Incident Responder - Weekday 2nd and 3rd Shifts

Leidos

Suitland (MD)

On-site

USD 108,000 - 195,000

Full time

4 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Leidos is hiring two Incident Responders to support the Navy’s cybersecurity environment at ONI HGCC in Suitland, MD. The role involves defending critical maritime intelligence networks, investigating incidents, containing affected systems, and analyzing artifacts across the incident response lifecycle.

Regular shifts are 2nd and 3rd weekdays, with initial training during day shift. Requires Active TS/SCI clearance and extensive CND/SIEM experience; on-site at Suitland, MD.

Qualifications

  • Bachelor’s degree in Cybersecurity, IT, Information Assurance, or related field with 8+ years of experience or Master’s with 6+ years.
  • Active TS/SCI clearance in DISS.
  • Extensive experience in Computer Network Defense (CND) and monitoring/analyzing security alerts.
  • Experience with SIEM systems such as Splunk and Elastic.

Responsibilities

  • Perform all phases of the incident response lifecycle: detection, analysis, containment, eradication, recovery.
  • Receive escalations from Tier 1 analysts and support incident response for TS/SCI networks.
  • Respond to incident notifications via phone and email.
  • Submit ESAFs to the NNWC Electronic Spillage Center.
  • Monitor DLP outputs for classified code words and spillage indicators.
  • Coordinate with SSOs, JAG, and IC/DoD teams for incident response.
  • Maintain detailed incident documentation and timelines.

Skills

Cybersecurity monitoring
Incident analysis
Scripting (Python/PowerShell)
Digital forensics

Education

Bachelor's degree in Cybersecurity/IT
Master’s degree in related field

Tools

Splunk
Elastic
Cisco FirePower
Palo Alto NGFW
Trellix ePO
Microsoft Defender
Tanium
Nmap
Burp Suite
Kali

Job description

Incident Responder - Weekday 2nd and 3rd Shifts

Location: Suitland, MD
Clearance: Active TS/SCI
Schedule: Full Time, Monday through Friday

Leidos is hiring two Incident Responder to join a mission focused team supporting the Navy's cybersecurity environment at the Office of Naval Intelligence (ONI) Hopper Global Communications Center (HGCC) in Suitland, MD.

Weekdays 2nd Shift

Monday through Friday: 1530 to 2330

Weekdays 3rd Shift

Monday through Friday: 2330 to 0730

Work Location and Hours

These are full-time, onsite positions supporting a 24 hour cybersecurity operation.

Training Schedule

For up to the first two months of employment, all selected candidates will be required to complete training during the day shift, Monday through Friday. Candidates must be available to work the day shift throughout the initial training period, regardless of their regular shift schedule.

Regular Work Schedule

Upon completion of training, each Incident Responder will transition to the 2nd or 3rd shift schedule for which they were hired. Occasional additional or alternate shift coverage may be required to support team coverage, employee leave, or other program and staffing needs.

In this role, you will serve as a digital first responder, helping defend the Navy's critical maritime intelligence networks against cyber threats. You will investigate and respond to cybersecurity incidents, contain affected systems, limit operational impact, and collect and analyze digital artifacts to support effective response and recovery. Working across the incident response lifecycle, you will collaborate with cybersecurity, intelligence, and investigative partners to help protect highly sensitive TS/SCI environments.

Primary Responsibilities
  • Perform all phases of the incident response lifecycle, including detection, analysis, containment, eradication, and recovery.
  • Receive and act on escalations from Tier 1 analysts, conduct spillage response and cleanup activities, and support incident response for TS/SCI networks, including JWICS, ATLAS, and other networks for which HGCC is responsible.
  • Receive and respond to incident notifications from customers via telephone and email.
  • Prepare and submit Electronic Spillage Assessment Forms (ESAFs) to the NNWC Electronic Spillage Center.
  • Monitor Data Loss Prevention (DLP) outputs for classified code words and potential spillage indicators.
  • Coordinate and communicate with internal and external stakeholders, including Special Security Officers (SSOs), Judge Advocate General (JAG), ONI ISSM, Hopper ISSM, CNI, NAVNETWARCOM, IC SCC, NCDOC, NCIS, and other IC and DoD SOC/DCO teams.
  • Maintain detailed and accurate incident documentation and timelines throughout the response process.
  • Participate in incident response meetings, briefings, and after action reviews.
  • Support the execution and evaluation of annual security exercises.
Required Qualifications
  • Bachelor's degree in Cybersecurity, Information Technology, Information Assurance, or a related area of study desired with 8+ years of experience or Master’s degree with 6+ years of experience. Additional experience may be considered in lieu of a degree.
  • Active TS/SCI security clearance in DISS.
  • Extensive experience in the Computer Network Defense (CND) discipline.
  • Significant professional experience monitoring, analyzing, and investigating alerts generated by cybersecurity tools.
  • Experience with Security Information and Event Management (SIEM) systems such as Splunk and Elastic.
  • Experience with Network Intrusion Detection/Prevention Systems (NIDPS), such as Cisco FirePower and Palo Alto NGFW, as well as host based tools such as Trellix ePO, Microsoft Defender, and Tanium.
  • Knowledge of scripting and coding languages such as Python, Perl, Ruby, JavaScript, PowerShell, C, C++, and Java.
  • Knowledge of penetration testing and red team tactics, techniques, and procedures, as well as tools such as Kali, SamuraiWTF, Nmap, Burp Suite, sqlmap, and Metasploit.
  • Knowledge of ticketing systems, report writing, and intelligence gathering, analysis, and dissemination techniques specific to cybersecurity.
Required Certifications
  • Must possess one of the following active certifications: CompTIA Security+, CompTIA CySA+, CompTIA PenTest+, CompTIA Cloud+, CEH, FITSP O, GIAC GMON, GIAC GRID, GIAC GCIA, GIAC GCIH, GIAC GICSP, GIAC GCED, GIAC GDSA, GIAC GSEC, CFR, or Cisco CyberOps.
Pay Range

Pay Range $107,900.00 - $195,050.00

The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

About Leidos

Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $16.7 billion for the fiscal year ended January 3, 2025. For more information, visit www.Leidos.com.

Pay and Benefits

Pay and benefits are fundamental to any career decision. That's why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available at www.leidos.com/careers/pay-benefits.

Commitment to Non-Discrimination

All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Incident Responder - 12 Hour Weekend Shifts
Incident Responder - 12 Hour Weekend Shifts

Leidos • Suitland (MD)

On-site
USD 108,000 - 195,000
Incident Responder – Weekday 2nd and 3rd Shifts
Incident Responder – Weekday 2nd and 3rd Shifts

Leidos • Suitland (MD)

On-site
USD 108,000 - 195,000
Incident Responder - 12 Hour Weekend Shifts
Incident Responder - 12 Hour Weekend Shifts

Leidos Inc • Suitland (MD)

Hybrid
USD 108,000 - 195,000
Incident Responder – 12 Hour Weekend Shifts
Incident Responder – 12 Hour Weekend Shifts

Leidos • Suitland (MD)

On-site
USD 108,000 - 195,000
Incident Responder – 12 Hour Weekend Shifts Leidos · Suitland, MD Part-time · On-site $107,900–195,050 1 hour ago
Incident Responder – 12 Hour Weekend Shifts Leidos · Suitland, MD Part-time · On-site $107,900–195,050 1 hour ago

Emploive • Suitland (MD), Northern (KY)

Hybrid
USD 108,000 - 195,000
Cyber Defense Analyst – Weekday 1st, 2nd and 3rd Shifts
Cyber Defense Analyst – Weekday 1st, 2nd and 3rd Shifts

Leidos • Suitland (MD)

On-site
USD 87,000 - 157,000
Cyber Defense Analyst - 12 Hour Weekend Shifts
Cyber Defense Analyst - 12 Hour Weekend Shifts

Leidos Inc • Suitland (MD)

On-site
USD 87,000 - 157,000
Cyber Defense Analyst – Weekday 1st, 2nd and 3rd Shifts
Cyber Defense Analyst – Weekday 1st, 2nd and 3rd Shifts

Leidos LLC • Suitland (MD)

On-site
USD 87,000 - 157,000
Cyber Defense Analyst – 12 Hour Weekend Shifts
Cyber Defense Analyst – 12 Hour Weekend Shifts

Leidos • Suitland (MD)

On-site
USD 87,000 - 157,000
Health and Wellness programs
Paid Leave
Retirement benefits
Cyber Defense Engineer
Cyber Defense Engineer

Leidos • Suitland (MD)

On-site
USD 108,000 - 195,000