Incident Responder

Leidos

Suitland (MD)

On-site

USD 108,000 - 195,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Leidos in Suitland, MD seeks an Incident Responder to defend Navy maritime intelligence networks and manage the full incident response lifecycle across TS/SCI environments.

You will investigate, contain, and recover from cyber incidents while collaborating with cybersecurity, intelligence, and investigative partners to protect sensitive networks and data.

Qualifications

  • Bachelor's degree in Cybersecurity, Information Technology, Information Assurance, or related field.
  • 15+ years of relevant professional experience without a degree.
  • Active TS/SCI security clearance.
  • 10 years of concentrated experience in the CND discipline.
  • 5+ years of professional experience monitoring and investigating alerts from cybersecurity tools.
  • Experience with SIEM systems such as Splunk and Elastic.
  • Experience with NIDPS such as Cisco FirePower and Palo Alto NGFW, and host-based tools like Trellix ePO, Defender, and Tanium.
  • Knowledge of scripting and coding languages such as Python, Perl, Ruby, JavaScript, PowerShell, C, C++, and Java.
  • Knowledge of penetration testing and red team tactics and tools such as Kali, SamuraiWTF, Nmap, Burp Suite, sqlmap, and Metasploit.
  • Knowledge of ticketing systems, report writing, and intelligence gathering, analysis, and dissemination techniques specific to cybersecurity.

Responsibilities

  • Perform all phases of the incident response lifecycle: detection, analysis, containment, eradication, recovery.
  • Receive/escalate from Tier 1 analysts and support TS/SCI networks including JWICS, ATLAS, HGCC responsibilities.
  • Respond to incident notifications via telephone and email.
  • Prepare and submit ESAFs to NNWC Electronic Spillage Center.
  • Monitor DLP outputs for classified indicators and spillage cues.
  • Coordinate with internal/external stakeholders (SSOs, JAG, ONI ISSM, etc.).
  • Maintain detailed incident documentation and timelines.
  • Participate in incident response meetings, briefings, and after-action reviews.
  • Support execution and evaluation of annual security exercises.

Skills

15+ years of relevant experience
5+ years monitoring alerts
SIEM experience (Splunk, Elastic)
NIDPS (Cisco FirePower, Palo Alto NGFW
Scripting languages (Python, PowerShel
Penetration testing tools (Kali, Burp,

Education

Bachelor's degree in Cybersecurity/Info Tech/Info Assurance or related
Master's degree preferred

Tools

Splunk
Elastic
Cisco FirePower
Palo Alto NGFW
Trellix ePO
Microsoft Defender
Tanium

Job description

Description

Incident Responder

Location: Suitland, MD

Clearance: Active TS/SCI

Leidos is seeking an Incident Responder to join a mission focused cybersecurity team supporting the Office of Naval Intelligence (ONI) at the Hopper Global Communications Center (HGCC) in Suitland, MD .

In this role, you will serve as a digital first responder, helping defend the Navy's critical maritime intelligence networks against cyber threats. You will respond to and investigate cybersecurity incidents, contain affected systems, limit operational impact, and collect and analyze digital artifacts to support effective response and recovery. Working across the incident response lifecycle, you will collaborate with cybersecurity, intelligence, and investigative partners to help protect highly sensitive TS/SCI environments.

Primary Responsibilities

  • Perform all phases of the incident response lifecycle, including detection, analysis, containment, eradication, and recovery.

  • Receive and act on escalations from Tier 1 analysts, conduct spillage response and cleanup activities, and support incident response for TS/SCI networks, including JWICS, ATLAS, and other networks for which HGCC is responsible.

  • Receive and respond to incident notifications from customers via telephone and email.

  • Prepare and submit Electronic Spillage Assessment Forms (ESAFs) to the NNWC Electronic Spillage Center.

  • Monitor Data Loss Prevention (DLP) outputs for classified code words and potential spillage indicators.

  • Coordinate and communicate with internal and external stakeholders, including Special Security Officers (SSOs), Judge Advocate General (JAG), ONI ISSM, Hopper ISSM, CNI, NAVNETWARCOM, IC SCC, NCDOC, NCIS, and other IC and DoD SOC/DCO teams.

  • Maintain detailed and accurate incident documentation and timelines throughout the response process.

  • Participate in incident response meetings, briefings, and after action reviews.

  • Support the execution and evaluation of annual security exercises.

Required Qualifications

  • Bachelor's degree in Cybersecurity, Information Technology, Information Assurance, or a related area of study desired; Master's degree preferred.

  • 15+ years of relevant professional experience without a degree.

  • Active TS/SCI security clearance.

  • 10 years of concentrated experience in the CND discipline.

  • 5+ years of professional experience monitoring and investigating alerts from cybersecurity tools.

  • Experience with Security Information and Event Management (SIEM) systems such as Splunk and Elastic.

  • Experience with Network Intrusion Detection/Prevention Systems (NIDPS), such as Cisco FirePower and Palo Alto NGFW, as well as host based tools such as Trellix ePO, Microsoft Defender, and Tanium.

  • Knowledge of scripting and coding languages such as Python, Perl, Ruby, JavaScript, PowerShell, C, C++, and Java.

  • Knowledge of penetration testing and red team tactics, techniques, and procedures, as well as tools such as Kali, SamuraiWTF, Nmap, Burp Suite, sqlmap, and Metasploit.

  • Knowledge of ticketing systems, report writing, and intelligence gathering, analysis, and dissemination techniques specific to cybersecurity.

Required Certifications

  • Must possess one of the following certifications: Certified Ethical Hacker (CEH), CyberSec First Responder (CFR), CompTIA Cybersecurity Analyst (CySA+), GIAC Certified Forensic Analyst (GCFA), GIAC Certified Incident Handler (GCIH), EC Council Certified Incident Handler (ECIH), or Cisco Cybersecurity Specialist (SCYBER).

Original Posting:

August 20, 2026

For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

Pay Range:

Pay Range $107,900.00 - $195,050.00

The Leidos pay range for this job level is a general guideline onlyand not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

About Leidos

Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $16.7 billion for the fiscal year ended January 3, 2025. For more information, visit www.Leidos.com .

Pay and Benefits

  • Pay and benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement.

More details are available at www.leidos.com/careers/pay-benefits .

Securing Your Data

Beware of fake employment opportunities using Leidos’ name. Leidos will never ask you to provide payment-related information during any part of the employment application process (i.e., ask you for money), nor will Leidos ever advance money as part of the hiring process (i.e., send you a check or money order before doing any work). Further, Leidos will only communicate with you through emails that are generated by the Leidos.com automated system – never from free commercial services (e.g., Gmail, Yahoo, Hotmail) or via WhatsApp, Telegram, etc. If you received an email purporting to be from Leidos that asks for payment-related information or any other personal information (e.g., about you or your previous employer), and you are concerned about its legitimacy, please make us aware immediately by emailing us at LeidosCareersFraud@leidos.com .

If you believe you are the victim of a scam, contact your local law enforcement and report the incident to the U.S. Federal Trade Commission (https://reportfraud.ftc.gov/#/) .

Commitment to Non-Discrimination

All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.

REQNUMBER: R-00190183

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status. Leidos will consider qualified applicants with criminal histories for employment in accordance with relevant Laws. Leidos is an equal opportunity employer/disability/vet.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Incident Responder
Incident Responder

Leidos Inc • Suitland (MD)

On-site
USD 108,000 - 195,000
Cyber Defense Analyst
Cyber Defense Analyst

Leidos Inc • Suitland (MD)

On-site
USD 87,000 - 157,000
Cyber Defense Infrastructure Support Engineer
Cyber Defense Infrastructure Support Engineer

Leidos • Suitland (MD)

On-site
USD 108,000 - 195,000
null
Cyber Defense Analyst
Cyber Defense Analyst

Leidos • Suitland (MD)

On-site
USD 87,000 - 157,000
Health and Wellness programs
Income Protection
Paid Leave
+1
Cyber Tier 1 Deputy Team Lead
Cyber Tier 1 Deputy Team Lead

Leidos • Chandler (AZ)

On-site
USD 87,000 - 157,000
Cyber Infrastructure Support Lead
Cyber Infrastructure Support Lead

Leidos Inc • Concord (MA)

On-site
USD 108,000 - 195,000
Systems Administrator
Systems Administrator

Leidos • Suitland (MD)

On-site
USD 92,000 - 167,000
Defensive Cyber Operations Analyst
Defensive Cyber Operations Analyst

Leidos • Washington

Hybrid
USD 87,000 - 157,000
Cyber Infrastructure Support Lead
Cyber Infrastructure Support Lead

Leidos • Concord (MA)

On-site
USD 108,000 - 195,000
Cybersecurity Engineer
Cybersecurity Engineer

Leidos • Fairfax (VA)

On-site
USD 126,000 - 228,000
Competitive compensation
Health and Wellness programs
Income Protection
+2