Endpoint Security Analyst - Elastic Defend

Leidos, Inc.
Adelphi, MD, United States
9 days ago
Apply on www.clearancejobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Compensation
$107,900.0 - $195,050.0
Working hours
Regular working hours

Tech stack

Cyber Security System Configuration Intrusion Detection and Prevention McAfee VirusScan Performance Tuning SAP (Applications) Mitre Att&ck Cyber Threat Analysis Tanium Platform Expertise Cybercrime Epic ECSA Cyber Warfare

Job description

You will work closely with threat, engineering, and cybersecurity operations teams to strengthen endpoint defenses, improve visibility, and rapidly identify and respond to emerging cyber threats., * Deploy, configure, operate, tune, upgrade, and troubleshoot Elastic Agent, Elastic Defend, and other enterprise endpoint security technologies.

  • Optimize endpoint protection and telemetry collection to maximize security visibility and detection effectiveness while minimizing operational and system performance impacts.
  • Partner with Threat and Detection teams to customize detection rules, develop threat signatures, and align endpoint defenses with emerging threat intelligence and MITRE ATT&CK techniques.
  • Conduct host-based defensive cyber operations to identify, investigate, contain, mitigate, and remediate vulnerabilities and intrusions.
  • Support cyber investigations using advanced endpoint queries, forensic data collection, and rapid containment and response capabilities.
  • Build and maintain queries, dashboards, and reports that provide enterprise security visibility and leadership awareness.
  • Coordinate with engineering teams on endpoint security deployments, patches, hot fixes, upgrades, and other critical security updates.
  • Troubleshoot endpoint security tool issues, performance concerns, and outages.
  • Develop and maintain endpoint security policies, configurations, and Standard Operating Procedures (SOPs).
  • Evaluate emerging endpoint security tools, techniques, and technologies and recommend improvements aligned with enterprise cybersecurity strategy.

Requirements

  • Bachelor’s degree in Science, Technology, Engineering, Mathematics (STEM), cybersecurity, or a related field and 4+ years of relevant cybersecurity experience.
  • Hands-on experience deploying, configuring, operating, or supporting enterprise endpoint security or EDR solutions.
  • Strong understanding of endpoint protection, security telemetry, threat detection, incident investigation, and response.
  • Experience investigating and responding to endpoint security alerts and potential compromises.
  • Knowledge of current cyber threats, attacker techniques, and defensive strategies, including familiarity with the MITRE ATT&CK framework.
  • Strong analytical, troubleshooting, and problem-solving skills.
  • Ability to work effectively across cybersecurity, threat, and engineering teams.
  • Strong written and verbal communication skills.
  • U.S. citizenship and an active TS/SCI with SAP eligibility.
  • At least one of the following certifications:
  • GIAC/SANS: GCIA, GCIH, GCFA, GCFE, GREM, GISF, GXPN, GWEB, GNFA, or GMON
  • Offensive Security: OSCP, OSCE, OSWP, or OSEE
  • ISC2: CCFP or CISSP
  • EC-Council: CEH, CHFI, LPT, ECSA, or ECI, * Hands-on experience with Elastic Agent and Elastic Defend, including deployment, configuration, policy management, tuning, and troubleshooting.
  • Experience optimizing endpoint telemetry and security controls in large-scale enterprise environments.
  • Experience developing or tuning endpoint detection rules, threat signatures, IOCs, and behavioral detections.
  • Experience using Elastic capabilities for endpoint investigation, advanced querying, forensic data collection, and response actions.
  • Experience with CrowdStrike Falcon, McAfee/Trellix ePO, Tanium, or similar enterprise endpoint security platforms.
  • Experience deploying and configuring CrowdStrike Falcon sensors and creating custom Indicators of Compromise (IOCs) and Indicators of Attack (IOAs).
  • Experience supporting endpoint security operations within large, complex, or mission-critical environments.
  • Relevant endpoint security certifications, such as Elastic, CrowdStrike, or Tanium certifications.

Benefits & conditions

Pay and benefits are fundamental to any career decision. That’s why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available at www.leidos.com/careers/pay-benefits .

About the company

The C5ISR Center Cyber Security Service Provider (CSSP) is a premier defensive cyber operations organization supporting the Department of War (DoW). Operating 24x7x365, the CSSP provides continuous monitoring, threat detection, incident response, and vulnerability management across cloud and on-premises environments, including AWS, Azure, GCP, Oracle Cloud, and SaaS platforms.

Every day, our team protects the networks, systems, and data that enable critical DoW missions., Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $16.7 billion for the fiscal year ended January 3, 2025. For more information, visit www.Leidos.com .

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:15 min

Retaining the defender advantage in the cybersecurity race

Michele Zuccala Michele Zuccala +4 Ā· World Congress 2026 Europe

1:38 min

Using language models to self-detect and flag software vulnerabilities

Julian Totzek-Hallhuber Julian Totzek-Hallhuber Ā· World Congress 2026 Europe

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa Ā· LIVE

2:16 min

Defending against supply chain and targeted endpoint attacks

Markus Dorner Ā· Coffee With Developers

2:11 min

Securing heterogeneous legacy payment infrastructure against AI

Michele Zuccala Michele Zuccala +4 Ā· World Congress 2026 Europe

46 sec

Using LLMs to reverse engineer undocumented legacy code

Michele Zuccala Michele Zuccala +4 Ā· World Congress 2026 Europe

Videos

See all

Related articles

See all