Endpoint Security Analyst

Leidos

Confirmed live yesterday High trust
Hybrid

Quick summary

Work type
Hybrid
Location
Adelphi, MD
Salary
$107,900–$195,050 / yr
Employment
Full-time
Posted
39 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $178k
This role $151k
$95k most similar roles pay here $225k

This role pays less than 66% of similar roles. Most pay $143,012–$212,800 — the shaded band above. At the midpoint, this role pays about $151k versus about $178k for comparable roles.

Based on 240 similar postings.

Employer

About Leidos

Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations.

Leidos currently has 350 open roles on FindRole.

Listed pay typically runs $92,300–$166,850 across 299 roles with salary data.

Most-posted roles

View all roles at Leidos

At a glance

TL;DR · Endpoint Security Analyst

The Endpoint Security Analyst – Elastic Defend joins the Cyber Security Service Provider team to provide specialized expertise in protecting critical networks and data. In this role, you will deploy, configure, tune, and troubleshoot Elastic Agent and Elastic Defend technologies while optimizing endpoint protection and telemetry collection across enterprise environments. You will collaborate with threat and engineering teams to develop detection rules, create threat signatures based on MITRE ATT&CK techniques, and conduct host-based defensive cyber operations to investigate and remediate intrusions. Your daily work involves building dashboards, managing security policies, and performing forensic data collection using advanced queries. The role requires proficiency in Elastic tools, potentially including experience with CrowdStrike Falcon, McAfee/Trellix ePO, or Tanium. You will solve complex security challenges by improving visibility and responding to emerging threats within a mission-critical infrastructure.

What you'll do

  • Deploy, configure, and troubleshoot Elastic Agent and Elastic Defend across enterprise environments.
  • Optimize endpoint protection and telemetry collection to improve security visibility while maintaining system performance.
  • Develop custom detection rules and threat signatures based on intelligence and MITRE ATT&CK techniques.
  • Conduct host-based defensive operations to identify, investigate, and remediate vulnerabilities or intrusions.
  • Perform forensic data collection and advanced querying to support cyber investigations and rapid containment.
  • Create dashboards and reports to provide leadership with visibility into enterprise security status.
  • Coordinate with engineering teams to manage patches, hotfixes, and critical security updates for endpoint tools.
  • Develop and maintain standard operating procedures (SOPs) and policies for endpoint security configurations.

What we're looking for

  • Bachelor's degree in a STEM field, cybersecurity, or a related field.
  • 4+ years of relevant cybersecurity experience.
  • Hands-on experience deploying, configuring, and supporting enterprise endpoint security or EDR solutions.
  • Strong understanding of threat detection, incident investigation, and the MITRE ATT&CK framework.
  • U.S. citizenship and an active TS/SCI with SAP eligibility.
  • One of the following certifications: GIAC/SANS (GCIA, GCIH, GCFA, GCFE, GREM, GISF, GXPN, GWEB, GNFA, or GMON), Offensive Security (OSCP, OSCE, OSWP, or OSEE), ISC2 (CCFP or CISSP), or EC-Council (CEH, CHFI, LPT, ECSA, or ECI).
  • Experience with Elastic Agent and Elastic Defend, including deployment, configuration, and troubleshooting (preferred).
  • Experience with CrowdStrike Falcon, McAfee/Trellix ePO, Tanium, or other enterprise endpoint security platforms (preferred).

More like this

Similar roles

Principal Endpoint Security Systems Engineer

Leidos

Bethesda, MD 9 days ago $131,300–$237,350
Trellix ePolicy Orchestrator Trellix Endpoint Threat Protection Linux Windows Splunk AppDynamics AWS Cisco Secure Endpoint Rapid7 SolarWinds Cisco IDS/IPS VPN WebInspect AppDetective Incident Response Forensics Cloud Computing Hybrid Cloud
10+ yrs exp

Defensive Cybersecurity Analyst

Leidos

Shiloh, IL 35 days ago $69,550–$125,725
SIEM SOAR IDS/IPS NetFlow Packet Analysis MITRE ATT&CK Cyber Kill Chain AWS Azure GCP Scripting OSI Model Defense-in-Depth MDM MAM MTD
2+ yrs exp

Defensive Cybersecurity Analyst

Leidos

Whitehall, OH 35 days ago $69,550–$125,725
SIEM SOAR IDS/IPS NetFlow Packet Analysis Cyber Kill Chain AWS Azure GCP Scripting OSI Model Defense-in-Depth MDM MAM MTD
2+ yrs exp

Endpoint Detection & Response Engineer

Booz Allen Hamilton

Scott AFB, IL 98 days ago
EDR Carbon Black CrowdStrike Falcon SentinelOne FireEye HX McAfee MVision Microsoft Defender for Endpoint Tanium Elastic Endpoint Protection SIEM ITSM TIP Splunk SOC Systems Administration Playbooks

Senior Endpoint Detection & Response Engineer

Booz Allen Hamilton

Scott AFB, IL 98 days ago
EDR Carbon Black EDR CrowdStrike Falcon SentinelOne FireEye HX McAfee MVision Microsoft Defender for Endpoint Tanium Elastic Endpoint Protection SIEM ITSM TIP Splunk SOC Playbooks Systems Administration

Enterprise Endpoint Security Architect

Salesforce

Remote (Bellevue, WA) 32 days ago $218,400–$365,200
EDR XDR CSPM SSPM AWS Azure Kubernetes Docker Terraform Jenkins Spinnaker GitLab ELK Grafana AppDynamics Scrum DMARC
10+ yrs exp Remote