Journeyman-level Media Malware Analysts

Leidos, Inc.
United States
11 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$87,100.0 - $157,450.0
Working hours
Regular working hours

Tech stack

Microsoft Windows Artificial Intelligence Unix Cyber Security Linux Digital Forensics Systems Analysis Intrusion Detection and Prevention Network Protocols Open Source Technology Power BI Reverse Engineering
+10 more
Software Engineering Technical Data Management Systems Wireshark Network Routers Malware Cyber Threat Analysis Information Technology IDA Pro Cybercrime Cyber Warfare

Job description

  • Provide timely, accurate, relevant support in manner that best supports USCYBERCOM in identifying and assessing emerging threats and vulnerabilities in the Cyberspace domain. \n
  • Conduct forensic analysis of vulnerable or compromised systems and media and identify and analyze adversary TTPs and intrusion artifacts. \n
  • Perform static and dynamic malware analysis, including reverse engineering and extracting malicious files from digital media and conduct detailed file analysis, as appropriate. \n
  • Create technical analysis reports with actionable intelligence findings, delivering timely, accurate, relevant threat briefs and analysis updates that meet explicit and implied requirements, and deliver presentations to leadership in appropriate formats. \n
  • Identify unique indicators for signature and heuristic development. \n
  • Draft and support implementation of security incident response policies. \n
  • Analyze operational reporting to correlate attack trends and shared tradecraft and support development and improvement of enterprise malware analysis tools. \n
  • Conduct log/system analysis (routers, Windows, UNIX) for threat detection and update DoD situational awareness mechanisms (e.g., USCYBERCOM portals). \n
  • Research open-source intel to inform threat assessments and signature creation. \n
  • Develop and maintain validated MD5 hash lists for signature repositories \n
  • Analyze and evaluate All-Source finished intelligence, single-source intelligence, and technical data from various sources to identify Cyber threat patterns and anomalies. \n
  • Conduct and publish in-depth risk assessments to evaluate and categorize the risk posture of detected cyber threats while supporting development and refinement of risk assessment methodologies and tools used for threat categorization. \n
  • Collaborate with operational, technical, and intelligence elements across USCYBERCOM to enhance situational awareness and threat response capabilities. \n
  • Maintain a current understanding of advanced persistent threats (APTs), threat actor tactics, techniques, and procedures (TTPs), and cyber threat trends affecting national security. \n
  • Maintain situational awareness of, and execute on demand, CO crisis plans. \n
  • Provide situational awareness to range of projects, Crisis Action Teams, and current operations activities supporting Operational Planning Teams (OPTs) \n
  • Execute resource allocation decisions aligned with organization objectives. \n
  • Apply knowledge of cyber threats and attack methods and techniques emanating from state and non-state adversaries and tiered vulnerabilities within Blue Space as focus of threats. \n
  • Review, approve, prioritize, and submit operational requirements for research, development, and/or acquisition of Cyber capabilities \n
  • Interpret and apply laws, regulations, policies, and guidance relevant to daily activities \n
  • Communicate complex information, concepts, or ideas in a confident and well-organized manner through verbal, written, and/or visual means. \n

Requirements

  • BA/BS degree or higher within Computer Science, Cybersecurity, Software Engineering, Digital Forensics, or related field, or ability to complete degree within one year of hire. Can substitute formal education with extended experience and technical certifications. \n
  • Five plus years’ demonstrated proficiency in malware analysis (static/dynamic), incident handling, and reverse engineering. \n
  • Working experience with tools such as IDA Pro, Ghidra, Wireshark, Volatility, and sandbox environments. \n
  • Intimate familiarity with network protocols, OS internals (Windows/Linux/UNIX), and cyber threat analysis \n
  • Broad knowledge of Blue-space Cyber capabilities and demonstrate understanding of available Cyber infrastructure or platforms to conduct Defensive (DCO) and Offensive Cyberspace Operations (OCO) \n
  • Knowledge of computer networking fundamentals as well as concepts, terminology, and operations of a wide range of communications media (computer and telephone networks, satellite, fiber, wireless). \n
  • Ability to support timely, accurate, relevant analytical production, to include documents, summaries, issue papers, talking points, and briefings. \n
  • Demonstrated proficiency working in a fast-paced collaborative environment, ability to proactively multi-task and meet short deadlines. \n
  • Strong interpersonal, critical thinking, and communication skills, including the ability to clearly convey complex and technical data to nontechnical consumers. \n, * Masters’ Degree or higher within Cybersecurity, Information Security, or related fields. \n
  • Experience developing detection signatures and writing technical reports for leadership. \n
  • Deep understanding of USCYBERCOM organizational structure and mission. \n
  • Prior experience supporting Joint operations across multiple warfighting domains. \n
  • Demonstrated experience incorporating Artificial Intelligence and Machine Learning into operations at any level to increase efficiency and effectiveness of operational outcomes \n
  • Experience with Space-enabled CO. \n
  • Formal training within field of Cyber Warfare and Joint Operations. \n
  • Familiar with art of Data Science and applicability to CO. \n
  • Familiar with Microsoft Power BI data visualization software. \n
  • Desired Certifications (not all inclusive, no expectations for candidate to hold all certifications): GIAC Reverse Engineering Malware (GREM); Certified Reverse Engineering Analyst (CREA); Certified Malware Analyst (CMA); Digital Forensics and Incident Response (DFIR); GIAC Certified Forensic Analyst (GCFA); GIAC Cyber Threat Intelligence (GCTI). \n

Benefits & conditions

n \nLooking for an opportunity to make an impact? \n \n At Leidos, we deliver innovative solutions through the efforts of our diverse and talented people who are dedicated to our customers’ success. We empower our teams, contribute to our communities, and operate sustainably. Everything we do is built on a commitment to do the right thing for our customers, our people, and our community. The Leidos Intelligence Sector) combines technology-enabled services and mission software capabilities in the areas of cyber, logistics, security operations, and decision analytics to support our defense and intel customers’ mission to defend against evolving threats around the world. \n \n \nYour greatest work is ahead! \n \n, Beware of fake employment opportunities using Leidos’ name. Leidos will never ask you to provide payment-related information during any part of the employment application process (i.e., ask you for money), nor will Leidos ever advance money as part of the hiring process (i.e., send you a check or money order before doing any work). Further, Leidos will only communicate with you through emails that are generated by the Leidos.com automated system - never from free commercial services (e.g., Gmail, Yahoo, Hotmail) or via WhatsApp, Telegram, etc. If you received an email purporting to be from Leidos that asks for payment-related information or any other personal information (e.g., about you or your previous employer), and you are concerned about its legitimacy, please make us aware immediately by emailing us at LeidosCareersFraud@leidos.com. \n \n If you believe you are the victim of a scam, contact your local law enforcement and report the incident to the U.S. Federal Trade Commission. \n \n \nCommitment to Non-Discrimination \n \n All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.”, “hiringOrganization”: {“@type”: “Organization”, “name”: “Leidos”, “logo”: “https://jobs.military.com/attachments/employer/0/962/152/273.svg”}, “jobLocation”: {“address”: {“addressCountry”: “United States”, “streetAddress”: “Not specified”, “@type”: “PostalAddress”, “postalCode”: “21113”, “addressLocality”: “Odenton”, “addressRegion”: “Maryland - MD”}, “@type”: “Place”}, “industry”: “Information”, “identifier”: {“@type”: “PropertyValue”, “name”: “Leidos”, “value”: “R-00188490”}, “baseSalary”: {“@type”: “MonetaryAmount”, “currency”: “USD”, “value”: {“minValue”: “87100”, “@type”: “QuantitativeValue”, “maxValue”: “157450”, “value”: “87100”, “unitText”

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobs.military.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin ¡ WWC 2022

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard ¡ WWC 2025

2:03 min

Microsoft integrating native Unix coreutils into Windows environments

Chris Heilmann +2 ¡ LIVE

14:14 min

Addressing audience inquiries on analytical implementation and career growth

Julian Joseph ¡ LIVE

2:39 min

Experiencing core Linux capabilities for DevOps administration

Michael Cade ¡ LIVE

2:04 min

Defining timestamps and the international standard format

Denny Biasiolli Denny Biasiolli ¡ Europe 2026 Virtual

Videos

See all

Related articles

See all