> Markdown version of [/jobs/ext/2311959-defensive-cybersecurity-analyst](https://www.wearedevelopers.com/jobs/ext/2311959-defensive-cybersecurity-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Defensive Cybersecurity Analyst - **Company:** Leidos, Inc. - **Location:** Scott Air Force Base, IL, United States - **Experience:** Experienced - **Salary:** $69,550.0 - $125,725.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, CompTIA Security+, Cyber Security, Information Systems, Intrusion Detection Systems, OSI Models, Log Files, NetFlow, Networking Basics, Packet Analyzer, Open Source Technology, Security Information and Event Management, Mobile Security, Google Cloud, Cloud Platform System, Mitre Att&ck, Cybercrime - **Published:** August 30, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9129031/defensive-cybersecurity-analyst ## About the Role We are seeking proactive defenders who bring Security Operations Center (SOC) experience, exceptional critical thinking skills, and a self-motivated approach to safeguarding infrastructure as Cyber Security Analysts in our 24x7 front-line security operations team. In this role, you will be directly responsible for defending Department of Defense (DoD) networks against sophisticated, rapidly evolving cyber threats., * SOC Experience: You understand the operational flow, high tempo demands, and rigorous standards of a 24x7 Security Operations Center. You are comfortable executing structured incident triage and escalation protocols. * Critical Thinking & Adversary Mindset: You possess the ability to look beyond the surface of an alert. You excel at correlating disparate data points, analyzing raw packet data, and conducting deep-dive investigation of complex security events to uncover sophisticated malicious activity. * Demonstrated Self-Motivation: You are a self-starter who takes active ownership of your professional development. Whether pursuing advanced certifications, researching emerging threat vectors, or mastering new tools, you drive your own growth. * Thrives on Change: The threat landscape and tactical priorities shift constantly. You demonstrate high operational adaptability, viewing unexpected shifts as opportunities to excel, and seamlessly pivot to adopt new processes, security tools, and analytical methodologies to counter evolving adversaries or challenges., * Clearance: Active DoD Secret clearance, with the ability to obtain and maintain a TS/SCI. * Baseline Certification: Current DoD 8570 IAT Level II (or higher) certification, such as CompTIA Security+ CE, ISC2 SSCP, or SANS GSEC (or equivalent 8140 requirements). * Specialized Certification: Ability to obtain a DoD 8570 CSSP-Analyst level certification (e.g., CEH, CySA+, GCIA, or equivalent) within 180 days of hire. * Technical Core: Solid foundation in networking principles, including packet analysis, common ports/protocols, traffic flow, the OSI model, and defense-in-depth architecture. * Experience & Education: + Level I: Bachelor's degree and 2+ years of relevant experience (Equivalent professional work or military experience will be considered in lieu of a degree) + Level II: Bachelor's degree and 4+ years of relevant experience (Equivalent professional work or military experience will be considered in lieu of a degree). * Location: Commutable distance (within 2 hours) or ability to self-relocate to Scott AFB, IL. Preferred Qualifications: * Prior experience working within Defense Information Systems Agency (DISA) or DOD Environments. * Experience applying intelligence-driven defense strategies utilizing the MITRE ATT&CK or Cyber Kill Chain frameworks, including a deep understanding of intrusion set tactics, techniques, and procedures (TTPs). * In-depth experience utilizing SIEM/SOAR platforms to perform behavioral and statistical analysis across multiple log types. * Knowledge or experience in defending cloud environments (AWS, Azure, GCP) or administering enterprise mobile security (MDM, MAM, MTD). * Basic scripting and programming skills to automate routine analytical tasks. ## Description * Investigate and triage security alerts generated from endpoints, IDS/IPS, NetFlow data, and custom sensors to identify suspicious activity. * Analyze extensive log files, pivot between diverse datasets, and correlate evidence to support incident investigations, producing detailed technical findings and reports. * Monitor and integrate DoD and open-source threat intelligence feeds and Indicators of Compromise (IOCs) into security sensors and SIEM platforms. * Collaborate closely with incident response teams and ensure timely, clear communication of security incidents to customers and USCYBERCOM., * Predictable Work-Life Balance: To support your well-being, we utilize a predictable five-day, 8-hour shift structure. * Shift Options to Fit Your Lifestyle: Our 24x7 mission requires continuous coverage, but it also provides the opportunity to align your work hours with your personal routine. Key coverage windows include: + Day Shift: 8:00 AM - 4:00 PM + Swing Shift: 4:00 PM - 12:00 AM + Mid Shift: 12:00 AM - 8:00 AM * Flexibility: We highly value your work-life balance and make every effort to honor your shift preferences whenever possible. While final assignments must ensure critical program requirements are met, we strive to manage scheduling with a balanced approach that respects our team members' personal needs alongside mission readiness. ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [The Software Bug All Stars - and what we can learn from them](https://www.wearedevelopers.com/videos/423-the-software-bug-all-stars-and-what-we-can-learn-from-them) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Logs in observability - Correlation](https://www.wearedevelopers.com/videos/1430-logs-in-observability-correlation) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)