Join our talent network

Job #: R-00005043
Location: CHANTILLY, VA
Category: Cyber Security
Schedule (FT/PT): Full time
Travel Required: No
Shift: Day
Potential for Telework: No
Clearance Required: Top Secret/SCI with Polygraph
Referral Eligibility: Eligible
Group: Defense & Intel

Job Description:

The candidate will act as the senior support person for the ArcSight team. Candidate must have the ability to configure and support ArcSight. Must have proven experience and ability to leverage CND analyst toolsets to detect and respond to IT security incidents. The candidate will be responsible for operating, maintaining, and monitoring an ArcSight SIEM installation at a 24/7 operations center. The candidate is responsible for Linux performance tuning & troubleshooting, identifying and resolving contention in CPU, memory, networking, disk I/O, etc.

In this role, the Cyber Security Engineer will:
  • Upgrade/update all ArcSight components as required (Loggers, Connectors, ESM).
  • On-board new event sources by obtaining access to the logs, installing the software, and then tuning/adjusting the connector;
  • Monitor and tune of all ESM components for performance;
  • Assist with analyst activity by providing reports, writing queries, running searches, fixing broken content, etc;
  • Investigate any reported problems and determine the root cause;
  • Create documentation of standard procedures, system configurations, etc.;
  • Configure the tools to work with Syslog, File and Database collection of events.
  • Create and edit content to both monitor and alert on security incidents;
  • Provide guidance to both internal and external Customer issues and supporting tickets; and,
  • Provide Tier 2/3 troubleshooting for ArcSight issues, either within the tool or as part of an integrated team of professionals addressing larger issues

Required Qualifications

Bachelor's degree from accredited university/college in Computer Science, Information Technology or related field; Associates degree with five additional year's applicable experience acceptable.
  • 12+ years of experience in cyber security
  • Demonstrated expertise in ArcSight SIEM
  • 4+ years of demonstrated expertise with Linux administration
  • Provide Tier 3 troubleshooting for ArcSight issues, either within the tool or as part of an integrated team of professionals addressing larger issues
  • Configure the tools to work with Syslog, File and Database collection of events.
  • Create and edit content to both monitor and alert on security incidents.
  • Providing guidance to both internal and external Customer issues and supporting tickets
  • Act as the senior subject matter expert on the tool for interactions with other teams
  • Develop documentation to support the mission
  • Provide "on the job training" to teammates
  • Ability to create custom dashboards and reports;
  • Significant understanding of SQL, REGEX, Bash and Perl;
  • Deep knowledge optimizations for large networks;
  • Ability to create content for ArcSight security alerting;
  • Demonstrated experience executing the responsibilities listed above
  • Provide on-call support when needed

Desired Qualifications
  • Ability to write Bash scripts
  • Knowledge of Windows systems administration
  • Knowledge of Splunk


Leidos is a Fortune 500® information technology, engineering, and science solutions and services leader working to solve the world’s toughest challenges in the defense, intelligence, homeland security, civil, and health markets. The company’s 31,000 employees support vital missions for government and commercial customers. Headquartered in Reston, Virginia, Leidos reported annual revenues of approximately $10.17 billion for the fiscal year ended December 29, 2017. (NYSE: LDOS) All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status.

Talent Community

Join our Talent Community to create a profile, enabling a streamlined application process and to help our recruiters better understand your areas of expertise and interest.

Join our Talent Community