Incident Responder

Leidos

Confirmed live yesterday High trust

Quick summary

Work type
On-site
Location
Suitland, MD
Salary
$107,900–$195,050 / yr
Employment
Full-time
Posted
6 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $159k
This role $151k
$97k $214k
below market most similar roles pay here above market

This role pays less than 58% of similar roles. Most pay $114,652–$202,800 — the blue band above. At the midpoint, this role pays about $151k versus about $159k for comparable roles.

Based on 240 similar postings.

Employer

About Leidos

Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations.

Leidos currently has 399 open roles on FindRole.

Listed pay typically runs $92,300–$166,850 across 331 roles with salary data.

Most-posted roles

View all roles at Leidos

At a glance

TL;DR · Incident Responder

Incident Responder – Weekday 2nd and 3rd Shifts will join a mission-focused team supporting the Navy's cybersecurity environment at the Office of Naval Intelligence. Serving as a digital first responder, the individual will investigate and respond to cybersecurity incidents, contain affected systems, and analyze digital artifacts to protect critical maritime intelligence networks. Key responsibilities include performing all phases of the incident response lifecycle, conducting spillage response, and monitoring Data Loss Prevention outputs. The role requires proficiency with SIEM systems like Splunk and Elastic, NIDPS such as Cisco FirePower and Palo Alto NGFW, and host-based tools like Trellix ePO, Microsoft Defender, and Tanium. Candidates must also possess knowledge of scripting languages including Python and PowerShell, as well as penetration testing tools like Kali and Metasploit.

What you'll do

  • Perform all phases of the incident response lifecycle including detection, analysis, containment, eradication, and recovery.
  • Investigate and respond to cybersecurity incidents to contain affected systems and limit operational impact.
  • Act on escalations from Tier 1 analysts and conduct spillage response and cleanup activities.
  • Monitor Data Loss Prevention (DLP) outputs for classified code words and potential spillage indicators.
  • Prepare and submit Electronic Spillage Assessment Forms (ESAFs) to the NNWC Electronic Spillage Center.
  • Maintain detailed incident documentation, timelines, and participate in after-action reviews.
  • Coordinate with internal and external stakeholders including Special Security Officers and other IC/DoD SOC teams.
  • Support the execution and evaluation of annual security exercises.

What we're looking for

  • Active TS/SCI security clearance in DISS.
  • Bachelor's degree in Cybersecurity, IT, Information Assurance, or related field with 8+ years of experience.
  • Master's degree with 6+ years of experience.
  • Additional experience may be considered in lieu of a degree.
  • Extensive experience in the Computer Network Defense (CND) discipline.
  • Significant professional experience monitoring, analyzing, and investigating alerts generated by cybersecurity tools.
  • Experience with SIEM systems such as Splunk and Elastic.
  • Experience with NIDPS (Cisco FirePower, Palo Alto NGFW) and host-based tools (Trellix ePO, Microsoft Defender, Tanium).
  • Knowledge of scripting and coding languages such as Python, Perl, Ruby, JavaScript, PowerShell, C, C++, and Java.
  • Knowledge of penetration testing and red team tactics, including tools like Kali, Nmap, and Metasploit.
  • Knowledge of ticketing systems, report writing, and cybersecurity intelligence gathering and analysis.
  • Must possess one of the following active certifications: Security+, CySA+, PenTest+, Cloud+, CEH, FITSP O, GMON, GRID, GCIA, GCIH, GICSP, GCED, GDSA, GSEC, CFR, or Cisco CyberOps.

More like this

Similar roles

Cyber Defense Analyst

Leidos

Suitland, MD 6 days ago $87,100–$157,450
Computer Network Defense (CND) SIEM Splunk Elastic NIDPS Cisco FirePower Palo Alto NGFW Trellix ePO Microsoft Defender Tanium Python PowerShell Java C C++ Ruby Perl JavaScript Kali Nmap Burp Suite Metasploit sqlmap SamuraiWTF Threat Hunting Ticketing Systems
4+ yrs exp

Incident Response Analyst

Leidos

Alexandria, VA +1 2 days ago $87,100–$157,450
Incident Response SIEM IDS IPS Firewalls endpoint-security malware-prevention web-security NIPRNet SIPRNet Risk Management Framework eMASS Cybersecurity Operations Antispam
4+ yrs exp

Senior Incident Response Analyst

Leidos

Arlington, VA 21 days ago $131,300–$237,350
Incident Response EDR IDS SIEM Python PowerShell Bash Malware Analysis Computer Forensics Windows Linux Firewalls Proxies Load Balancers VPN ATT&CK Framework Cyber Kill Chain FISMA
10+ yrs exp

Cyber Defense Analyst

Leidos

Suitland, MD 10 days ago $87,100–$157,450
SIEM Splunk Elastic NIDPS Cisco FirePower Palo Alto NGFW Trellix ePO Microsoft Defender Tanium Python PowerShell Ruby Perl JavaScript C C++ Java Kali Nmap Burp Suite sqlmap Metasploit Threat Hunting Penetration Testing
4+ yrs exp

Network Security Tools Engineer

Leidos

Suitland, MD 9 days ago $107,900–$195,050
SIEM IDS/IPS Firewalls Endpoint Security Packet Capture Network Visibility Splunk Microsoft Sentinel Elastic CrowdStrike Palo Alto Networks Wireshark SteelCloud Python PowerShell Bash AWS Azure Google Cloud Platform TCP/IP DNS DHCP HTTP/S Linux Windows
8+ yrs exp

Incident Responder

Salesforce

McLean, VA +1 18 days ago $96,300–$145,200
Incident Response Security Operations DNS HTTP HTTPS/TLS SMTP macOS Microsoft Windows Linux/Unix Firewalls Proxies Antivirus File Integrity Monitoring OS Logs GenAI Agentic AI Prompt Engineering
2+ yrs exp Hybrid