Cyber Real-Time Analyst

Leidos

Pearl City (HI)

On-site

USD 70,000 - 126,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Leidos seeks Real Time Analysts to join the Network Assurance Team supporting DISA Pacific at Ford Island, Pearl Harbor-Hickam. You will monitor, analyze, and respond to threats across the DoDIN/DODN boundary 24/7 using SIEM tools and threat-hunting playbooks.

Role requires TS clearance, DoD cyber defense experience, and collaboration with DJOC, USCYBERCOM, and partner SOCs to protect USPACOM infrastructure.

Qualifications

  • Active Top Secret security clearance with eligibility/ability to obtain SCI.
  • Level II/III education and experience requirements per DoD standards.

Responsibilities

  • Monitor, detect, and analyze intrusions, incidents, and threats for DoD networks on a 24/7/365 basis.
  • Perform near real-time triage of security events and correlate alerts to confirm or refute malicious activity.
  • Investigate events using SIEM platforms (Splunk, Elastic, Microsoft Sentinel) and correlate data.
  • Develop threat-hunting playbooks and tune detection signatures to mitigate threats.
  • Coordinate with DISA and fellow SOCs to synchronize threat intelligence and response.

Skills

SIEM
MITRE ATT&CK
JIRA
Splunk
Elastic
Microsoft Sentinel
Corelight

Education

Bachelor's degree

Tools

JIRA
Splunk
Elastic
Microsoft Sentinel
Corelight

Job description

Description

Join the Team Defending the Pacific's Front Line in Cyberspace Leidos is hiring Real Time Analysts to join the Network Assurance Team supporting DISA Pacific (DNC-PAC) at Ford Island, Joint Base Pearl Harbor-Hickam. This team serves as the Security Operations Center (SOC) for USPACOM and the broader DoD Information Network (DODIN/DISN), standing watch 24/7/365 to detect, analyze, and respond to threats against the boundary of the Department of Defense's global network.

Join the Team Defending the Pacific's Front Line in Cyberspace Leidos is hiring Real Time Analysts to join the Network Assurance Team supporting DISA Pacific (DNC-PAC) at Ford Island, Joint Base Pearl Harbor-Hickam. This team serves as the Security Operations Center (SOC) for USPACOM and the broader DoD Information Network (DODIN/DISN), standing watch 24/7/365 to detect, analyze, and respond to threats against the boundary of the Department of Defense's global network.

What You\'ll Do

Boundary Cyber Defense & SOC Operations

  • Monitor, detect, and analyze intrusions, incidents, and threats across the DODIN/DISN boundary — Internet Access Points, Boundary Cloud Access Points, and related infrastructure — using DoD-approved network monitoring and traffic analysis tools on a 24/7/365 basis.
  • Perform near real-time triage of security events, correlating alerts,netflow, IDS/IPS output, and raw packet captures to confirm or refute malicious activity.
  • Conduct deep-dive analysis of “low and slow” activity to uncover unauthorized access that automated tools miss.
  • Investigate and analyze events using SIEM platforms including Splunk, Elastic, and Microsoft Sentinel, and correlate sensor data through the ThunderDome cybersecurity suite.
  • Apply the MITRE ATT&CK framework to characterize adversary tactics, techniques, and procedures, and to guide incident analysis and threat-hunting.
  • Develop, tune, and recommend custom detection signatures and countermeasures to prevent or mitigate emerging threats.
  • Document analysis and findings in the DoD-mandated incident reporting/ticketing system, and issue Situational Awareness Reports and TIPPERs to mission partners.
  • Coordinate directly with the DISA Joint Operations Center (DJOC), USCYBERCOM, and peer SOCs to synchronize threat intelligence and incident response across the DODIN.

Joint Fires Network (JFN) SOC Support

  • Support stand-up and sustainment of a 24x7x365 Security Operations Center for the JFN IL-6 environment, focused on threat detection and continuous monitoring across JFN nodes.
  • Conduct Syslog review and Elastic stack alerting to identify anomalies, and tune advanced sensors such as Corelight as the SOC matures.
  • Triage, escalate, and track incidents through JIRA using standardized SOC intake and escalation processes.
  • Handle TS/SCI-level incidents in accordance with DIA-aligned requirements, ensuring spills, breaches, or anomalies are reported through authorized channels within mandated timelines.
  • Develop threat-hunting playbooks focused on behavioral anomalies and traffic pattern analysis as the mission matures from initial monitoring into full detection and response.
  • Work from a Sensitive Compartmented Information Facility (SCIF) at DISA Pacific, Ford Island.

What You\'ll Need For Success

  • Active Top Secret security clearance with eligibility/ability to obtain SCI
  • Education and experience requirements depending on job level, as follows:
    • Level II: Bachelor\'s degree and 2+ years of relevant experience; equivalent work experience and/or military service may be considered in lieu of a degree.
    • Level III: Bachelor\'s degree and 4+ years of relevant experience; equivalent work experience and/or military service may be considered in lieu of a degree.
  • Qualifications/credentials compliant with DoD 8140 DCWF Code 531, Cyber Defense Analyst at the Intermediate proficiency level.
  • Hands-on experience with Computer Network Defense duties — protect, defend, respond, and sustain.
  • Strong networking fundamentals, including communication protocols and common security tooling (IDS/IPS, firewalls).
  • Experience evaluating packet captures and analyzing raw network traffic.
  • Willingness and ability to work rotating shifts in support of 24/7/365 operations, including some after-hours and surge support.

Preferred Qualifications

  • AI capability development and implementation to automate analysis and detection tasks.
  • Working knowledge of adversary tactics, techniques, and procedures (TTPs), and familiarity with MITRE ATT&CK and the Cyber Kill Chain.
  • Direct experience with Splunk, Elastic, or similar SIEM/detection platforms.
  • Familiarity with JIRA-based incident workflows and/or SOC intake and escalation processes.
  • Understanding of software exploits, and experience analyzing packed or obfuscated code.

Why This Role?

  • Direct, high-visibility mission impact defending USPACOM and DODIN/DISN infrastructure in a strategically critical theater.
  • Ground-floor opportunity to help build a new SOC capability alongside an established, mature SOC operation.
  • Daily collaboration with DISA, USCYBERCOM, and Government leadership — direct exposure to enterprise-level cyber defense decision-making.
  • Long-term program stability: multi-year task order (base plus four option years) with an established incumbent team.

If you\'re looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We\'re not hiring followers. We\'re recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We\'re already at step 30 — and moving faster than anyone else dares.

Original Posting

August 10, 2026

For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

Pay Range

Pay Range $69,550.00 - $125,725.00

The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

About Leidos

Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $16.7 billion for the fiscal year ended January 3, 2025. For more information, visit www.Leidos.com.

Pay And Benefits

Pay and benefits are fundamental to any career decision. That\'s why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available at www.leidos.com/careers/pay-benefits.

Securing Your Data

Beware of fake employment opportunities using Leidos\’ name. Leidos will never ask you to provide payment-related information during any part of the employment application process (i.e., ask you for money), nor will Leidos ever advance money as part of the hiring process (i.e., send you a check or money order before doing any work). Further, Leidos will only communicate with you through emails that are generated by the Leidos.com automated system – never from free commercial services (e.g., Gmail, Yahoo, Hotmail) or via WhatsApp, Telegram, etc. If you received an email purporting to be from Leidos that asks for payment-related information or any other personal information (e.g., about you or your previous employer), and you are concerned about its legitimacy, please make us aware immediately by emailing us at LeidosCareersFraud@leidos.com.

If you believe you are the victim of a scam, contact your local law enforcement and report the incident to the U.S. Federal Trade Commission.

Commitment to Non-Discrimination

All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Real-Time Analyst
Cyber Real-Time Analyst

Leidos Inc • Pearl City (HI)

On-site
USD 70,000 - 126,000
Cyber Security Analyst
Cyber Security Analyst

Leidos • Fort Belvoir (VA)

On-site
USD 87,000 - 157,000
Cyber Fusion and Threats Analyst
Cyber Fusion and Threats Analyst

Via Logic LLC • Odenton (MD)

On-site
USD 108,000 - 195,000
Defensive Cyber Operations Analyst
Defensive Cyber Operations Analyst

Leidos • Washington

Hybrid
USD 87,000 - 157,000
Cybersecurity Analyst Intern
Cybersecurity Analyst Intern

Leidos • Pearl City (HI)

On-site
USD 48,000 - 87,000
Defensive Cyber Operations Analyst
Defensive Cyber Operations Analyst

Leidos Inc • Washington

Hybrid
USD 87,000 - 157,000
Cloud Security Team Lead
Cloud Security Team Lead

Via Logic LLC • Scott Air Force Base (IL)

On-site
USD 117,000 - 196,000
Cyber Security Analyst
Cyber Security Analyst

Leidos • Adelphi (MD)

Hybrid
USD 87,000 - 157,000
Health and Wellness programs
Paid Leave
Retirement plan
Senior Media Malware Analyst & Threat Forensics Lead
Senior Media Malware Analyst & Threat Forensics Lead

Leidos • United States

On-site
SOC Lead
SOC Lead

Leidos • Alexandria (VA)

On-site
USD 131,000 - 237,000