Endpoint Security Analyst - Elastic Defend

Via Logic LLC

Adelphi (MD)

Hybrid

USD 108,000 - 195,000

Full time

8 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Leidos seeks an experienced Endpoint Security Analyst to support a DoW cyber operations task order. You will deploy, configure, and sustain Elastic Agent and Elastic Defend across enterprise endpoints, optimize telemetry collection, and enhance threat detection with MITRE ATT&CK techniques.

You will work with Threat, Engineering, and Cybersecurity Operations teams to strengthen defenses, improve visibility, and rapidly respond to threats.

Qualifications

  • Bachelor's degree in STEM, cybersecurity, or related field; 4+ years of cybersecurity experience.
  • Hands-on experience deploying/configuring enterprise endpoint security/EDR solutions.
  • Strong understanding of endpoint protection, telemetry, threat detection, and incident response.
  • Familiarity with MITRE ATT&CK framework and threat intelligence.
  • US citizenship with TS/SCI and SAP eligibility; one of the listed certifications is preferred.

Responsibilities

  • Deploy, configure, operate, tune, upgrade, and troubleshoot Elastic Agent, Elastic Defend, and related endpoint security technologies.
  • Optimize endpoint protection and telemetry to maximize visibility while minimizing performance impact.
  • Collaborate with Threat and Detection teams to customize detections and MITRE-aligned rules.
  • Conduct host-based defensive cyber operations to identify, contain, and remediate vulnerabilities.
  • Support investigations using endpoint queries, forensic data collection, and rapid containment actions.
  • Develop queries, dashboards, and reports for enterprise security visibility and leadership awareness.
  • Coordinate with engineering on deployments, patches, upgrades, and security updates.
  • Troubleshoot endpoint security tool issues and outages.
  • Develop and maintain endpoint security SOPs and configurations.
  • Evaluate emerging endpoint security tools and certifications.

Skills

Endpoint security
EDR
Threat detection
MITRE ATT&CK
Analytical skills
Communication skills
Collaboration

Education

Bachelor's degree in STEM/related field
4+ years cybersecurity experience

Tools

Elastic Agent
Elastic Defend
CrowdStrike Falcon
Tanium
McAfee ePO

Job description

The C5ISR Center Cyber Security Service Provider (CSSP) is a premier defensive cyber operations organization supporting the Department of War (DoW). Operating 24x7x365, the CSSP provides continuous monitoring, threat detection, incident response, and vulnerability management across cloud and on-premises environments, including AWS, Azure, GCP, Oracle Cloud, and SaaS platforms.

Every day, our team protects the networks, systems, and data that enable critical DoW missions.

Leidos has an immediate opportunity for an experienced Endpoint Security Analyst to support a highly visible, strategic Cybersecurity Task Order. In this role, you will provide specialized expertise supporting Elastic Agent and Elastic Defend, helping deploy, configure, optimize, and sustain endpoint protection, telemetry collection, threat detection, and automated response capabilities across the enterprise.

You will work closely with threat, engineering, and cybersecurity operations teams to strengthen endpoint defenses, improve visibility, and rapidly identify and respond to emerging cyber threats.

Location:

Hybrid - 3 days on site at Adelphi, MD

Clearance:

U.S. Citizenship with an active TS/SCI with SAP Eligibility

Primary Responsibilities:
  • Deploy, configure, operate, tune, upgrade, and troubleshoot Elastic Agent, Elastic Defend, and other enterprise endpoint security technologies.
  • Optimize endpoint protection and telemetry collection to maximize security visibility and detection effectiveness while minimizing operational and system performance impacts.
  • Partner with Threat and Detection teams to customize detection rules, develop threat signatures, and align endpoint defenses with emerging threat intelligence and MITRE ATT&CK techniques.
  • Conduct host-based defensive cyber operations to identify, investigate, contain, mitigate, and remediate vulnerabilities and intrusions.
  • Support cyber investigations using advanced endpoint queries, forensic data collection, and rapid containment and response capabilities.
  • Build and maintain queries, dashboards, and reports that provide enterprise security visibility and leadership awareness.
  • Coordinate with engineering teams on endpoint security deployments, patches, hot fixes, upgrades, and other critical security updates.
  • Troubleshoot endpoint security tool issues, performance concerns, and outages.
  • Develop and maintain endpoint security policies, configurations, and Standard Operating Procedures (SOPs).
  • Evaluate emerging endpoint security tools, techniques, and technologies and recommend improvements aligned with enterprise cybersecurity strategy.
Basic Qualifications:
  • Bachelor's degree in Science, Technology, Engineering, Mathematics (STEM), cybersecurity, or a related field and 4+ years of relevant cybersecurity experience.
  • Hands-on experience deploying, configuring, operating, or supporting enterprise endpoint security or EDR solutions.
  • Strong understanding of endpoint protection, security telemetry, threat detection, incident investigation, and response.
  • Experience investigating and responding to endpoint security alerts and potential compromises.
  • Knowledge of current cyber threats, attacker techniques, and defensive strategies, including familiarity with the MITRE ATT&CK framework.
  • Strong analytical, troubleshooting, and problem-solving skills.
  • Ability to work effectively across cybersecurity, threat, and engineering teams.
  • Strong written and verbal communication skills.
  • U.S. citizenship and an active TS/SCI with SAP eligibility.
  • At least one of the following certifications:
    • GIAC/SANS: GCIA, GCIH, GCFA, GCFE, GREM, GISF, GXPN, GWEB, GNFA, or GMON
    • Offensive Security: OSCP, OSCE, OSWP, or OSEE
    • ISC2: CCFP or CISSP
    • EC-Council: CEH, CHFI, LPT, ECSA, or ECI
Preferred Qualifications:
  • Hands-on experience with Elastic Agent and Elastic Defend, including deployment, configuration, policy management, tuning, and troubleshooting.
  • Experience optimizing endpoint telemetry and security controls in large-scale enterprise environments.
  • Experience developing or tuning endpoint detection rules, threat signatures, IOCs, and behavioral detections.
  • Experience using Elastic capabilities for endpoint investigation, advanced querying, forensic data collection, and response actions.
  • Experience with CrowdStrike Falcon, McAfee/Trellix ePO, Tanium, or similar enterprise endpoint security platforms.
  • Experience deploying and configuring CrowdStrike Falcon sensors and creating custom Indicators of Compromise (IOCs) and Indicators of Attack (IOAs).
  • Experience supporting endpoint security operations within large, complex, or mission-critical environments.
  • Relevant endpoint security certifications, such as Elastic, CrowdStrike, or Tanium certifications.

If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo - because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 - and moving faster than anyone else dares.

Pay Range

Pay Range $107,900.00 - $195,050.00 The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

About Leidos

Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $16.7 billion for the fiscal year ended January 3, 2025. For more information, visit www.Leidos.com.

Pay and Benefits

Pay and benefits are fundamental to any career decision. That's why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available at www.leidos.com/careers/pay-benefits.

Commitment to Non-Discrimination

All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Endpoint Security Analyst - Elastic Defend
Endpoint Security Analyst - Elastic Defend

Quest Oracle Community • Adelphi (MD)

Hybrid
USD 108,000 - 195,000
Endpoint Security Analyst - Elastic Defend
Endpoint Security Analyst - Elastic Defend

Koitecc Solutions • Adelphi (MD)

Hybrid
USD 108,000 - 195,000
Endpoint Security Analyst - Elastic Defend
Endpoint Security Analyst - Elastic Defend

Leidos Inc • Adelphi (MD)

Hybrid
USD 108,000 - 195,000
Endpoint Security Engineer Lead
Endpoint Security Engineer Lead

Leidos • Arlington (VA)

Hybrid
USD 131,000 - 238,000
Health and Wellness programs
Paid Leave
Retirement benefits
Sr. Endpoint Security Systems Engineer
Sr. Endpoint Security Systems Engineer

Leidos Inc • Bethesda (MD)

Hybrid
USD 108,000 - 195,000
Competitive benefits
Paid Time Off
401K with company match
Cyber Security Analyst
Cyber Security Analyst

Leidos • Fort Belvoir (VA)

On-site
USD 87,000 - 157,000
Principal Endpoint Security Systems Engineer
Principal Endpoint Security Systems Engineer

Association of Old Crows • Bethesda (MD)

Hybrid
USD 131,000 - 237,000
Paid Time Off
11 paid Holidays
401K with company match
+5
Sr. Endpoint Security Systems Engineer
Sr. Endpoint Security Systems Engineer

Via Logic LLC • Bethesda (MD)

Hybrid
USD 108,000 - 195,000
Competitive benefits
Paid Time Off
11 holidays
+3
Sr. Endpoint Security Systems Engineer
Sr. Endpoint Security Systems Engineer

Koitecc Solutions • Bethesda (MD)

Hybrid
USD 108,000 - 195,000
Cyber Security Analyst
Cyber Security Analyst

Leidos Inc • Fort Belvoir (VA)

On-site
USD 87,000 - 157,000