Journeyman Cyber Security Engineer

Leidos, Inc.
United States
26 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$87,100.0 - $157,450.0
Working hours
Regular working hours

Tech stack

Data Analysis Systems Engineering Bash Shell C Sharp (Programming Language) Cloud Computing Cyber Security Information Systems Linux Intrusion Detection and Prevention Information Systems Security Architecture Professional Python (Programming Language) Microsoft Security Essentials
+13 more
Windows PowerShell Azure Active Directory Zero Trust Network Access Security Information and Event Management Systems Integration Scripting Microsoft Power Automate Mitre Att&ck Microsoft Fabric Information Technology Microsoft Sentinel Security Orchestration, Automation & Response Vulnerability Analysis

Job description

Leidos Digital is seeking a Journeyman Cyber Security Engineer (Microsoft) to support the U.S. Special Operations Command (USSOCOM) Enterprise Development, Application and Training (EDAT) Zero Trust initiative. This position provides engineering and operational support for Microsoft’s enterprise security platform, helping implement and maintain Zero Trust security capabilities across identity, endpoint, data, and security operations.\n \n The Journeyman Cyber Security Engineer will support the integration of Microsoft security technologies-including Microsoft Sentinel, Microsoft Defender, Microsoft Purview, Microsoft Entra ID, Logic Apps, and Behavior Analytics-to strengthen the Department of Defense (DoD) Visibility and Analytics pillar while enabling security automation and orchestration. Working alongside senior engineers and cybersecurity professionals, this role supports engineering, operational, and RMF activities that improve the organization’s security posture. \n \n This Journeyman role is intended for cybersecurity engineers with solid experience supporting Microsoft security technologies who can independently execute engineering and operational tasks while working under the technical leadership of senior engineers in support of USSOCOM’s Zero Trust implementation.\n \n Active Top Secret clearance with SCI eligibility (TS/SCI) is REQUIRED to be considered for this opportunity.\n \n Key Responsibilities\n \n \n

  • Support the implementation, configuration, and maintenance of Microsoft security technologies within the Zero Trust architecture.\n
  • Assist with deployment and administration of Microsoft Sentinel, Microsoft Defender, Microsoft Purview, Microsoft Entra ID, Logic Apps, and related Microsoft security services.\n
  • Configure and tune analytics rules, workbooks, dashboards, alerts, and automation workflows to improve threat detection and response.\n
  • Support User and Entity Behavior Analytics (UEBA) and Security Orchestration, Automation, and Response (SOAR) capabilities using Microsoft security platforms.\n
  • Assist with integrating security telemetry from Microsoft and third-party enterprise systems.\n
  • Collaborate with ISSOs, cybersecurity engineers, system administrators, and government stakeholders supporting the Zero Trust initiative.\n
  • Support RMF activities, including documentation updates, implementation of security controls, and maintenance of Authorization to Operate (ATO) artifacts.\n
  • Assist with vulnerability assessments, system hardening, and implementation of DISA Security Technical Implementation Guides (STIGs).\n
  • Troubleshoot Microsoft security platform issues and assist with resolving operational challenges.\n
  • Participate in cybersecurity investigations, incident response, and security monitoring activities.\n
  • Document engineering procedures, technical configurations, and operational processes.\n
  • Recommend improvements to security monitoring, automation, and enterprise cybersecurity processes.\n
  • Support continuous improvement initiatives while following cybersecurity best practices.\n

Requirements

  • Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, Engineering, or a related field; and 4 - 8 years of relevant experience may be substituted for a degree.\n
  • Three or more (3+) years of experience supporting enterprise cybersecurity, Microsoft security platforms, or systems engineering.\n
  • Experience administering or supporting Microsoft enterprise security solutions.\n
  • Experience with one or more of the following, + Microsoft Logic Apps\n
  • Microsoft Behavior Analytics\n \n

  • Experience supporting SIEM, SOAR, UEBA, or security monitoring operations.\n
  • Working knowledge of Windows and Linux operating systems.\n
  • Familiarity with enterprise identity, endpoint, cloud, and security architectures.\n
  • Experience supporting RMF documentation or cybersecurity compliance activities.\n
  • Knowledge of DISA STIG implementation and cybersecurity best practices.\n
  • DoD 8140 / 8570 IAT Level II certification (Security+, CySA+, CCNA Security, or equivalent) with the ability to obtain IAT Level III within an approved timeframe if required.\n, * Experience with scripting or automation using PowerShell, Python, Bash, or C#.\n
  • Experience integrating Microsoft security products with third-party security tools.\n
  • Familiarity with MITRE ATT&CK and threat detection engineering.\n
  • Familiarity with Department of Defense and NSA Zero Trust guidance.\n
  • Experience supporting the DoD RMF process and Authorization to Operate (ATO) lifecycle.\n

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobs.military.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

3:52 min

Avoiding remote code execution from unsanitized inputs

Alexander Pirker · WWC 2022

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

2:39 min

Experiencing core Linux capabilities for DevOps administration

Michael Cade · LIVE

54 sec

Interpreting complex terminal commands safely using external explanation utilities

Dan Cranney +2 · LIVE

Videos

See all

Related articles

See all