TS Mission Lead - SOC

Leidos

Riverdale (UT)

On-site

USD 87,000 - 157,000

Full time

4 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Leidos is seeking an on-site Cyber Defense Team Lead to manage a security operations group within a classified environment. The role requires Top Secret/SCI clearance, DoD 8570 IAT II, and CSSP certifications, plus hands-on incident response and threat analysis across endpoints, networks, and SIEM platforms.

You will mentor staff, coordinate training, ensure compliance, and partner with shift leadership to maintain mission readiness at Hill AFB, UT, with a 2-hour recall window.

Qualifications

  • Active DoD Top Secret / SCI clearance.
  • Current DoD 8570/8140 IAT Level II baseline certification (e.g., Security+ CE, SSCP, GSEC, CySA+).
  • Current CSSP-A or CSSP-IR certification (e.g., CySA+, CEH, GCIA, GCIH), or ability to obtain within 180 days.
  • Foundational knowledge of TCP/IP networking, packet analysis (Wireshark/tcpdump), OSI model, and defense-in-depth.
  • Level III or Level IV education requirements: Bachelor’s + 4 or 8 years of relevant cyber defense/SOC experience.
  • On-site SCIF requirement with 5x8 schedule and 2-hour recall commute to Hill AFB UT / Scott AFB IL / Columbus OH.

Responsibilities

  • Coach and mentor team members with Biweekly 1-on-1s to guide career growth and retention.
  • Partner with Operations Managers to deliver advanced technical training and certifications.
  • Establish clear performance expectations and ensure policy compliance and accountability.
  • Maintain a strong security culture and collaboration with HR and leadership.
  • Coordinate shift coverage, training schedules, and mission readiness within the SCIF.
  • Lead analysts to triage alerts across endpoints, IDS/IPS, NetFlow, and network sensors in classified enclaves.
  • Correlate log data to CIRs, integrate threat feeds into SIEM, align with MITRE ATT&CK and Cyber Kill Chain.
  • Direct incident reporting and containment actions to leadership, JFHQ-DODIN, and USCYBERCOM per DoD standards.

Skills

Leadership
Incident response
Threat analysis
Team mentoring
Communication

Education

Bachelor’s degree + 4 years cyber defense or SOC experience
Bachelor’s degree + 8 years cyber defense or SOC experience
DoD 8570/8140 IAT Level II certification
CSSP-A or CSSP-IR certification

Tools

Splunk
Elastic
Sentinel
Wireshark
tcpdump
NetFlow

Job description

Description

Primary Responsibilities
Team Leadership & Development
  • Coaching & Mentoring: Conduct 1-on-1 check-ins with team members every two weeks to provide supportive, actionable career guidance, reduce operational burnout, and foster long-term retention.
  • Professional Growth: Partner with Operations Managers to facilitate advanced technical training, support certification pathways, and deliver objective, performance-driven reviews.
  • Trust & Accountability: Establish clear, mission-aligned performance expectations, follow through on team commitments, and address policy compliance and operational gaps fairly and promptly.
  • Positive Work Culture: Maintain strong ties with HR and leadership to resolve challenges, build psychological safety in high-stress classified environments, and focus the team on joint problem-solving during operational setbacks.
  • Operational Integration: Collaborate with Shift Leads and operations leadership on shift coverage, training schedules, and mission readiness within the SCIF, ensuring rapid recall capability during critical incidents.
Cybersecurity Monitoring & Analysis
  • Triage & Investigation: Lead analysts in evaluating alerts from endpoints, IDS/IPS, NetFlow, and custom network sensors across classified enclaves to identify, investigate, and mitigate sophisticated malicious activity.
  • Reporting & Intel Integration: Correlate complex multi-source log data to produce detailed Cyber Incident Reports (CIR), integrate tactical threat intelligence feeds into SIEM platforms, and align analysis with MITRE ATT&CK and Cyber Kill Chain frameworks.
  • Incident Response Coordination: Direct immediate reporting and applicable containment action's and escape validated, critical security incidents to customer leadership, JFHQ-DODIN, and USCYBERCOM in accordance with DoD reporting standards.
Basic Qualifications
  • Clearance: Active DoD Top Secret / SCI security clearance
  • Certifications:
    • Current DoD 8570/8140 IAT Level II baseline certification (e.g., Security+ CE, SSCP, GSEC, CySA+).
    • Current CSSP-A or CSSP-IR certification (e.g., CySA+, CEH, GCIA, GCIH), or the ability to obtain within 180 days of hire.
  • Foundational Knowledge: Strong technical mastery of TCP/IP networking, packet analysis (Wireshark/tcpdump), the OSI model, and defense-in-depth principles.
  • Education & Experience:
    • Level III: Bachelor’s degree + 4 year of relevant operational cyber defense or SOC experience (or equivalent military/work experience).
    • Level IV: Bachelor’s degree + 8 years of relevant operational cyber defense or SOC experience (or equivalent military/work experience).
  • Location & Availability: 100% on-site SCIF requirement; willingness to work the assigned 5x8 schedule and reside within a 2-hour physical recall commute of Hill AFB, UT; Scott AFB, IL; or Columbus, OH.
Preferred Qualifications
  • Prior experience supporting DISA, DoD Cyber Security Service Providers (CSSP), or Service Cyber Components
  • Hands-on technical experience operating enterprise SIEMs/log aggregators (such as Splunk, Elastic, or Sentinel) on classified networks.
  • Familiarity with advanced threat actor TTPs, static/dynamic malware analysis, and CJCSM 6510 incident reporting procedures.
  • Advanced cybersecurity certifications (such as SANS GIAC, CASP+, or CISSP).
  • At least two years of experience leading, mentoring, or supervising cross-functional cybersecurity teams.

If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares.

Pay Range:

Pay Range $87,100.00 - $157,450.00

The Leidos pay range for this job level is a general guideline onlyand not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

About Leidos

Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $16.7 billion for the fiscal year ended January 3, 2025. For more information, visit www.Leidos.com.

Pay and Benefits

Pay and benefits are fundamental to any career decision. That's why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available at www.leidos.com/careers/pay-benefits.

Commitment to Non-Discrimination

All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

TS Mission Lead - SOC
TS Mission Lead - SOC

Leidos • Whitehall (OH)

On-site
USD 87,000 - 157,000
TS Mission Lead - SOC
TS Mission Lead - SOC

Leidos • Shiloh (IL)

On-site
USD 87,000 - 157,000
TS Mission Lead - SOC
TS Mission Lead - SOC

Leidos • Clearfield (UT)

On-site
USD 87,000 - 157,000
TS Mission Lead - SOC
TS Mission Lead - SOC

Leidos Inc • Whitehall (OH)

On-site
USD 87,000 - 157,000
TS Mission Lead - SOC
TS Mission Lead - SOC

Leidos Inc • Clearfield (UT)

On-site
USD 87,000 - 157,000
TS Mission Lead - SOC
TS Mission Lead - SOC

Leidos Inc • Shiloh (IL)

On-site
USD 87,000 - 157,000
TS Mission Lead - SOC
TS Mission Lead - SOC

Leidos LLC • Whitehall (OH)

On-site
USD 87,000 - 157,000
Defensive Cybersecurity Analyst
Defensive Cybersecurity Analyst

Via Logic LLC • Illinois

On-site
USD 70,000 - 126,000
Defensive Cybersecurity Analyst
Defensive Cybersecurity Analyst

Leidos LLC • Illinois

On-site
USD 70,000 - 126,000
Defensive Cybersecurity Analyst
Defensive Cybersecurity Analyst

Leidos • Illinois

On-site
USD 70,000 - 126,000