Security Operations Center (SOC) Analyst

Leidos

Confirmed live today High trust

Quick summary

Work type
On-site
Location
Alexandria, VA
Salary
$69,550–$125,725 / yr
Employment
Full-time
Posted
2 days ago
Freshness
Confirmed live today

Market check

Salary context

Below market

How this pay compares to similar roles

Similar $151k
This role $98k
$56k $198k
below market most similar roles pay here above market

This role pays less than 93% of similar roles. Most pay $116,875–$184,468 — the blue band above. At the midpoint, this role pays about $98k versus about $151k for comparable roles.

Based on 240 similar postings.

Employer

About Leidos

Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations.

Leidos currently has 399 open roles on FindRole.

Listed pay typically runs $92,300–$166,850 across 331 roles with salary data.

Most-posted roles

View all roles at Leidos

At a glance

TL;DR · Security Operations Center (SOC) Analyst

The Tier 2 Security Operations Center (SOC) Analyst joins the CyberPRIMES program to support the Defense Human Resources Activity and Defense Manpower Data Center. This role involves performing advanced analysis of cybersecurity events escalated from Tier 1 analysts or identified through enterprise monitoring. The analyst will correlate security telemetry to determine the scope and impact of suspicious activity, support incident triage and containment, preserve technical evidence, and coordinate with incident responders. Key responsibilities include troubleshooting cybersecurity tools, documenting investigative findings in government-approved systems, and tuning monitoring capabilities to reduce false positives. The position requires proficiency with Security Information and Event Management (SIEM) platforms, endpoint security, and network-security concepts. The work focuses on protecting a large repository of personnel and manpower data within a complex Department of Defense IT environment.

What you'll do

  • Perform advanced analysis of cybersecurity events escalated from Tier 1 analysts or identified through enterprise monitoring.
  • Correlate security telemetry to determine the nature, scope, severity, and potential impact of suspicious activity.
  • Distinguish between legitimate activity, false positives, policy violations, and potential cybersecurity incidents.
  • Support cybersecurity incident triage, escalation, and containment in coordination with the incident-response team.
  • Preserve relevant technical evidence and supporting information required for further investigation and incident response.
  • Document investigative actions, analysis, findings, and conclusions in Government-approved systems.
  • Perform Tier 2 troubleshooting of cybersecurity tools, alerts, security data, and related technical issues.
  • Identify detection gaps and recommend improvements to monitoring capabilities and SOC procedures.

What we're looking for

  • U.S. Citizenship is required.
  • Active Secret security clearance is required.
  • BS degree and 2+ years of relevant experience, or a Masters with less than 2 years of relevant experience.
  • Experience performing cybersecurity event analysis, SOC operations, cyber defense, incident triage, or security monitoring.
  • Experience analyzing and correlating alerts from multiple cybersecurity monitoring capabilities.
  • Experience investigating endpoint, network, user-activity, or other cybersecurity events.
  • Experience supporting cybersecurity incident escalation, containment, mitigation, or evidence preservation.
  • Experience using enterprise security-analysis or cybersecurity monitoring tools.
  • Experience performing Tier 2 cybersecurity troubleshooting.
  • Working knowledge of cybersecurity attack techniques, network-security concepts, endpoint security, event analysis, and incident-response processes.
  • Experience supporting a Department of Defense or Federal Security Operations Center (preferred).
  • Experience working in a 24x7 SOC or Cybersecurity Service Provider environment (preferred).
  • Experience with SIEM platforms and enterprise cybersecurity monitoring tools (preferred).
  • Experience tuning security alerts, detection logic, or monitoring capabilities (preferred).
  • Familiarity with Department of Defense cybersecurity requirements and Risk Management Framework processes (preferred).

More like this

Similar roles

Security Operations Center (SOC) Analyst

Leidos

Shiloh, IL 4 days ago $69,550–$125,725
SIEM SOAR Python PowerShell IDS IPS NetFlow Packet Analysis MITRE ATT&CK Cyber Kill Chain AWS Azure OSI Model Defense-in-Depth Threat Intelligence IOCs TTPs
2+ yrs exp

Security Operations Center (SOC) Analyst II

Leidos

Shiloh, IL 4 days ago $87,100–$157,450
SIEM SOAR Python PowerShell IDS/IPS NetFlow Packet Analysis MITRE ATT&CK Cyber Kill Chain AWS Azure OSI Model Security+ CySA+ CEH GCIA Threat Intelligence IOCs TTPs
4+ yrs exp

SOC Analyst

Leidos

Alexandria, VA 11 days ago $107,900–$195,050
Incident Response SIEM Splunk ArcSight QRadar LogLogic IDS/IPS Netflow Full Packet Capture Network Forensics Unix Linux TCP/IP MITRE ATT&CK Cyber Kill Chain Malware Analysis CompTIA Security+ CySA+ CEH GCIA
8+ yrs exp

Incident Response Analyst

Leidos

Alexandria, VA +1 2 days ago $87,100–$157,450
Incident Response SIEM IDS IPS Firewalls endpoint-security malware-prevention web-security NIPRNet SIPRNet Risk Management Framework eMASS Cybersecurity Operations Antispam
4+ yrs exp

Security Operations Center (SOC) Analyst II

General Dynamics

Bossier City, LA 31 days ago $76,565–$97,075
SOAR SIEM EDR XDR Splunk Microsoft Defender Microsoft Intune Entra ID Palo Alto Networks AWS Azure GCP Machine Learning AI MITRE ATT&CK TCP/IP NIST FISMA FedRAMP Incident Response Threat Hunting
3+ yrs exp Hybrid