At Leidos, we deliver innovative solutions through the efforts of our diverse and talented people who are dedicated to our customers’ success. We empower our teams, contribute to our communities, and operate sustainable practices. Everything we do is built on a commitment to do the right thing for our customers, our people, and our community. Our Mission, Vision, and Values guide the way we do business. Employees enjoy career enrichment opportunities available through mobility and development and experience rewarding relationships with supportive supervisors and talented colleagues and customers. Your most important work is ahead.
If this sounds like the kind of environment where you can thrive, keep reading!
The CND watch provides 24x7 support. Candidates must have the ability to support shift work. Duties include leading a team responsible for network security monitoring and detection, proactively searching for threats, inspecting traffic for anomalies and new malware patterns, investigating and analyzing logs, providing analysis and response to alerts, and documenting activity in investigations.
This is a 24/7/365 team.
- Lead a team of cyber professionals responsible for 24x7x365 monitoring of all CND detection on all customer security domains.
- Ensure accountability and punctuality of security analysts assigned to your shift
- Ensure shift continuity during call-outs and emergencies
- Compile incident reports, executive summaries, and analysis reports of intrusions and/or security events
- Perform critical thinking and analysis to investigate cyber security alerts and clearly communicate findings to the customer
- Perform initial alert triage and document findings and recommendations
- Analyze network traffic using enterprise tools (e.g. SIEM, Full PCAP, Firewall, Proxy logs, IDS logs, etc)
- Collaborate with team members to analyze an alert or a threat
- Review and provide feedback to junior analysts’ investigation
- Review and implement network counter measures
- Stay up to date with latest threats
- Mentor and train junior analysts and manage the operations of your shift.
- Utilize OSINT to aid in their investigation
- Contribute to content tuning and development
- Familiarity with a SOC’s purpose and role within an organization
- General understanding of common network ports and protocols (e.g. TCP/UDP, HTTP, ICMP, DNS, SMTP, etc)
- Familiarity with network topologies and network security device functions (e.g. Firewall, IDS/IPS, Proxy, DNS, etc).
- Experience performing analysis of network traffic and correlating diverse security logs to perform recommendations for response
- Able to perform critical thinking and analysis to investigate cyber security alerts
- Familiarity with common malware and attack vectors
- Familiarity with various operating systems and standard OS logging
- Familiarity with Malware Protection, DLP, and host based firewalls
- Experience working in a 24/7/365 SOC environment
- Excellent oral and written communication skills. Ability to communicate and work effectively with other contractors and Government civilians.
- Highly organized with strong troubleshooting and problem-solving skills
- Ability to work independently and as a team member under tight deadlines with changing priorities.
- Must be a self-motivated individual in pursuit of a career in cybersecurity!
- TS/SCI with CI Poly required for Position or TS/SCI and willingness to get a poly.
- US Citizenship is required due to the nature of the government contracts we support.
- DoD 8570 IAT Level II equivalent certification (with continuing education where applicable) (Security+, CCNA Security, CSA+, GICSP, GSEC, SSCP) or higher
- DoDD 8140/DoD 8570.01M Computing Environment certification
- GIAC Continuous Monitoring (GMON) or equivalent (CySA+, CCNA – Cyber Operations, CCIH) within 180 days of contract start
- DoD 8570 CND-Analyst/CSSP Analyst equivalent certification (CEH, CFR, CSA+, GCIA, GCIH, GICSP, SCYBER) within 180 days of contract start
- Splunk Core Certified User within 180 days of contract start
- Bachelor’s Degree in Computer Science, Engineering, Information Technology, Cybersecurity, or related field. Additional experience may be considered in lieu of degree.
- A minimum of 4 years of professional experience in relevant areas such as:
- Vulnerability Assessment
- Intrusion Prevention and Detection
- Access Control and Authorization
- Policy Enforcement
- Application Security
- Protocol Analysis
- Firewall Management
- Incident Response
- Web content filtering
- Advanced Threat Protection
- Experience with both Splunk and ArcSight SIEM platforms
- Splunk certifications (Splunk Core Certified User, Splunk Core Certified Power User)
- Experience as a SOC shift lead supporting 24x7 missions
- Experience in network and cybersecurity design, engineering and operations
- Experience with Service Desk support and operations
- Familiarity with SOC methodologies and processes
Pay Range:Pay Range $78,000.00 - $120,000.00 - $162,000.00
The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.
Leidos is a Fortune 500® innovation company rapidly addressing the world’s most vexing challenges in national security and health. The company's global workforce of 47,000 collaborates to create smarter technology solutions for customers in heavily regulated industries. Headquartered in Reston, Virginia, Leidos reported annual revenues of approximately $15.4 billion for the fiscal year ended December 29, 2023. For more information, visit www.Leidos.com.
Pay and Benefits
Pay and benefits are fundamental to any career decision. That's why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available here.
Securing Your Data
Beware of fake employment opportunities using Leidos’ name. Leidos will never ask you to provide payment-related information during any part of the employment application process (i.e., ask you for money), nor will Leidos ever advance money as part of the hiring process (i.e., send you a check or money order before doing any work). Further, Leidos will only communicate with you through emails that are generated by the Leidos.com automated system – never from free commercial services (e.g., Gmail, Yahoo, Hotmail) or via WhatsApp, Telegram, etc. If you received an email purporting to be from Leidos that asks for payment-related information or any other personal information (e.g., about you or your previous employer), and you are concerned about its legitimacy, please make us aware immediately by emailing us at [email protected].
If you believe you are the victim of a scam, contact your local law enforcement and report the incident to the U.S. Federal Trade Commission.
Commitment to Diversity
All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.