, and custom sensors to identify suspicious activity.
  • Analyze extensive log files and correlate diverse datasets to produce detailed technical findings and reports.
  • Integrate DoD and open-source threat intelligence feeds and Indicators of Compromise into SIEM platforms and security sensors.
  • Perform deep-dive investigations of complex security events by analyzing raw packet data and identifying malicious behavior.
  • Communicate security incidents clearly and timely to customers and USCYBERCOM.
  • Execute structured incident triage and escalation protocols within a 24/7 high-tempo environment.
  • Automate routine analytical tasks using basic scripting and programming skills.

What we're looking for

  • Active DoD Secret clearance with the ability to obtain and maintain a TS/SCI.
  • Current DoD 8570 IAT Level II certification, such as CompTIA Security+ CE, ISC2 SSCP, or SANS GSEC.
  • Ability to obtain a DoD 8570 CSSP-Analyst level certification within 180 days of hire.
  • Solid foundation in networking principles including packet analysis, ports/protocols, traffic flow, and defense-in-depth architecture.
  • Bachelor's degree and 2+ years of relevant experience (or equivalent professional work or military experience).
  • Bachelor's degree and 4+ years of relevant experience (or equivalent professional work or military experience).
  • Must be within a commutable distance or able to self-relocate to Scott AFB, IL.
  • Experience in DISA/DoD environments, MITRE ATT&CK frameworks, SIEM/SOAR platforms, cloud defense, and scripting (preferred).

More like this

Similar roles

Defensive Cybersecurity Analyst

Leidos

Whitehall, OH 33 days ago $69,550–$125,725
SIEM SOAR IDS/IPS NetFlow Packet Analysis Cyber Kill Chain AWS Azure GCP Scripting OSI Model Defense-in-Depth MDM MAM MTD
2+ yrs exp

Cyber Security Analyst

Leidos

Adelphi, MD 37 days ago $87,100–$157,450
SIEM IDS Incident Response NetFlow Packet Capture AWS Microsoft Azure Google Cloud Platform Oracle Cloud TCP/IP Unix Cyber Kill Chain SaaS Vulnerability Management Network Security Security+ CE CSSP-Infrastructure Support
4+ yrs exp Hybrid

Cyber Security Analyst

Leidos

Adelphi, MD 37 days ago $87,100–$157,450
SIEM IDS Incident Response NetFlow Packet Capture AWS Microsoft Azure Google Cloud Platform Oracle Cloud TCP/IP Unix Cyber Kill Chain SaaS Vulnerability Management Network Security Security+ CE CSSP-Infrastructure Support
4+ yrs exp Hybrid

Cyber Security Analyst

Leidos

Adelphi, MD 37 days ago $87,100–$157,450
SIEM IDS AWS Microsoft Azure Google Cloud Platform Oracle Cloud NetFlow Packet Capture TCP/IP Unix Incident Response Cyber Kill Chain SaaS Security+ CE CSSP-Infrastructure Support Vulnerability Management Network Security
4+ yrs exp Hybrid

Cyber Intel Analyst

Leidos

Washington, DC 16 days ago $87,100–$157,450
MITRE ATT&CK SIEM EDR Python PowerShell Bash Splunk KQL Elastic DSL AWS Azure O365 Threat Intelligence Platforms DFIR TCP/IP DNS HTTP/S IDS/IPS
4+ yrs exp Hybrid

Defensive Cyber Operations Analyst

Leidos

Washington, DC 51 days ago $87,100–$157,450
Cyber Network Defense Security Operations Center (SOC) SIEM Splunk Elastic IDS/IPS Firewalls PCAP Cyber Kill Chain Data Correlation Technical Writing
2+ yrs exp Hybrid