R-00173461 Attack Sensing & Warning Analyst (AS&W Analyst)

Leidos

Quick summary

Work type
On-site
Location
Ashburn, VA
Salary
$87,100–$157,450 / yr
Posted
2 days ago

Market check

Salary context

Below market

How this pay compares to similar roles

Similar $167k
This role $122k
$74k most similar roles pay here $211k

This role pays less than 88% of similar roles. Most pay $142,400–$191,500 — the shaded band above. At the midpoint, this role pays about $122k versus about $167k for comparable roles.

Based on 239 similar postings.

Employer

About Leidos

Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations.

Leidos currently has 237 open roles on FindRole.

Listed pay typically runs $107,900–$195,050 across 230 roles with salary data.

Most-posted roles

View all roles at Leidos

At a glance

TL;DR · R-00173461 Attack Sensing & Warning Analyst (AS&W Analyst)

Leidos seeks an experienced Tier 2 Attack Sensing & Warning Analyst to join the Customs and Border Protection (CBP) Security Operations Center team. This role involves leveraging advanced security technologies such as EDR, SIEM, and network forensics tools to monitor, triage, and investigate endpoint and network activity, escalating alerts according to established procedures, analyzing attacker behaviors, aggregating IOCs, and developing security content and tools to enhance detection and response capabilities. The analyst will also lead incident response activities, mentor junior staff, and create detailed reports for customer leadership. Essential skills include extensive experience in areas like email security, digital forensics, monitoring, and cyber intelligence analysis, along with strong problem-solving abilities and the capability to stay updated on threat intelligence trends. Preferred qualifications include detection engineering expertise, familiarity with frameworks such as MITRE ATT&CK, and relevant certifications like CompTIA CySA+ or CEH.

What you'll do

  • Utilize EDR, SIEM, and network security tools to monitor and investigate endpoint and network activity.
  • Triage alerts from multiple sources and escalate according to established procedures.
  • Analyze logs and attacker behaviors to identify APT tactics and aggregate IOCs.
  • Develop security content, scripts, and tools to enhance detection and incident response capabilities.
  • Lead Incident Response activities and mentor junior SOC staff.

What we're looking for

  • 5+ years of professional experience in incident detection, response, and remediation.
  • Extensive experience in email security, digital media forensics, monitoring and detection, incident response, vulnerability assessment, and cyber intelligence analysis.
  • Ability to analyze complex data sources, provide guidance on cyber threat operations, and mentor junior staff.
  • Strong problem-solving skills with an analytic mindset for reasoning and independent task prioritization.
  • Possession of at least one relevant cybersecurity certification such as CompTIA CySA+, CISSP, or others listed.

More like this

Similar roles

Cybersecurity Analyst

Leidos

OH +2 2 days ago $69,550$125,725
SIEM SOAR NetFlow Full Packet Capture AWS Azure GCP Python Shell_scripting Cisco_IDS Snort Talos_Intelligence OSI_Model DoD_8570_IAT_Level_II CEH CySA+_GCIA

Cyber Threat Intelligence Analyst

Leidos

9358 Undisclosed Dc Customer Site, US 100 days ago $107,900$195,050
MITRE ATT&CK Threat Intelligence Platform (TIP) Python PowerShell SPL KQL Elastic DSL AWS Azure O365 Cyber Kill Chain Diamond Model of Intrusion Analysis Anomali ThreatConnect MISP
Hybrid

Technical Security Analyst

CVS Health

Remote (Work At Home-Florida, US) 3 days ago $72,100$173,040
NIST ISO HITRUST HIPAA PCI CISSP CRISC IaaS PaaS SaaS API Encryption Container Security Security Risk Management Cloud Security Architecture Information security policies Security development methodologies
Remote

Cyber Security Analyst

Nvidia

Remote (Virginia, VA) +2 9 days ago $160,000$258,750
AWS Azure GCP Kubernetes Python Go Docker MITRE ATT&CK CI/CD Terraform Prometheus Grafana Splunk SIEM SOC Digital_Forensics Malware_Analysis
Remote

Sr. Analyst, Cybersecurity

Carmax

Richmond, VA 4 days ago
Sarbanes-Oxley GLBA HIPAA CFPB PCI NIST COSO OWASP ISO-27001 ITIL CRISC CISA CISM BCBP CIA CISSP Kubernetes AWS Azure GCP Terraform Python SQL PostgreSQL Docker CI/CD
Hybrid

Cyber Security Risk Analyst

The Federal Reserve

New York, NY 53 days ago
NIST 800-53 DevSecOps CI/CD Cloud application security Application security testing Agile management Gen AI systems security U.S. Citizenship National Security Clearance