Defensive Cybersecurity Analyst

Leidos

Confirmed live today High trust

Quick summary

Work type
On-site
Location
Whitehall, OH
Salary
$69,550–$125,725 / yr
Employment
Full-time
Posted
33 days ago
Freshness
Confirmed live today

Market check

Salary context

Below market

How this pay compares to similar roles

Similar $150k
This role $98k
$56k most similar roles pay here $197k

This role pays less than 95% of similar roles. Most pay $122,275–$177,250 — the shaded band above. At the midpoint, this role pays about $98k versus about $150k for comparable roles.

Based on 240 similar postings.

Employer

About Leidos

Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations.

Leidos currently has 340 open roles on FindRole.

Listed pay typically runs $92,300–$166,850 across 294 roles with salary data.

Most-posted roles

View all roles at Leidos

At a glance

TL;DR · Defensive Cybersecurity Analyst

As a Defensive Cybersecurity Analyst on the front-line security operations team, you will protect Department of Defense networks against sophisticated and rapidly evolving cyber threats. You will be responsible for investigating and triaging security alerts from endpoints, IDS/IPS, NetFlow data, and custom sensors to identify suspicious activity. Your daily work involves analyzing extensive log files, correlating diverse datasets to support incident investigations, and integrating threat intelligence feeds into SIEM platforms. To succeed, you must possess a strong understanding of networking principles, packet analysis, and defense-in-depth architecture. You will utilize tools such as SIEM/SOAR platforms while applying frameworks like MITRE ATT&CK or the Cyber Kill Chain to analyze adversary tactics. The role requires proficiency in identifying indicators of compromise and performing behavioral analysis to defend critical infrastructure against complex malicious activities.

What you'll do

  • Investigate and triage security alerts from endpoints, IDS/IPS, NetFlow data, and custom sensors to identify suspicious activity.
  • Analyze extensive log files and correlate diverse datasets to produce detailed technical findings and reports.
  • Integrate DoD and open-source threat intelligence feeds and Indicators of Compromise into security sensors and SIEM platforms.
  • Perform deep-dive investigations of complex security events by analyzing raw packet data and identifying malicious behavior.
  • Communicate security incidents clearly and timely to customers and USCYBERCOM.
  • Execute structured incident triage and escalation protocols within a 24x7 Security Operations Center environment.
  • Utilize SIEM/SOAR platforms to perform behavioral and statistical analysis across multiple log types.

What we're looking for

  • Active DoD Secret clearance with the ability to obtain and maintain a TS/SCI.
  • Current DoD 8570 IAT Level II certification (e.g., Security+, SSCP, or GSEC).
  • Ability to obtain a DoD 8570 CSSP-Analyst level certification within 180 days of hire.
  • Bachelor's degree and 2+ years of relevant experience (or equivalent professional/military experience).
  • Solid foundation in networking principles including packet analysis, ports, protocols, and defense-in-depth architecture.
  • Experience working within DISA or DoD environments (preferred).
  • Experience using MITRE ATT&CK or Cyber Kill Chain frameworks to defend against known TTPs (preferred).
  • Proficiency with SIEM/SOAR platforms, cloud security, mobile management, or scripting for automation (preferred).

More like this

Similar roles

Defensive Cybersecurity Analyst

Leidos

Shiloh, IL 33 days ago $69,550–$125,725
SIEM SOAR IDS/IPS NetFlow Packet Analysis MITRE ATT&CK Cyber Kill Chain AWS Azure GCP Scripting OSI Model Defense-in-Depth MDM MAM MTD
2+ yrs exp

Cyber Security Analyst

Leidos

Adelphi, MD 37 days ago $87,100–$157,450
SIEM IDS Incident Response NetFlow Packet Capture AWS Microsoft Azure Google Cloud Platform Oracle Cloud TCP/IP Unix Cyber Kill Chain SaaS Vulnerability Management Network Security Security+ CE CSSP-Infrastructure Support
4+ yrs exp Hybrid

Cyber Security Analyst

Leidos

Adelphi, MD 37 days ago $87,100–$157,450
SIEM IDS Incident Response NetFlow Packet Capture AWS Microsoft Azure Google Cloud Platform Oracle Cloud TCP/IP Unix Cyber Kill Chain SaaS Vulnerability Management Network Security Security+ CE CSSP-Infrastructure Support
4+ yrs exp Hybrid

Cyber Security Analyst

Leidos

Adelphi, MD 37 days ago $87,100–$157,450
SIEM IDS AWS Microsoft Azure Google Cloud Platform Oracle Cloud NetFlow Packet Capture TCP/IP Unix Incident Response Cyber Kill Chain SaaS Security+ CE CSSP-Infrastructure Support Vulnerability Management Network Security
4+ yrs exp Hybrid

Defensive Cyber Operations Analyst

Leidos

Washington, DC 51 days ago $87,100–$157,450
Cyber Network Defense Security Operations Center (SOC) SIEM Splunk Elastic IDS/IPS Firewalls PCAP Cyber Kill Chain Data Correlation Technical Writing
2+ yrs exp Hybrid

Defensive Cyber Operations Analyst

Booz Allen Hamilton

Peterson AFB, CO 2 days ago $69,300–$158,000
Splunk HBSS Microsoft Defender Security Onion SIGACT RALLY Incident Response Threat Intelligence Network Security Cybersecurity Information Assurance NetOps AI
1+ yrs exp