Leidos' Digital sector offers frequent opportunities for SOC Analysts to join our team in Alexandria, VA.
Primary Responsibilities
- Utilize alerts from endpoints, IDS/IPS, netflow, and custom sensors to identify compromises on customer networks and endpoints.
- Perform intermediate-level review of massive log files, pivot between data sets, and correlate evidence for incident investigations.
- Pass triaged alerts to senior-level SOC personnel and assist in identifying malicious actors on customer networks.
- Document analysis, findings, and actions in a case/knowledge management system.
- Create and distribute incident reports to customers and higher headquarters.
Required Clearance And Certifications
- Must have an active DoD Top Secret clearance with the ability to obtain SCI.
- Must possess DoD 8570 IAT II or higher certification (e.g., CompTIA Security+ CE, ISC2 SSCP, SANS GSEC) prior to starting.
- Must obtain DoD 8570 CSSP-Analyst certification (e.g., CEH, CySA+, GCIA) within 6 months of starting.
Required Qualifications
- Willingness to perform shift work on site; all shifts include weekend hours and inclement weather.
- Bachelor's degree and 4+ years of prior relevant experience; additional military service and/or relevant work experience may be considered in lieu of a degree.
- 2+ years of prior incident handling/response experience.
- 2+ years of experience working in a SOC environment.
- CND experience (Protect, Detect, Respond and Sustain) within a Computer Incident Response organization.
- Demonstrated understanding of the life cycle of network threats, attacks, attack vectors, and an understanding of intrusion set tactics, techniques and procedures (TTPs).
- Sound understanding of TCP/IP, common networking ports and protocols, traffic flow, system administration, OSI model, defense-in-depth and common security elements.
- Motivated self-starter with strong written and verbal communication skills and the ability to create complex technical reports on analytic findings.
- Demonstrated commitment to mentoring, training, self-study and maintaining proficiency in the technical cybersecurity domain and the ability to think and work independently.
- Strong analytical and troubleshooting skills.
Preferred Qualifications
- Hands‑on experience analyzing high volumes of logs, network data (e.g., Netflow, Full Packet Capture), and other attack artifacts in support of incident investigations.
- In-depth knowledge of architecture, engineering, and operations of at least one enterprise SIEM platform (e.g., ArcSight, Splunk, Nitro/McAfee Enterprise Security Manager, QRadar, LogLogic).
- Experience and proficiency with Anti‑Virus, HIPS/HBSS, IDS/IPS, Full Packet Capture, Network Forensics.
- Experience with malware analysis concepts and methods.
- Unix/Linux command line experience.
- Scripting and programming experience.
- Motivated self‑starter with strong written and verbal communication skills, and the ability to create complex technical reports on analytic findings.
- Familiarity or experience in Intelligence Driven Defense, Cyber Kill Chain methodology, and/or MITRE ATT&CK framework.
Pay Range
$87,100.00 – $157,450.00
Pay and Benefits
Competitive compensation, Health and Wellness programs, Income Protection, Paid Leave, and Retirement.
Commitment to Non‑Discrimination
All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider qualified applicants with criminal histories consistent with relevant laws.