About this role
Cyber Defense Analyst – Weekday 1st, 2nd and 3rd Shifts
Location: Suitland, MD Clearance: Active TS/SCI Schedule: Full Time, Monday through Friday
Leidos is hiring three Cyber Defense Analysts to join a mission focused team supporting the Navy's cybersecurity environment at the Office of Naval Intelligence (ONI) Hopper Global Communications Center (HGCC) in Suitland, MD.
We have one opening for each of the following Monday through Friday shifts:
Weekdays 1st Shift Monday through Friday: 0730 to 1530
Weekdays 2nd Shift Monday through Friday: 1530 to 2330
Weekdays 3rd Shift Monday through Friday: 2330 to 0730
Work Location and Hours
These are full-time, onsite positions supporting a 24 hour cybersecurity operation.
Training Schedule: For up to the first two months of employment, all selected candidates will be required to complete training during the day shift, Monday through Friday. Candidates must be available to work the day shift throughout the initial training period, regardless of their regular shift schedule.
Regular Work Schedule: Upon completion of training, each Cyber Defense Analyst will transition to the 1st, 2nd, or 3rd shift schedule for which they were hired. Occasional additional or alternate shift coverage may be required to support team coverage, employee leave, or other program and staffing needs.
In this role, you will serve on the front line of cyber defense, helping protect critical TS/SCI networks by monitoring and investigating cybersecurity alerts, identifying potential threats, and supporting proactive threat hunting activities. You will apply your experience in the Computer Network Defense (CND) discipline and knowledge of IT systems and networks to analyze security events, manage incident tickets, support intelligence gathering and analysis, and communicate findings to key stakeholders.
Primary Responsibilities
- Perform first line monitoring of security tools and conduct initial analysis of alerts for TS/SCI networks, including JWICS, ATLAS, and other networks for which HGCC is responsible.
- Monitor organizational cybersecurity tools for alerts, anomalies, and indicators of compromise.
- Investigate and perform initial technical analysis of cybersecurity alerts and events, escalating potential incidents to Tier 2 as appropriate.
- Create, update, and manage incident and event tickets within the approved ticketing system.
- Conduct proactive threat hunting activities to identify potential malicious activity and emerging threats.
- Perform wireless security scans of facilities and document and report findings.
- Correlate alerts and security events across multiple platforms to identify patterns, trends, and potential threats.
- Prepare and deliver operational and situational awareness briefings.
- Support annual cyber defense exercises.
Required Qualifications
- Bachelor's degree in Cybersecurity, Information Technology, Information Assurance, or a related area of study desired with 4+ years of experience or Master’s degree with 2+ years of experience. Additional experience may be considered in lieu of a degree.
- Active TS/SCI security clearance in DISS.
- Concentrated experience in the Computer Network Defense (CND) discipline, regardless of degree.
- Experience monitoring and investigating alerts from cybersecurity tools.
- Experience with Security Information and Event Management (SIEM) systems such as Splunk and Elastic.
- Experience with Network Intrusion Detection/Prevention Systems (NIDPS), such as Cisco FirePower and Palo Alto NGFW, as well as host based tools such as Trellix ePO, Microsoft Defender, and Tanium.
- Knowledge of scripting and coding languages such as Python, Perl, Ruby, JavaScript, PowerShell, C, C++, and Java.
- Knowledge of penetration testing and red team tactics, techniques, and procedures, as well as tools such as Kali, SamuraiWTF, Nmap, Burp Suite, sqlmap, and Metasploit.
- Knowledge of ticketing systems, report writing, and intelligence gathering, analysis, and dissemination techniques specific to cybersecurity.
- Strong analytical, conceptual, and problem solving skills.
Required Certifications
- Must possess one of the following active certifications: CompTIA Security+, CompTIA CySA+, CompTIA PenTest+, CompTIA Cloud+, CEH, FITSP O, GIAC GMON, GIAC GRID, GIAC GCIA, GIAC GCIH, GIAC GICSP, GIAC GCED, GIAC GDSA, GIAC GSEC, CFR, or Cisco CyberOps.
Pay Range Pay Range $87,100.00 - $157,450.00
The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.