Cyber Security Analyst

Leidos LLC

Adelphi (MD)

Hybrid

USD 87,000 - 157,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Leidos is seeking a Cyber Security Analyst to support the C5ISR Defensive Cyber Solutions Branch (DCSB) and help protect DoD networks, systems, and data from sophisticated cyber threats. You’ll join a high-visibility SOC providing 24x7 operations across on-prem and cloud platforms.

The role requires incident response leadership, SIEM tuning, and log analysis. Ideal candidates have 4–8 years’ cybersecurity experience, a TS/SCI with SAP eligibility, Security+ CE, and CSSP‑Infrastructure

Qualifications

  • Bachelor's degree in cybersecurity or related field.
  • Hands-on experience with SIEM and security monitoring.
  • Experience analyzing security logs, NetFlow, and packet captures.

Responsibilities

  • Lead and coordinate investigations throughout the Incident Response lifecycle.
  • Correlate and analyze security events, logs, and network data.
  • Acquire and analyze endpoint/network artifacts to identify activity.
  • Identify attacker TTPs and IOCs to strengthen detection and response.
  • Tune and maintain SIEM/IDS to reduce false positives.
  • Develop and maintain IR processes, workflows, and playbooks.
  • Document investigations and prepare actionable incident reports.
  • Collaborate with cyber professionals to defend the DoDIN against threats.

Skills

SIEM
NetFlow analysis
Packet capture analysis
TCP/IP understanding
Cloud security concepts
Unix-based systems
Team collaboration

Education

Bachelor's degree in cybersecurity or related field

Tools

SIEM
IDS/IPS

Job description

Ready to take your cybersecurity experience beyond routine alert monitoring? Leidos is seeking a Cyber Security Analyst to support the C5ISR Defensive Cyber Solutions Branch (DCSB) and help protect critical Department of War networks, systems, and data from sophisticated cyber threats. You'll join a high-visibility Security Operations Center (SOC) providing 24x7x365 defensive cyber operations, including continuous monitoring, threat detection, incident response, and vulnerability management. Our team protects a diverse, multi-tenant environment spanning on-premises infrastructure and leading cloud platforms, including AWS, Microsoft Azure, Google Cloud Platform (GCP), Oracle Cloud, and SaaS environments. If you thrive on investigating complex threats, analyzing network activity, and working alongside experienced cyber professionals to defend critical missions, we want to hear from you.

Location: Hybrid - 3 days on site at Adelphi, MD

Schedule: Full Time | Swing Shift: 2:00 p.m. to 10:00 pm

Clearance: U.S. Citizenship with an active TS/SCI with SAP Eligibility Required

Certifications: Baseline certification (Security+ CE) and CSSP-Infrastructure Support

Primary Responsibilities
  • Lead and coordinate investigations throughout the Incident Response lifecycle, from initial detection through remediation.
  • Correlate and analyze security events, alerts, logs, and network data to determine the scope and impact of cyber incidents.
  • Acquire and analyze endpoint and network artifacts, including NetFlow and full packet capture, to identify malicious or suspicious activity.
  • Identify attacker tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) to strengthen detection and response capabilities.
  • Tune and maintain SIEM and IDS technologies to reduce false positives and improve SOC detection effectiveness.
  • Develop and maintain Incident Response processes, procedures, workflows, and playbooks.
  • Document investigations and response actions in case management systems and prepare clear, actionable incident reports.
  • Collaborate with cyber professionals in a fast-paced operational environment to defend the DoD Information Network (DoDIN) against sophisticated threats and advanced persistent threat (APT) actors.
Basic Qualifications
  • Bachelor's degree and 4–8 years of relevant cybersecurity experience.
  • Hands‑on experience using an enterprise Security Information and Event Management (SIEM) platform.
  • Experience analyzing high volumes of security logs and network data, including NetFlow and/or full packet capture.
  • Experience with network traffic and packet analysis.
  • Strong understanding of TCP/IP, common ports and protocols, network traffic flows, the OSI model, system administration, defense‑in‑depth, and network security technologies.
  • Understanding of cloud security concepts and considerations.
  • Familiarity with Unix‑based systems.
  • Ability to work effectively in a collaborative, mission‑focused SOC environment.
  • Ability to work the 2:00 p.m.–10:00 p.m. swing shift.
  • Baseline certification (Security+ CE) and CSSP‑Infrastructure Support certification at start.
  • U.S. citizenship with an active TS/SCI clearance with SAP Eligibility.
Preferred Qualifications

You don't need to check every box below. We'd especially like to hear from candidates with experience in one or more of the following areas:

  • Cybersecurity experience across Protect, Detect, Respond, and Sustain functions within a Computer Incident Response or Security Operations organization.
  • Experience working in a 24x7 SOC or cyber operations environment.
  • Understanding of the cyber threat lifecycle, attack vectors, exploitation techniques, and adversary behavior.
  • Familiarity with intelligence‑driven defense, Cyber Kill Chain methodology, and/or related threat frameworks.
  • Experience analyzing advanced attacker TTPs and indicators of compromise.
  • Strong written and verbal communication skills, including the ability to translate complex technical findings into clear, actionable reports.
  • A proactive, self‑motivated approach with the ability to perform effectively in a fast‑paced operational environment.
Your Impact

This role gives you the opportunity to investigate real‑world cyber activity, work with enterprise‑scale security data and technologies, and directly strengthen defensive cyber capabilities. At Leidos, you'll work alongside a mission‑focused team helping protect the digital infrastructure behind critical national security operations.

At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it.

We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail.

Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares.

Pay Range: Pay Range $87,100.00 - $157,450.00

The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

Leidos Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $17.2 billion for the fiscal year ended January 2, 2026. For more information, visit www.Leidos.com.

Pay and Benefits

Pay and benefits are fundamental to any career decision. That's why we craft compensation packages that reflect the importance of the work we do for our customers.

Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available here.

Securing Your Data

Leidos will never ask you to provide payment‑related information at any part of the employment application process. And Leidos will communicate with you only through emails that are sent from a Leidos.com email address. If you receive an email purporting to be from Leidos that asks for payment‑related information or any other personal information, please report the email to spam.leidos@leidos.com.

Commitment and Diversity

All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Security Analyst
Cyber Security Analyst

Leidos Inc • Fort Belvoir (VA)

On-site
USD 87,000 - 157,000
Cyber Security Analyst
Cyber Security Analyst

Leidos • Adelphi (MD)

On-site
USD 87,000 - 157,000
Health and Wellness programs
Paid Leave
Retirement plan
Defensive Cybersecurity Analyst
Defensive Cybersecurity Analyst

Leidos LLC • Illinois

On-site
USD 70,000 - 126,000
Cyber Defense Analyst
Cyber Defense Analyst

Leidos LLC • Suitland (MD)

On-site
USD 87,000 - 157,000
Defensive Cybersecurity Analyst
Defensive Cybersecurity Analyst

Leidos LLC • Whitehall (OH)

On-site
USD 70,000 - 126,000
Defensive Cybersecurity Analyst
Defensive Cybersecurity Analyst

Leidos • Illinois

On-site
USD 70,000 - 126,000
Principal Cybersecurity Engineer
Principal Cybersecurity Engineer

Leidos LLC • Adelphi (MD)

Hybrid
USD 131,000 - 237,000
Cyber Intelligence Fusion Analyst
Cyber Intelligence Fusion Analyst

Leidos LLC • Alexandria (VA)

On-site
USD 108,000 - 195,000
Health benefits
Retirement program
Detection, Monitoring, & Countermeasures Lead
Detection, Monitoring, & Countermeasures Lead

Leidos LLC • Alexandria (VA)

On-site
USD 131,000 - 237,000
Defensive Cyber Operations Analyst
Defensive Cyber Operations Analyst

Leidos LLC • Washington

Hybrid
USD 87,000 - 157,000
Hybrid work up to 20% Telework