Job Description
Salary: $87,100 - 157,450 per year Requirements:
- We require an active DoD TS clearance.
- We require a current DoD 8570 IAT Level II certification or higher, such as CompTIA Security+ CE, ISC2 SSCP, or SANS GSEC, or an equivalent credential.
- We need the ability to obtain a DoD 8570 CSSP-A Level certification, such as CEH, CySA+, GCIA, or an equivalent, within 180 days of hire.
- We look for a strong networking background, including packet analysis, common ports and protocols, traffic flow, the OSI model, defense-in-depth principles, and core security concepts.
- We require a bachelors degree and 4+ years of relevant experience, though equivalent work experience and/or military service may be considered in place of a degree.
- We value the ability to work independently and collaboratively, with initiative and a strong work ethic.
- We expect a commitment to continuous learning and professional growth in cybersecurity, including pursuing certifications and staying current on emerging threats and technologies.
- We look for strong problem-solving skills and the ability to communicate technical information clearly, build alignment, and drive issues to resolution.
- We need a reliable and flexible team member who can work assigned shifts to meet operational needs.
- We require the ability to live within a commutable distance of Hill AFB, UT; Scott AFB, IL; or Columbus, OH, or to relocate to one of those locations.
- Preferred qualifications include experience with DISA and/or DoD networks.
- Preferred qualifications include advanced knowledge of TCP/IP, networking ports and protocols, traffic flow analysis, system administration principles, the OSI model, defense-in-depth strategies, and standard security components.
- Preferred qualifications include hands-on expertise with an enterprise SIEM platform such as ArcSight, QRadar, LogLogic, Splunk, or Elastic.
- Preferred qualifications include familiarity with malware analysis concepts and methods.
- Preferred qualifications include advanced certifications such as SANS GIAC credentials or CompTIA CASP+.
- Preferred qualifications include experience applying intelligence-driven defense strategies and/or the Cyber Kill Chain framework.
- Preferred qualifications include at least two years of experience leading cross-functional cybersecurity teams.
Responsibilities: - We lead a team of approximately 6-8 cybersecurity analysts and provide day-to-day direction, coaching, and oversight.
- We monitor, analyze, and correlate real-time DoD and open-source intelligence feeds to identify indicators of compromise and feed threat intelligence into security sensors and SIEM tools.
- We triage and investigate security alerts from endpoints, IDS/IPS, NetFlow, VPC flows, raw packet data, and cloud-native or custom monitoring tools to quickly identify malicious activity.
- We correlate security events and review large log sets across multi-cloud environments such as AWS, GCP, and Oracle to spot, prioritize, and investigate potential compromises.
- We coordinate closely with incident response teams to contain and remove threats across hybrid and cloud-hosted environments.
- We author detailed technical investigation reports and escalate critical security events to customers and USCYBERCOM to support timely, coordinated response.
- We support team development by running engagement activities, partnering on training and performance management, and contributing to performance reviews.
- We maintain clear communication with the chain of command, customers, civilian personnel, and employees so daily operations stay on track.
- We work with senior leadership to resolve operational blockers and support long-term mission effectiveness.
- We ensure leadership directives and organizational policies are consistently followed in partnership with People Leaders.
Technologies: - AWS
- Cloud
- Flow
- GCP
- Support
- Oracle
- Security
- Splunk
- TCP/IP
- Network
More:
We are Leidos, an industry and technology leader delivering smarter, more efficient digital and mission innovations for government and commercial customers. Our team supports 24x7 cybersecurity monitoring for Department of Defense networks in a five-day, eight-hour shift structure, with opportunities to grow into a leadership role supporting cyber operations. We offer competitive compensation and benefits, including health and wellness programs, income protection, paid leave, and retirement. We also provide a broad pay range for this role and support a culture built on innovation, mission focus, and professional growth, with positions associated with Hill AFB, UT; Scott AFB, IL; or Columbus, OH.
last updated 25 week of 2026
Job Tags
Full time, Work experience placement, Relocation, Flexible hours, Shift work, Day shift