R-00173461 Attack Sensing & Warning Analyst (AS&W Analyst)

Leidos

Quick summary

Work type
On-site
Location
Ashburn, Virginia
Salary
$87,100–$157,450 / yr
Posted
92 days ago

Market check

Salary context

Below market

How this pay compares to similar roles

Similar $163k
This role $122k
$74k most similar roles pay here $211k

This role pays less than 88% of similar roles. Most pay $140,975–$185,000 — the shaded band above. At the midpoint, this role pays about $122k versus about $163k for comparable roles.

Based on 239 similar postings.

Employer

About Leidos

Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations.

Leidos currently has 230 open roles on FindRole.

Listed pay typically runs $106,600–$192,700 across 218 roles with salary data.

Most-posted roles

View all roles at Leidos

At a glance

TL;DR · R-00173461 Attack Sensing & Warning Analyst (AS&W Analyst)

Leidos seeks an experienced Tier 2 Attack Sensing & Warning Analyst to join the CBP Security Operations Center team. This role involves leveraging advanced security technologies like EDR and SIEM tools to monitor, triage, and investigate endpoint and network activity, escalating alerts according to established procedures, analyzing attacker behaviors, aggregating IOCs, and developing security content and tools to enhance detection capabilities. The analyst will lead incident response activities, mentor junior staff, and create detailed reports for customer leadership. Essential skills include experience with email security, digital forensics, monitoring, incident response, vulnerability assessment, and cyber intelligence analysis, along with strong problem-solving abilities and the ability to communicate effectively with technical and non-technical stakeholders. Preferred qualifications include familiarity with frameworks like MITRE ATT&CK and experience in detection engineering to reduce false positives.

What you'll do

  • Utilize EDR, SIEM, and network security tools to monitor and investigate endpoint and network activity.
  • Triage alerts and determine the nature of activities on customer networks, systems, servers, and mobile devices.
  • Analyze logs and attacker behaviors to identify APT tactics and aggregate indicators of compromise (IOCs).
  • Develop security content, scripts, and tools to enhance detection and incident response capabilities.
  • Create detailed reports for customer leadership on a daily, weekly, and monthly basis.

What we're looking for

  • 5+ years of professional experience in incident detection, response, and remediation.
  • Extensive experience in email security, digital media forensics, monitoring and detection, incident response, vulnerability assessment, and cyber intelligence analysis.
  • Ability to analyze complex data sources, provide guidance on cyber threat operations, and mentor junior staff.
  • Strong problem-solving skills with an analytic mindset for identifying root causes of issues.
  • Possession of at least one relevant cybersecurity certification such as CompTIA CySA+, CISSP, or others listed.

More like this

Similar roles

Cybersecurity Analyst

Leidos

OH 30 days ago $69,550$125,725
SIEM SOAR AWS Azure GCP Python NetFlow Full Packet Capture IDS/IPS HIPS/HBSS Anti-Virus Network Forensics Mobile Device Management MAM MTD OSI Model Defense-in-Depth Packet Analysis Behavioral Analysis Statistical Analysis Machine Learning

Cyber Threat Intelligence Analyst

Leidos

9358 Undisclosed Dc Customer Site, US 84 days ago $107,900$195,050
MITRE ATT&CK Threat Intelligence Platform (TIP) Python PowerShell SPL KQL Elastic DSL AWS Azure O365 Cyber Kill Chain Diamond Model of Intrusion Analysis Anomali ThreatConnect MISP
Hybrid

Sr. Analyst, Cybersecurity

Carmax

Richmond, VA 13 days ago
Sarbanes-Oxley GLBA HIPAA CFPB PCI NIST COSO OWASP ISO-27001 CISSP CRISC CISA CISM BCBP CIA Terraform AWS Kubernetes Python SQL Git Jira Confluence
Hybrid

Cyber Security Risk Analyst

The Federal Reserve

New York, NY 37 days ago
NIST 800-53 DevSecOps CI/CD Cloud application security Application security testing Agile management Gen AI systems security U.S. Citizenship National Security Clearance

Sr Analyst, Cyber Defense

McDonald’s Corporation

Chicago, Illinois 34 days ago $127,332$159,165
SIEM EDR Python Autopsy Velociraptor Ghidra NIST Cybersecurity Framework Cyber Kill Chain SOAR Linux Windows MacOS CI/CD eDiscovery Forensics

Information Security Analyst

Apex

Belfast, Northern Ireland, United Kingdom 63 days ago
SIEM UEBA Threat_Intel EDR Firewalls NIDS NIPS HIDS HIPS DLP SOAR TCP/IP UDP DNS FTP SSH SSL_TLS HTTP PowerShell Python Bash .NET Ruby Java C Mitre_ATT&CK Cyber_Kill_Chain Network_Analysis Email_Security