Defensive Cyber Operations Analyst

Leidos, Inc.
Fort Meade, MD, United States
7 days ago
Apply on jobs.military.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Compensation
$107,900.0 - $195,050.0
Working hours
Regular working hours

Tech stack

Cyber Security Network Security ArcSight SIEM Tool Security Information and Event Management Mitre Att&ck Cyber Threat Analysis Splunk Vulnerability Analysis

Requirements

  • Bachelor’s degree in a related discipline with 8+ years of applicable combined education and experience; additional related years of experience is accepted in lieu of a degree.\n
  • Active DoD TS/SCI Clearance\n
  • Must have a DoD-8140 WRC 511 Intermediate certification (see list below for acceptable certifications) to start.\n
  • SIEM Tool Experience (ArcSight, Splunk, Elastic, etc..)\n
  • Knowledge of network and application protocols, cyber vulnerabilities and exploitation techniques and cyber threat/adversary methodologies (TTPs)\n
  • Computer Network Defense (CND) experience (Protect, Detect, Respond and Sustain) within a Computer Incident Response organization. Requires a deep understanding and the ability to apply cyber security related principles, theories, and concepts.\n
  • Work independently and as part of a team to develop solutions to issues that are unclear and require deep technical knowledge.\n, * Experience with DISA/DCDC and DoD Networks.\n
  • Knowledge of the DoD orders process\n
  • Demonstrated experience briefing Senior Executive Service (SES) and General Officer/Flag Officer (GO/FO) leadership.\n
  • Experience in building extended cyber security analytics.\n
  • Demonstrated understanding of the life cycle of network threats, attacks, attack vectors and methods of exploitation with an understanding of intelligence driven defense and/or Cyber Kill Chain methodology.\n
  • Experience with User Acceptance Testing (UAT)\n

Benefits & conditions

GSM-O II enables Current Operations Command, Control, and Defensive Cyber Operations (DCO) functions across all - Combatant Commands, Service Cyber Components, Agencies, and Field Activities’ (CC/S/A/FAs) Area of Operations (AOs) in addition to 24/7 coordination with USCYBERCOM and other partner agencies.\n \n \nPrimary Responsibilities:\n \n \n

  • Execute continuous network monitoring and incident handling/problem resolution.\n
  • Triage events, incidents, and assist with developing AO specific trends.\n
  • Support various collaborative and cross functional forums (Intelligence, Current Operations, Future Operations, Logistics, Planning, Resourcing and Requirements) to achieve centrally coordinated, threat informed and prioritized vulnerability scoring and mitigation methodology.\n
  • Support the development, coordination, release, and compliance of orders\n
  • Provide threat analysis, track relevant prioritized incidents, and provide recommendations in coordination with the Cross Functional Fusion Team.\n
  • Leverage intelligence and operational data, information, and processes to identify threats, improve security, and reduce the enterprise’s exposure to vulnerabilities.\n
  • Identify problems, determine accuracy and relevance of a broad range of technical information. Use sound judgment to generate, evaluate, and execute alternative courses of action. Produce timely, effective, decision-quality technical recommendations to support senior leadership.\n
  • Actively engage with a variety of customers and mission partners, anticipating their needs, and delivering flawlessly.\n

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobs.military.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin ¡ World Congress 2022

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 ¡ LIVE

1:38 min

Using language models to self-detect and flag software vulnerabilities

Julian Totzek-Hallhuber Julian Totzek-Hallhuber ¡ World Congress 2026 Europe

4:11 min

Introduction to cloud-native application developer security

Micah Silverman ¡ World Congress 2022

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 ¡ LIVE

Videos

See all

Related articles

See all