Enable job alerts via email!

Incident Response Analyst

Leidos

Arlington (VA)

Remote

USD 85,000 - 154,000

Full time

2 days ago
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

Leidos is hiring an Incident Response Analyst in Arlington, VA, to support the DHS Security Operations Center. The role requires expertise in incident response, cyber analysis, and familiarity with the Cyber Kill Chain. Ideal candidates should possess a bachelor's degree and relevant cybersecurity experience. This is a full-time position with an annual salary ranging from $85,150 to $153,925.

Qualifications

  • Experience with incident detection, response, and malware analysis.
  • 4-8 years of related experience in cybersecurity.
  • Certifications like SANS GIAC or CISSP preferred.

Responsibilities

  • Coordinate investigation and response efforts during incidents.
  • Analyze events and data to determine the scope of cyber incidents.
  • Document investigation actions in case management systems.

Skills

Incident Response lifecycle
Operating Systems expertise
Enterprise Network Architecture understanding
Scripting experience
Analytic problem-solving

Education

Bachelor's degree in Computer Science or related field

Job description

Join to apply for the Incident Response Analyst role at Leidos

22 hours ago Be among the first 25 applicants

Join to apply for the Incident Response Analyst role at Leidos

Get AI-powered advice on this job and more exclusive features.

This range is provided by Leidos. Your actual pay will be based on your skills and experience — talk with your recruiter to learn more.

Base pay range

$85,150.00/yr - $153,925.00/yr

Description

At Leidos, we deliver innovative solutions through the efforts of our diverse and talented people who are dedicated to our customers’ success. We empower our teams, contribute to our communities, and operate sustainable. Everything we do is built on a commitment to do the right thing for our customers, our people, and our community. Our Mission, Vision, and Values guide the way we do business.

If this sounds like the kind of environment where you can thrive, keep reading!

The Digital Modernization Sector brings together our digital transformation and IT programs, allowing us to better serve our customers through scale and repeatability. Leidos has a critical need for a Incident Response Analyst to support DHS.

The Department of Homeland Security (DHS), Security Operations Center (SOC) Support Services is a US Government program responsible to monitor, detect, analyze, mitigate, and respond to cyber threats and adversarial activity on the DHS Enterprise. The DHS SOC has primary responsibility for monitoring and responding to security events and incidents detected at the Trusted Internet Connection (TIC) and Policy Enforcement Point (PEP) and is responsible for directing and coordinating detection and response activities performed by each Component SOC. Direction and coordination are achieved through a new shared DHS incident tracking system and other means of coordination and communication. Leidos is seeking a Senior Incident Response Analyst to join our team on this highly visible DHS CISA SOC Program.

The Incident Responder Will Perform The Following

  • Coordinate investigation and response efforts throughout the Incident Response lifecycle
  • Correlate and and analyze events and data to determine scope of Cyber Incidents
  • Acquire and analyze endpoint and network artifacts, volatile memory, malicious files/binaries and scripts
  • Recognize attacker tactics, techniques, and procedures as potential indicators of compromise (IOCs) that can be used to improve monitoring, analysis and Incident Response.
  • Develop, document, and maintain Incident Response process, procedures, workflows, and playbooks
  • Tune and maintain security tools (EDR, IDS, SIEM, etc) to reduce false positives and improve SOC detection capabilities
  • Document Investigation and Incident Response actions taken in Case Management Systems and prepare formal Incident Reports
  • Create metrics and determine Key Performance Indicators to drive maturity of SOC operations
  • Develop security content such as scripts, signatures, and alerts

The Ideal Candidate Will Possess

  • In-depth knowledge of each phase of the Incident Response life cycle
  • Expertise of Operating Systems (Windows/Linux) operations and artifacts
  • Understanding of Enterprise Network Architectures to include routing/switching, common protocols (DHCP, DNS, HTTP, etc), and devices (Firewalls, Proxies, Load Balancers, VPN, etc)
  • Ability to recognize suspicious activity/events, common attacker TTPs, and perform logical analysis and research to determine root cause and scope of Incidents
  • Be familiar with Cyber Kill Chain and have utilized the ATT&CK Framework
  • Have scripting experience with Python, PowerShell, and/or Bash
  • Ability to independently prioritize and complete multiple tasks with little to no supervision
  • Flexible and adaptable self-starter with strong relationship-building skills
  • Strong problem-solving abilities with an analytic and qualitative eye for reasoning
  • Strong verbal and written communication skills
  • Ability to communicate with all levels of audiences (subordinates, peers & leadership)

Basic Qualifications

All Department of Homeland Security SOC employees are required to favorably pass a 5-year (BI) Background Investigation. Experience in the areas of incident detection and response, malware analysis, or computer forensics.

Bachelors’ degree in Computer Science, Engineering, Information Technology, Cyber Security, or related field and 4-8 years of related experience. Additional years of experience and cyber certifications may be considered in lieu of degree.

Should Have At Least One Of The Following Certifications

SANS GIAC: GCIH, GCIA, GCFA, GPEN GCFE, GREM

CISSP OSCP, OSCE, OSWP

Preferred Qualifications

Experience in cyber government, and/or federal law enforcement FISMA systems.

Original Posting

March 14, 2025

For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

Pay Range

Pay Range $85,150.00 - $153,925.00

The Leidos pay range for this job level is a general guideline onlyand not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

#Remote

Seniority level
  • Seniority level
    Mid-Senior level
Employment type
  • Employment type
    Full-time
Job function
  • Job function
    Information Technology
  • Industries
    IT Services and IT Consulting

Referrals increase your chances of interviewing at Leidos by 2x

Sign in to set job alerts for “Incident Analyst” roles.

Washington, DC $100,000.00-$105,000.00 1 week ago

Washington DC-Baltimore Area $69.00-$73.00 21 hours ago

Washington, DC $55,000.00-$85,000.00 3 hours ago

Washington DC-Baltimore Area $20.00-$25.00 6 days ago

Washington, DC $124,400.00-$232,700.00 3 hours ago

Washington, DC $90,000.00-$110,000.00 1 week ago

Washington DC-Baltimore Area $70,000.00-$95,000.00 1 day ago

District of Columbia, United States 15 hours ago

Security Operations Center (SOC) Analyst

Ashburn, VA $85,150.00-$153,925.00 1 month ago

Security Operations Center (SOC) Analyst - Mid
Security Operations Center Analyst (SOC)
Major Incident Response (MIR) Specialist

Washington, DC $124,400.00-$232,700.00 1 week ago

Incident Response Analyst (US Government Clearance Required)

Indian Head, MD $75,000.00-$115,000.00 1 week ago

We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Incident Response Analyst

Softswiss

Remote

USD 70,000 - 100,000

Today
Be an early applicant

Associate Cyber Threat Analyst (Incident Response) - Remote

Florida Blue

Remote

USD 82,000 - 103,000

3 days ago
Be an early applicant

Associate Cyber Threat Analyst (Incident Response) - Remote

Davita Inc.

Jacksonville

Remote

USD 82,000 - 103,000

3 days ago
Be an early applicant

Associate Cyber Threat Analyst (Incident Response) - Remote

Davita Inc.

Largo

Remote

USD 82,000 - 103,000

5 days ago
Be an early applicant

Senior Cyber Security Incident Response Analyst

FIS

Remote

USD 104,000 - 176,000

6 days ago
Be an early applicant

Analyst Program Assoc (Critical Incidents Analyst) - Remote in Indiana

Freddie Mac

Indianapolis

Remote

USD 90,000 - 117,000

2 days ago
Be an early applicant

Incident Response Analyst

Check Point Software

Rockville

On-site

USD 85,000 - 120,000

Yesterday
Be an early applicant

ServiceNow Business Analyst

TEKsystems, Inc.

Arbutus

Remote

USD 84,000 - 127,000

Today
Be an early applicant

Cybersecurity Incident Response Analyst

Splunk

Hyde Park Township

Remote

USD 106,000 - 147,000

30+ days ago