Defensive Cybersecurity Analyst

Leidos LLC

Whitehall (OH)

On-site

USD 70,000 - 126,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Leidos is seeking proactive Cyber Security Analysts to join our 24x7 front-line SOC team, defending DoD networks against sophisticated threats. You will investigate alerts, analyze logs, and correlate data to support investigations while collaborating with incident response and communicating clearly to customers and USCYBERCOM.

The role requires a DoD Secret clearance (TS/SCI possible), DoD 8570 IAT Level II certification, and the ability to obtain CSSP-Analyst within 180 days.

Qualifications

  • Clearance: Active DoD Secret with ability to obtain TS/SCI.
  • Baseline Certification: DoD 8570 IAT Level II (Security+ CE, SSCP, or GSEC).
  • Specialized Certification: DoD 8570 CSSP-Analyst level within 180 days of hire.
  • Technical Core: Networking principles, packet analysis, OSI model, defense-in-depth.
  • Experience & Education: Level I: 2+ years; Level II: 4+ years; commutable to Columbus, OH.

Responsibilities

  • Investigate and triage security alerts from endpoints, IDS/IPS, NetFlow, and sensors.
  • Analyze large logs, pivot datasets, and correlate evidence for investigations.
  • Monitor DoD and open-source threat intel and IOCs in SIEM platforms.
  • Collaborate with incident response teams and communicate incidents to customers/USCYBERCOM.

Skills

SOC Experience
Critical Thinking
Adversary Mindset
Self-Motivation

Education

Bachelor's degree + 2+ years
Bachelor's degree + 4+ years

Job description

We are seeking proactive defenders who bring Security Operations Center (SOC) experience, exceptional critical thinking skills, and a self-motivated approach to safeguarding infrastructure as Cyber Security Analysts in our 24x7 front-line security operations team. In this role, you will be directly responsible for defending Department of Defense (DoD) networks against sophisticated, rapidly evolving cyber threats.

Primary Responsibilities
  • Investigate and triage security alerts generated from endpoints, IDS/IPS, NetFlow data, and custom sensors to identify suspicious activity.
  • Analyze extensive log files, pivot between diverse datasets, and correlate evidence to support incident investigations, producing detailed technical findings and reports.
  • Monitor and integrate DoD and open-source threat intelligence feeds and Indicators of Compromise (IOCs) into security sensors and SIEM platforms.
  • Collaborate closely with incident response teams and ensure timely, clear communication of security incidents to customers and USCYBERCOM.
Key Skillsets We Are Looking For
  • SOC Experience: You understand the operational flow, high tempo demands, and rigorous standards of a 24x7 Security Operations Center. You are comfortable executing structured incident triage and escalation protocols.
  • Critical Thinking & Adversary Mindset: You possess the ability to look beyond the surface of an alert. You excel at correlating disparate data points, analyzing raw packet data, and conducting deep-dive investigation of complex security events to uncover sophisticated malicious activity.
  • Demonstrated Self-Motivation: You are a self-starter who takes active ownership of your professional development. Whether pursuing advanced certifications, researching emerging threat vectors, or mastering new tools, you drive your own growth.
  • Thrives on Change: The threat landscape and tactical priorities shift constantly. You demonstrate high operational adaptability, viewing unexpected shifts as opportunities to excel, and seamlessly pivot to adopt new processes, security tools, and analytical methodologies to counter evolving adversaries or challenges.
Shift & Operational Requirements

Predictable Work-Life Balance: To support your well-being, we utilize a predictable five-day, 8-hour shift structure.

Shift Options to Fit Your Lifestyle: Our 24x7 mission requires continuous coverage, but it also provides the opportunity to align your work hours with your personal routine.

  • Day Shift: 8:00 AM - 4:00 PM
  • Swing Shift: 4:00 PM - 12:00 AM
  • Mid Shift: 12:00 AM - 8:00 AM

Flexibility: We highly value your work-life balance and make every effort to honor your shift preferences whenever possible. While final assignments must ensure critical program requirements are met, we strive to manage scheduling with a balanced approach that respects our team members' personal needs alongside mission readiness.

Required Qualifications
  • Clearance: Active DoD Secret clearance, with the ability to obtain and maintain a TS/SCI.
  • Baseline Certification: Current DoD 8570 IAT Level II (or higher) certification, such as CompTIA Security+ CE, ISC2 SSCP, or SANS GSEC (or equivalent 8140 requirements).
  • Specialized Certification: Ability to obtain a DoD 8570 CSSP-Analyst level certification (e.g., CEH, CySA+, GCIA, or equivalent) within 180 days of hire.
  • Technical Core: Solid foundation in networking principles, including packet analysis, common ports/protocols, traffic flow, the OSI model, and defense-in-depth architecture.
  • Experience & Education: Level I: Bachelor's degree and 2+ years of relevant experience (Equivalent professional work or military experience will be considered in lieu of a degree)
  • Level II: Bachelor's degree and 4+ years of relevant experience (Equivalent professional work or military experience will be considered in lieu of a degree).
  • Location: Commutable distance (within 2 hours) or ability to self-relocate to Columbus, OH.
Preferred Qualifications
  • Prior experience working within Defense Information Systems Agency (DISA) or DOD Environments.
  • Experience applying intelligence-driven defense strategies utilizing the MITRE ATT&CK or Cyber Kill Chain frameworks, including a deep understanding of intrusion set tactics, techniques, and procedures (TTPs).
  • In-depth experience utilizing SIEM/SOAR platforms to perform behavioral and statistical analysis across multiple log types.
  • Knowledge or experience in defending cloud environments (AWS, Azure, GCP) or administering enterprise mobile security (MDM, MAM, MTD).
  • Basic scripting and programming skills to automate routine analytical tasks.

If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo - because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 - and moving faster than anyone else dares.

Original Posting: August 29, 2026 For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

Pay Range: Pay Range $69,550.00 - $125,725.00 The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary.

Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

Leidos Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $17.2 billion for the fiscal year ended January 2, 2026.

For more information, visit www.Leidos.com.

Pay and Benefits Pay and benefits are fundamental to any career decision.

That's why we craft compensation packages that reflect the importance of the work we do for our customers.

Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement.

More details are available here.

Securing Your Data

Leidos will never ask you to provide payment-related information at any part of the employment application process. And Leidos will communicate with you only through emails that are sent from a Leidos.com email address. If you receive an email purporting to be from Leidos that asks for payment-related information or any other personal information, please report the email to spam.leidos@leidos.com.

Commitment and Diversity

All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Defensive Cybersecurity Analyst
Defensive Cybersecurity Analyst

Leidos LLC • Illinois

On-site
USD 70,000 - 126,000
Defensive Cybersecurity Analyst
Defensive Cybersecurity Analyst

Leidos • Illinois

On-site
USD 70,000 - 126,000
Cyber Security Analyst
Cyber Security Analyst

Leidos LLC • Adelphi (MD)

Hybrid
USD 87,000 - 157,000
Defensive Cyber Operations Analyst
Defensive Cyber Operations Analyst

Leidos LLC • Washington

Hybrid
USD 87,000 - 157,000
Hybrid work up to 20% Telework
Security Operations Center (SOC) Analyst
Security Operations Center (SOC) Analyst

Leidos LLC • Illinois

On-site
USD 70,000 - 126,000
Defensive Cybersecurity Analyst
Defensive Cybersecurity Analyst

Via Logic LLC • Illinois

On-site
USD 70,000 - 126,000
Detection, Monitoring, & Countermeasures Lead
Detection, Monitoring, & Countermeasures Lead

Leidos LLC • Alexandria (VA)

On-site
USD 131,000 - 237,000
Defensive Cybersecurity Analyst
Defensive Cybersecurity Analyst

Leidos • Whitehall (OH)

On-site
USD 70,000 - 126,000
Security Operations Center (SOC) Analyst
Security Operations Center (SOC) Analyst

Via Logic LLC • Shiloh (IL)

On-site
USD 70,000 - 126,000
Defensive Cybersecurity Analyst
Defensive Cybersecurity Analyst

Leidos Inc • Whitehall (OH)

On-site
USD 70,000 - 126,000