Cyber Security Watch Officer

Leidos

Odenton (MD)

On-site

USD 70,000 - 126,000

Full time

5 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Compressed workweek

Job summary

Leidos is seeking a Swing-Shift Cyber Security Watch Officer (CSWO) at Ft. Meade, MD to support the DISA GSM-O II program. You will triage events, perform incident handling, analyze threats, and produce daily situational awareness for senior leadership.

The role requires TS/SCI clearance, a DoD-8140 WRC 511 Intermediate certification, and 2+ years of relevant experience. A compressed workweek is offered with a swing shift from 1pm-11pm.

Qualifications

  • BA degree with 2+ years of related experience; additional experience accepted in lieu of degree.
  • Active Top Secret/SCI clearance required to start.
  • DoD-8140 WRC 511 Intermediate certification required.
  • Experience in a Computer Incident Response or cyber defense environment.
  • Familiarity with cyber kill chain and threat lifecycle concepts.

Responsibilities

  • Triage events and handle incidents; provide IOC recommendations and assess security posture.
  • Oversee information security services and maintain KM tools and sites.
  • Prepare daily situational awareness and coordinate SA products with cyber elements.
  • Report on network intrusions, malware, and other cyber events.
  • Deliver daily briefings to DISA senior leadership; support 24x7 operations.
  • Coordinate incident handling per DoD guidance and CJCSM 6510 standards.

Skills

Active TS/SCI clearance
Cybersecurity operations
24x7 operations
Team collaboration

Education

BA degree

Tools

DoD-8140 WRC 511 Intermediate
CEH(P)
GSEC
Security+
PenTest+

Job description

Description

The Leidos Digital Modernization Sector has a current job opportunity for a Swing-Shift Cyber Security Watch Officer (CSWO) at Ft. Meade, MD

POSITION SUMMARY:

Serve as a Cyber Security Watch Officer (CSWO) on the DISA GSM-O II program supporting the DISA Joint Operations Center (DJOC) Network Assurance team. CSWOs are principally engaged in the triage of events, cyber incident handling, network analysis and threat detection, trend analysis, metric development, vulnerability information dissemination, and the DoD Cyber Security Service Provider (CSSP) methodology. This position offers a compressed workweek on a set Monday, Tuesday, Thursday, Friday schedule. (Day-shift hours: 5am-3pm. Swing-shift hours: 1pm-11pm. Mid-shift hours 9pm-7am).

PRIMARY RESPONSIBILITIES:
  • Support the DJOC Battle Captain and senior CSWOs with all Cyber Defense and Network Assurance issues to include making recommendations regarding Indicators of Compromise (IOC), malicious cyber activity, and the overall security posture of our networks.
  • Assist senior CSWOs in providing technical oversight of information security services and customer support initiatives, by updating DoD shared SA and knowledge management (KM) tools, including CMDNet, websites, blogs, and wikis, chat, collaboration tools, and portals.
  • Consume and analyze operational reporting from cyber organizations; prepare and deliver daily situational awareness and operational update briefings, through the by coordinating with other cyber elements to obtain information for slide, briefings, presentations, or other SA products.
  • Report DCO and incident management responses to network intrusions, malware, and other cyber events.
  • Maintain awareness of all pertinent directives, orders, alerts, and messages to include the preparation and delivery of daily situational awareness and operational update briefings to DISA Senior Leadership.
  • Support the senior CSWOs in overseeing all network defense operations and become familiar with the operations process flow and execution. Coordinate and collaborate with internal DISA elements and mission partners to share the understanding and impact of day-to-day malicious cyber activity.
  • Identify problems, determine accuracy and relevance of a broad range of technical information. Use sound judgment to generate, evaluate, and execute alternative courses of action. Produce timely, effective, decision-quality technical recommendations to support senior leadership.
  • Coordinate and ensure DoD incident handling reporting procedures are adhered to in accordance with (IAW) DoD, CJCS, USCC, and DISA guidance, regulations, and directives. Review Commander Joint Chiefs of Staff Manual (CJCSM) 6510: Cyber Incident Handling Program.
  • Serve as Defensive Cybersecurity Watch Officer during 24x7 operations. Requires the ability to independently analyze security events, formulate response strategies, and deliver timely, well-reasoned recommendations to senior CSWOs and leadership to protect and defend network assets.
BASIC QUALIFICATIONS:
  • Must hold a BA degree and 2+ years of experience. Additional experience will be accepted in lieu of degree.
  • Must have an active Top Secret/SCI security clearance.
  • Must have a DoD-8140 WRC 511 Intermediate certification (see list below for acceptable certifications) to start.
  • CND experience (Protect, Detect, Respond and Sustain) within a Computer Incident Response organization.
  • Familiarity with the life cycle of network threats, attacks, attack vectors and methods of exploitation with an understanding of intelligence driven defense and/or Cyber Kill Chain methodology.
  • Work as part of a team to develop solutions to issues that are unclear and require technical knowledge.
  • Experience in a 24x7 environment.
PREFERRED QUALIFICATIONS:
  • Prior Military IT or IC Experience
  • Hands on Experience working with DoD Networks including NIPR and SIPR
  • Willing to perform Shift Work – Swing-shift hours: 1pm-11pm. Monday, Tuesday, Thursday, Friday.
  • Performs well under pressure and has the ability to Multitask.
  • Motivated, initiative driven person with strong written and verbal communication skills, replying to official communications via email or phone, with the ability to report or speak to complex technical reports on analytical findings.
  • Demonstrated understanding of the life cycle of cybersecurity threats, attacks, attack vectors and understanding of intrusion set tactics, techniques, and procedures (TTPs)
WRC 511 Intermediate Certifications
  • CEH(P)
  • GMON
  • GRID
  • Cloud+
  • FITSP-O
  • GCED
  • GDSA
  • GSEC
  • PenTest+
  • Security+

If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares.

Original Posting:

September 15, 2026

For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

Pay Range:

Pay Range $69,550.00 - $125,725.00

The Leidos pay range for this job level is a general guideline onlyand not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

About Leidos

Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $16.7 billion for the fiscal year ended January 3, 2025. For more information, visit www.Leidos.com.

Pay and Benefits

Pay and benefits are fundamental to any career decision. That's why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available at www.leidos.com/careers/pay-benefits.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Defensive Cybersecurity Analyst
Defensive Cybersecurity Analyst

Leidos Inc • Illinois

On-site
USD 70,000 - 126,000
Health insurance
Cyber Fusion and Threats Analyst
Cyber Fusion and Threats Analyst

Leidos • Odenton (MD)

On-site
USD 108,000 - 195,000
Cyber Security Analyst
Cyber Security Analyst

Leidos • Arlington (VA)

On-site
USD 87,000 - 157,000
On-site in Arlington
Cyber Security Analyst
Cyber Security Analyst

COMFORT SYSTEMS • Adelphi (MD)

Hybrid
USD 87,000 - 157,000
Defensive Cybersecurity Analyst
Defensive Cybersecurity Analyst

Leidos Inc • Whitehall (OH)

On-site
USD 70,000 - 126,000
Defensive Cybersecurity Analyst
Defensive Cybersecurity Analyst

Leidos • Whitehall (OH)

On-site
USD 70,000 - 126,000
Cyber Defense Analyst (2nd Shift)
Cyber Defense Analyst (2nd Shift)

Via Logic LLC • Suitland (MD)

On-site
USD 87,000 - 157,000
Cyber Security Analyst
Cyber Security Analyst

Leidos • Adelphi (MD)

On-site
USD 87,000 - 157,000
Health and Wellness programs
Paid Leave
Retirement plan
Defensive Cybersecurity Analyst
Defensive Cybersecurity Analyst

Via Logic LLC • Illinois

On-site
USD 70,000 - 126,000
Cyber Defense Watch Officer - Swing Shift
Cyber Defense Watch Officer - Swing Shift

Leidos • Odenton (MD)

On-site
USD 70,000 - 126,000
Compressed workweek