> Markdown version of [/jobs/ext/2038117-defensive-cyber-operations-analyst](https://www.wearedevelopers.com/jobs/ext/2038117-defensive-cyber-operations-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Defensive Cyber Operations Analyst - **Company:** Leidos, Inc. - **Location:** Washington, VA, United States - **Contract:** Permanent contract - **Skills:** Issue Tracking Systems, Intrusion Detection Systems, Pcap, Log Analysis, Computer Networking Systems, In-Plane Switching (IPS), Firewalls (Computer Science), Cyber Warfare - **Published:** August 12, 2026 - **Apply:** https://us.experteer.com/career/view-jobs/defensive-cyber-operations-analyst-washington-va-usa-58917306 ## About the Role _ translating security events into actionable insights * Document every event and analysis in the ticketing system for audit and follow-on actions * Coordinate with team and customers in a collocated, high-tempo environment * Support CSSP with detect, respond, mitigate, and recover activities Tasks * Bachelor in related discipline with 2+ years (Level II) or 4+ years (Level III) or 8+ years (Level IV) of relevant experience * DoD 8570 IAT Level II/III certification or higher (e.g., Security+, CySA+, GSEC, SSCP) or equivalent * DoD 8570 CSSP Analyst certification or equivalent * DoD 8570 CSSP Infrastructure Support certification or equivalent * Current DoD TS/SCI security clearance and ability to pass customer suitability screenings * Strong networking knowledge, including IDS/IPS, firewalls, PCAP and log analysis Key requirements * ## Description Experteer Overview In this role you will support a Defensive Cyber Operations team protecting federal networks from threats. You will work in a 24/7 operational environment, collaborating with cross-functional teams to detect and respond to incidents. You will translate complex security events into actionable guidance for management and ensure thorough documentation. This role offers hands-on defense work with opportunities to influence solutions and improve processes. Join a mission-driven team that defends critical infrastructure and contributes to national security. Compensation / Benefits * Detect and characterize anomalous network activity to identify enterprise threats * Monitor security tools, investigate alerts, and develop mitigation actions * Follow SOPs with strong attention to detail and maintain complete documentation * Provide technical leadership and influence project approaches; review peer investigations * Develop and deliver technical briefings to senior management, translating security events into actionable insights * Document every event and analysis in the ticketing system for audit and follow-on actions * Coordinate with team and customers in a collocated, high-tempo environment * Support CSSP with detect, respond, mitigate, and recover activities Tasks * Bachelor in related discipline with 2+ years (Level II) or 4+ years (Level III) or 8+ years (Level IV) of relevant experience * DoD 8570 IAT Level II/III certification or higher (e.g., Security+, CySA+, GSEC, SSCP) or equivalent * DoD 8570 CSSP Analyst certification or equivalent * DoD 8570 CSSP Infrastructure Support certification or equivalent * Current DoD TS/SCI security clearance and ability to pass customer suitability screenings * Strong networking knowledge, including IDS/IPS, firewalls, PCAP and log analysis Key requirements * ## Related Videos - [Progressive Delivery in Kubernetes](https://www.wearedevelopers.com/videos/949-progressive-delivery-in-kubernetes) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Leveraging Large Language Models for Legacy Code Translation: Challenges and Solutions](https://www.wearedevelopers.com/videos/1157-leveraging-large-language-models-for-legacy-code-translation-challenges-and-solutions) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [APItoolkit: Using Merkle Trees and LLMs to Detect the UnDetectable in Software Monitoring](https://www.wearedevelopers.com/videos/1639-apitoolkit-using-merkle-trees-and-llms-to-detect-the-undetectable-in-software-monitoring) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)