Cyber Security Analysts
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+24 more
Job description
As a Cyber Security Analyst, you’ll be on the front lines, defending Department of Defense networks from evolving cyber threats. You will be a key member of our 24x7 security operations team, responsible for:
- Analyzing real-time cyber threat intelligence to stay ahead of emerging threats.
- Correlating security events to identify and prioritize potential incidents.
- Conducting in-depth network traffic analysis using raw packet data to uncover malicious activity.
- Collaborating with incident response teams to contain and eradicate threats.
Shift Opportunities:
We offer flexible shift options to accommodate your needs. The primary available shifts are: 7:00 AM - 3:00 PM, 3:00 PM - 11:00 PM, & 11:00 PM - 7:00 AM. Shift assignments will be based on program requirements and your preference, but some flexibility may be required., * Investigate alerts generated from endpoints, IDS/IPS, NetFlow data, and custom sensors to detect compromises on customer networks.
- Analyze extensive log files, pivot between diverse datasets, and correlate evidence to support incident investigations, creating detailed technical reports outlining your findings.
- Triage security alerts to rapidly identify malicious actors targeting customer networks.
- Monitor and analyze DoD and open-source intelligence feeds to identify Indicators of Compromise (IOCs) and integrate them into security sensors and SIEMs.
- Report security incidents to customers and USCYBERCOM, ensuring timely communication and coordinated response.
Requirements
- Minimum active DoD Secret clearance with the ability to obtain TS/SCI.
- Current DoD 8570 IAT Level II certification (or higher), such as CompTIA Security+ CE, ISC2 SSCP, or SANS GSEC (or equivalent).
- Ability to obtain DoD 8570 CSSP-A Level Certification (e.g., CEH, CySA+, GCIA, or equivalent) within 180 days of hire.
- Strong foundation in networking, including packet analysis, common ports and protocols, and traffic flow. Knowledge of the OSI model, defense-in-depth security principles, and common security elements for effective threat detection, analysis, and mitigation as a SOC Security Analyst.
- Education and experience requirements:
- Level I: Bachelor’s degree and 1+ years of relevant experience; equivalent work experience and/or military service may be considered in lieu of a degree.
- Level II: Bachelor’s degree and 3+ years of relevant experience; equivalent work experience and/or military service may be considered in lieu of a degree.
- Proven ability to work effectively both independently and as a collaborative team member, demonstrating initiative and a strong work ethic in both settings.
- Committed to continuous learning and self-improvement in the cybersecurity domain, as evidenced by ongoing pursuit of certifications, active participation in industry forums, and dedication to staying ahead of emerging threats and technologies.
- Excellent problem-solving skills, including the ability to collaborate effectively with cross-functional teams to address complex security challenges in real-world scenarios. This includes the ability to communicate technical information clearly and concisely, build consensus, and drive solutions to completion.
- Reliable and flexible, with a demonstrated willingness to work assigned shifts to support operational requirements and team objectives.
- Located within a commutable distance (within 2 hours) or able to self-relocate to Scott AFB, IL.
Preferred Qualifications:
- Hands-on experience analyzing large volumes of logs, network data (e.g., Netflow, Full Packet Capture), and other attack artifacts during incident investigations.
- In-depth experience using a SIEM/SOAR platform to analyze multiple log types and events across various data points, applying techniques such as behavioral analysis, statistical analysis, and machine learning to detect and respond to advanced threats.
- Comprehensive understanding of the network threat lifecycle, attack vectors, and methods of exploitation, including intrusion set tactics, techniques, and procedures (TTPs).
- Experience with Anti-Virus, HIPS/HBSS, IDS/IPS, Full Packet Capture, and Network Forensics tools.
- Experience or knowledge in monitoring, defending, or administering cloud networks (e.g., AWS, Azure, GCP), including cloud-native security tools and strategies for protecting data in cloud environments. Experience identifying and mitigating cloud-specific attacks.
- Experience managing, defending, administering, or deploying mobile devices (iOS, Android) for enterprise, including mobile device management (MDM), mobile application management (MAM), and mobile threat defense (MTD). A strong understanding of mobile security best practices and mobile threat landscape is highly desired.
- Scripting and programming skills., Amazon Web Services (AWS), Analysis Skills, Android, Antivirus, Best Practices, Cloud Computing, Communication Skills, Computer Hacking, Computer Programming, Computer Security, Cross-Functional, Data Sets, Defense Information Systems Agency (DISA), Defense in Depth, DoD Secret Clearance, Emerging Technology, Establish Priorities, Forensic Science, GCP (Good Clinical Practices), GSM (Global System for Mobile Communications), Incident Response, Information/Data Security (InfoSec), Internet Security, Intrusion Detection Systems, Intrusion Prevention Systems, Legal, Logfile Analysis, Machine Learning, Manufacturing Data Management, Microsoft Windows Azure, Mobile Applications, Mobile Devices, Netflow, Network Administration/Management, Network Security, Network Traffic Analysis, OSINT (Open Source Intelligence), Open Systems Interconnection (OSI), Operational Support, Problem Solving Skills, Scripting (Scripting Languages), Security Analysis, Security Attacks, Security Information and Event Management (SIEM), Sensitive Compartmented Information (SCI), Statistics, Team Building, Team Lead/Manager, Team Player, Time Management, Top Secret Clearance, United States Department of Defense (DoD), iOS
About the company
If you’re looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo - because the mission demands it. We’re not hiring followers. We’re recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We’re already at step 30 - and moving faster than anyone else dares., SAIC is a premier Fortune 500® technology integrator driving our nation’s digital transformation. Our robust portfolio of offerings across the defense, space, civilian, and intelligence markets includes secure high-end solutions in engineering, IT modernization, and mission solutions. Using our expertise and understanding of existing and emerging technologies, we integrate the best components from our own portfolio and our partner ecosystem to deliver innovative, effective, and efficient solutions that are critical to achieving our customers’ missions. We are a team of 26,000 strong driven by mission, united purpose, and inspired by opportunity. Headquartered in Reston, Virginia, SAIC has annual revenues of approximately $7.1 billion. For more information, visit saic.com.
Company Size: 10,000 employees or more
Industry: Computer/IT Services
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Dev Digest 134 - Where pixels sing?
Best Paying Jobs in Technology
Understanding and Mitigating Common Web Vulnerabilities
The Most Popular IT Jobs on the Market