Cyber Intrusion Analyst

Leidos, Inc.
San Antonio, TX, United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
$69,550.0 - $125,725.0
Working hours
Regular working hours

Tech stack

HTML Java (Programming Language) JavaScript (Programming Language) Command-Line Interface Communications Protocols CompTIA Security+ Cyber Security Computer Networks Linux Perl (Programming Language) Issue Tracking Systems Intrusion Detection and Prevention
+17 more
Intrusion Detection Systems Python (Programming Language) MySQL Network Forensics Network Monitoring Shell Script Security Information and Event Management Transmission Control Protocol (TCP) Traffic Analysis Wireshark Network Simulation Scripting Mitre Att&ck Firewalls (Computer Science) SC Clearance Information Technology Splunk

Job description

The Defense Sector at Leidos currently has an opening for a Cyber Intrusion Analyst with a active SECRET clearance!

Primary Responsibilities.

  • Leadership & Team Development
  • Member of the IMCOM HHA team, ensuring compliance with Army quality and regulatory standards.
  • Provide hands-on leadership to the IMCOM HHA team, mentoring and developing inspectors to ensure efficient operational support and continuous improvement.
  • Perform computer network inspections to mitigate / prevent incident detection, and response activities to detect, correlate, identify and characterize anomalous activity that may be indicative of threats to the enterprise.

  • Monitor various security tools and applications for possible malicious activities, investigate any associated alerts or indicators, and develop recommendations for a course of action, including mitigation strategies as necessary.
  • Conduct analysis of low-level (ā€œlow and slowā€) events to identify unauthorized activity utilizing exploratory problem-solving or self-learning techniques.
  • Conduct event triage and analysis, which can result in network traffic validations or a Mission Partner’s incident report.
  • Utilize formal monitoring policies and procedures that include the appropriate use of DoD-approved network monitoring and traffic analysis tools to assist with identifying suspicious, anomalous, or overtly malicious network traffic on a 24/7/365 basis.
  • Review and analyze available logs in a timely manner to detect intruders and notify Mission Partners of activity through a formal reporting process/pending an incident report.
  • Apply, develop, tune, and distribute or optimize new and existing countermeasures or guidance to prevent or mitigate potential cyber event impacts when possible.
  • Perform network traffic analysis utilizing raw packet data, net flow, IDS, IPS and custom sensor output, as it pertains to the cyber security of communications networks.
  • Understand attack signatures, tactics, techniques, and procedures associated with advanced threats.
  • Requires good technical writing skills as each event, including the associated analysis, are documented in a ticketing system for review and action.
  • Requires excellent communication skills as we are collocated with our customer and regular face-to-face interaction is necessary throughout the day, as well as significant coordination and communication between team members.

Requirements

  • Ability to obtain Secret Clearance. Ability to achieve TS/SCI clearance level
  • Bachelor’s, additional relevant work experience and/or military service may be considered in lieu of degree
  • Networking: TCP/IP Fundamentals, Network Traffic Analysis, Wireshark, Cisco Packet Tracer
  • Programming: Python, Java, JavaScript, HTML
  • Systems: Linux, Operating Systems Concepts, Computer Architecture, MySQL
  • Security & Analysis: Security Monitoring, Threat Detection Concepts, SIEM Concepts, Risk Mitigation, NIST Framework Concepts
  • Experience working with DoW / Government.
  • Strong computing system knowledge, particularly networking, including a knowledge of communication protocols and familiarity with common computing security elements such as IDS/IPS systems and firewalls.

Preferred Qualifications.

  • Active DOW Secret Clearance.
  • CompTIA Security+, TCP/IP networking, Linux systems, Cisco Packet Tracer, Wireshark
  • Familiarity with Military Regulations and security compliance procedures
  • Experience with both CONUS and OCONUS threat environments to Department of War facilities.
  • Command Line Scripting skills (PERL, python, shell scripting) to automate analysis task.
  • Knowledge of hacker tactics, techniques and procedures (TTP).
  • Familiarity with computing security frameworks such as MITRE ATT&CK and Cyber Kill Chain.
  • Monitoring of intrusion detection and computer defense appliances (Splunk, Elastic), applications, and analysis of associated alerts.
  • Knowledge of advanced threat actor tactics, techniques, and procedures (TTP)
  • Understanding of software exploits.

Benefits & conditions

Pay and benefits are fundamental to any career decision. That’s why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available at www.leidos.com/careers/pay-benefits .

About the company

Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $16.7 billion for the fiscal year ended January 3, 2025. For more information, visit www.Leidos.com .

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:21 min

Projecting external HTML content using default and named slots

Rowdy Rabouw Rowdy Rabouw Ā· WWC 2022

2:18 min

Scaling MySQL databases for massive user growth

Johannes Nicolai Johannes Nicolai +1 Ā· LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard Ā· WWC 2025

1:45 min

Transitioning from software development to security roles

Stefania Chaplin Ā· WWC 2022

6:12 min

Streaming HTML content natively using declarative processing instructions

Chris Heilmann +2 Ā· LIVE

14:14 min

Addressing audience inquiries on analytical implementation and career growth

Julian Joseph Ā· LIVE

Videos

See all

Related articles

See all