Cyber Fusion Analyst

Leidos, Inc.
Washington, DC, United States
28 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
6 years minimum
Compensation
$107,900.0 - $195,050.0
Working hours
Shift work

Tech stack

Amazon Web Services Software System Penetration Testing Audit Trail Microsoft Azure Cloud Computing CompTIA Security+ Emulators Python (Programming Language) Open Source Intelligence Kusto Query Language Security Information and Event Management Technical Data Management Systems
+7 more
Scripting Office365 Mitre Att&ck Cyber Threat Analysis Firewall Services Module Cyber Warfare Splunk

Job description

The Leidos Digital Modernization sector is looking for a to support a Defensive Cyber Operations (DCO) team in Washington, DC.

Our Cyber Fusionteam provides mission-critical support to the customer’s mission of protecting federal networked systems by integrating disparate intelligence, hunting telemetry, and vulnerability data into a single operational view. We bridge the gap between “knowing the threat” and “stopping the threat,” ensuring that intelligence directly drives defensive actions.

This hybrid position is primarily on-site, with potential for up to 20% telework. While this position will primarily work during core hours (0600 - 1600), this position will be supporting a team of analysts working 24/7 rotating shifts (days, swings, nights). As such, occasional shift work or weekend work may be required to fill unexpected gaps in coverage.

  • Synthesize external threat intelligence (TTPs, IOCs) with internal hunt telemetry to develop a comprehensive understanding of the adversary’s impact on the enterprise.
  • Author high-impact “Fusion Reports” that blend technical forensics with strategic intelligence to brief senior leadership on trending threats and operational risks.
  • Utilize SIEM and Threat Intelligence Platforms (TIP) to correlate global threat actor activity against internal sensor logs, identifying “low and slow” campaigns that span multiple mission sets.
  • Maintain a living “Adversary Encyclopedia” by mapping internal discoveries to the MITRE ATT&CK framework to identify systemic defensive gaps.
  • Analyze Vulnerability Disclosure Program (VDP) data alongside active threat reporting to prioritize patching efforts based on real-world exploitation trends.
  • Provide data-backed recommendations to Engineering and DCO teams to adjust firewall rules, EDR policies, and SIEM logic based on emerging fusion findings.
  • Develop and refine custom analytics that provide “early warning” of adversary reconnaissance or pre-exploitation activity targeting the customer enterprise.
  • Maintain the “Single Source of Truth” for threat data, ensuring that Hunt, Intel, and Engineering teams are operating from a synchronized set of prioritized threats.

Requirements

  • Bachelor’s Degree with 8+ yrs of experience or Master’s Degree with 6+ yrs of relevant experience; additional years of experience may be substituted in lieu of degrees.
  • Must hold a certification such as CompTIA Security+, CASP+ CE, or CISSP.
  • Must hold a CSSP Analyst certification (e.g., CEH, CySA+) or obtain within 180 days.
  • Analytic Writing Mastery: Demonstrated ability to synthesize complex technical data into concise, non-technical executive briefings.
  • Framework Proficiency: Expert understanding of the Cyber Kill Chain, Diamond Model, and MITRE ATT&CK.
  • and ability to passprior to start and maintain throughout employment

  • Fusion Center Experience: Previous experience working within a government or large-scale commercial Cyber Fusion Center (CFC) or Joint Operations Center (JOC).
  • Query & Scripting: Proficiency in SPL (Splunk) or KQL (Kusto) for data correlation; Python skills for automating intelligence ingestion and enrichment.
  • OSINT & Commercial Portals: Experience utilizing tools like Recorded Future, VirusTotal, or Mandiant Advantage to pivot from external indicators to internal threats.
  • Cloud Fusion: Familiarity with fusion analysis within AWS, Azure, or O365 environments, specifically correlating cloud-native audit logs.
  • Adversary Emulation: Basic understanding of Red Teaming or Penetration Testing methodologies to better predict adversary movement.

ms

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

58 sec

Navigating limitations of local Cosmos DB emulators

Radu Vunvulea Radu Vunvulea · WWC 2022

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

1:49 min

Testing with emulators, simulators, and real devices

Milica Aleksic Milica Aleksic · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

Videos

See all

Related articles

See all