An application made for this job — a tailored resume and cover letter that speak straight to the posting.
Leidos is hiring Real Time Analysts to join the Network Assurance Team at Ford Island, Pearl Harbor, to defend DODIN/DISN boundaries. You'll monitor and analyze threats 24/7, using SIEM tools and best practices, while coordinating with DISA/JOC and USCYBERCOM to maintain mission readiness.
The role supports the JFN SOC as it stands up, requiring rotating shifts and TS/SCI eligibility. This is a high-visibility defense position with multi-year mission impact.
Leidos is hiring Real Time Analysts to join the Network Assurance Team supporting DISA Pacific (DNC-PAC) at Ford Island, Joint Base Pearl Harbor-Hickam. This team serves as the Security Operations Center (SOC) for USPACOM and the broader DoD Information Network (DODIN/DISN), standing watch 24/7/365 to detect, analyze, and respond to threats against the boundary of the Department of Defense's global network.
You'll work at the intersection of two missions: the established DISA SOC boundary defense operation that protects the DODIN's Pacific footprint, and the emerging Joint Fires Network (JFN) Security Operations Center supporting a next generation, TS/SCI-level sensor and detection environment being stood up at the same location.It's a rare opportunity to defend mature, mission-critical infrastructure while helping build a brand-new SOC capability from the ground up.
Monitor, detect, and analyze intrusions, incidents, and threats across the DODIN/DISN boundary - Internet Access Points, Boundary Cloud Access Points, and related infrastructure - using DoD-approved network monitoring and traffic analysis tools on a 24/7/365 basis.
Perform near real-time triage of security events, correlating alerts,netflow, IDS/IPS output, and raw packet captures to confirm or refute malicious activity.
Conduct deep-dive analysis of "low and slow" activity to uncover unauthorized access that automated tools miss.
Investigate and analyze events using SIEM platforms including Splunk, Elastic, and Microsoft Sentinel, and correlate sensor data through the ThunderDome cybersecurity suite.
Apply the MITRE ATT&CK framework to characterize adversary tactics, techniques, and procedures, and to guide incident analysis and threat-hunting.
Develop, tune, and recommend custom detection signatures and countermeasures to prevent or mitigate emerging threats.
Document analysis and findings in the DoD-mandated incident reporting/ticketing system, and issue Situational Awareness Reports and TIPPERs to mission partners.
Coordinate directly with the DISA Joint Operations Center (DJOC), USCYBERCOM, and peer SOCs to synchronize threat intelligence and incident response across the DODIN.
Support stand-up and sustainment of a 24x7x365 Security Operations Center for the JFN IL-6 environment, focused on threat detection and continuous monitoring across JFN nodes.
Conduct Syslog review and Elastic stack alerting toidentifyanomalies, andtune advanced sensors such asCorelightas the SOC matures.
Triage, elevate, and track incidents through JIRA using standardized SOC intake and escalation processes.
Handle TS/SCI-level incidentsin accordance withDIA-aligned requirements, ensuring spills, breaches, or anomalies are reported through authorized channels within mandated timelines.
Develop threat-hunting playbooks focused on behavioral anomalies and traffic pattern analysis as the mission matures frominitialmonitoring into full detection and response.
Work from a Sensitive Compartmented Information Facility (SCIF) at DISA Pacific, Ford Island.
Active Top Secret security clearance with eligibility/ability to obtain SCI
Education and experience requirements depending on job level, as follows:
Qualifications/credentials compliant with DoD 8140 DCWF Code 531, Cyber Defense Analyst at the Intermediateproficiencylevel.
Hands-on experience with Computer Network Defense duties - protect, defend, respond, and sustain.
Strong networking fundamentals, including communication protocols and common security tooling (IDS/IPS, firewalls).
Experience evaluating packet captures and analyzing raw network traffic.
Willingness and ability to work rotating shifts in support of 24/7/365 operations, including some after-hours and surge support.
AI capability development and implementation to automate analysis and detection tasks.
Working knowledge of adversary tactics, techniques, and procedures (TTPs), and familiarity with MITRE ATT&CK and the Cyber Kill Chain.
Direct experience with Splunk, Elastic, or similar SIEM/detection platforms.
Familiarity with JIRA-based incident workflows and/or SOC intake and escalation processes.
Understanding of software exploits, and experience analyzing packed or obfuscated code.
If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo - because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 - and moving faster than anyone else dares.
For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.
Pay Range $69,550.00 - $125,725.00
Pay and benefits are fundamental to any career decision. That's why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available at www.leidos.com/careers/pay-benefits.
Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $16.7 billion for the fiscal year ended January 3, 2025. For more information, visit www.Leidos.com.
All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.