Leidos logo
Leidos
Posted 174 days agoVerified live 11h ago

Cyber Intrusion Analyst

Brief overview

Pearl City, HIIn-person
UndergradOr in progress
$70k–$126k/yrStated range
2+ yrsMinimum
263 H-1B approvalsDept. of Labor
55 green cardsCertified filings
Clearance requiredU.S. government
Incident detection and responseSecurity tool monitoringLog analysisNetwork traffic analysisPacket capture evaluationCountermeasure development and tuningIDS/IPS systemsFirewall managementAutomation of analysis tasksKnowledge of MITRE ATT&CKCyber Kill Chain familiaritySplunkElasticUnderstanding of software exploitsAnalysis of packed and obfuscated codeTechnical writingCommunication and coordination

About the company

A global technology and defense contractor delivering innovative solutions for national security and health.

Visa sponsorship history

4 years sponsoring, last filed FY2026

Data powered by U.S. Department of Labor. This does not guarantee sponsorship for this specific role.
263H-1B approved
98%approval rate
76new H-1B hires
55PERM certified
$139,285median wage / yr
H-1B Petition ApprovalsVisas USCIS actually granted: the strongest sign the company sponsors.
202393
202476
202584
202610
LCA Certified ApplicationsAn early filing step, not a visa approval: it signals intent, not confirmed sponsorship.
202329
202414
202518
202616
Green Card (PERM) FilingsCertified green card filings: a long-term commitment to international hires.
202318
202412
202519
20266
Top sponsored roles
ServiceNow DeveloperSenior Software DeveloperPublic Health AnalystSenior Java DeveloperCatalyst Synthesis Research Scientist
Sponsored employees from
IndiaEthiopiaChinaNetherlandsCanada

Job description

Summary

Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. They are seeking a Cyber Intrusion Analyst to provide guidance in the CND-SP area, support incident detection and response, and maintain the security of enterprise-wide systems and networks.

Responsibilities

  • Perform computer network incident detection, and response activities to detect, correlate, identify and characterize anomalous activity that may be indicative of threats to the enterprise
  • Monitor various security tools and applications for possible malicious activities, investigate any associated alerts or indicators, and develop recommendations for a course of action, including mitigation strategies as necessary
  • Conduct analysis of low-level (“low and slow”) events to identify unauthorized activity utilizing exploratory problem-solving or self-learning techniques
  • Conduct near real-time event triage and analysis, which can result in network traffic validations or a Mission Partner’s incident report
  • Utilize formal monitoring policies and procedures that include the appropriate use of DoD-approved network monitoring and traffic analysis tools to assist with identifying suspicious, anomalous, or overtly malicious network traffic on a 24/7/365 basis
  • Review and analyze available logs in a timely manner to detect intruders and notify Mission Partners of activity through a formal reporting process/pending an incident report
  • Apply, develop, tune, and distribute or optimize new and existing countermeasures or guidance to prevent or mitigate potential cyber event impacts when possible
  • Perform network traffic analysis utilizing raw packet data, net flow, IDS, IPS and custom sensor output, as it pertains to the cyber security of communications networks
  • Understand attack signatures, tactics, techniques, and procedures associated with advanced threats
  • Requires good technical writing skills as each event, including the associated analysis, are documented in a ticketing system for review and action
  • Requires excellent communication skills as we are collocated with our customer and regular face-to-face interaction is necessary throughout the day, as well as significant coordination and communication between team members

Skills

  • Minimum active DoD Secret clearance with ability to obtain Top Secret (active TS strongly preferred)
  • Current DoD 8570 IAT Level II Certification (e.g. Sec+ CE) or higher at time of start
  • Ability to obtain DoD 8570 CSSP-Analyst certification, such as CEH, CySA+, GCIA or equivalent, within 180 days of hire
  • Bachelor's and 2+ years of relevant experience; additional relevant work experience and/or military service may be considered in lieu of degree
  • Experience working CND duties (e.g., Protect, Defend, Respond, and Sustain)
  • Experience working with DoD / Government Leaders at all levels
  • Strong computing system knowledge, particularly networking, including a knowledge of communication protocols and familiarity with common computing security elements such as IDS/IPS systems and firewalls
  • Experience evaluating packet captures
  • Willingness and ability to perform shift work (shifts may not be static)
  • Command Line Scripting skills (PERL, python, shell scripting) to automate analysis task
  • Knowledge of hacker tactics, techniques and procedures (TTP)
  • Familiarity with computing security frameworks such as MITRE ATT&CK and Cyber Kill Chain
  • Monitoring of intrusion detection and computer defense appliances (Splunk, Elastic), applications, and analysis of associated alerts
  • Knowledge of advanced threat actor tactics, techniques, and procedures (TTP)
  • Understanding of software exploits
  • Analyze packed and obfuscated code

Qualifications

Must Haves

  • Minimum active DoD Secret clearance with ability to obtain Top Secret (active TS strongly preferred)
  • Current DoD 8570 IAT Level II Certification (e.g. Sec+ CE) or higher at time of start
  • Ability to obtain DoD 8570 CSSP-Analyst certification, such as CEH, CySA+, GCIA or equivalent, within 180 days of hire
  • Bachelor's and 2+ years of relevant experience; additional relevant work experience and/or military service may be considered in lieu of degree
  • Experience working CND duties (e.g., Protect, Defend, Respond, and Sustain)
  • Experience working with DoD / Government Leaders at all levels
  • Strong computing system knowledge, particularly networking, including a knowledge of communication protocols and familiarity with common computing security elements such as IDS/IPS systems and firewalls
  • Experience evaluating packet captures
  • Willingness and ability to perform shift work (shifts may not be static)

Nice to Haves

  • Command Line Scripting skills (PERL, python, shell scripting) to automate analysis task
  • Knowledge of hacker tactics, techniques and procedures (TTP)
  • Familiarity with computing security frameworks such as MITRE ATT&CK and Cyber Kill Chain
  • Monitoring of intrusion detection and computer defense appliances (Splunk, Elastic), applications, and analysis of associated alerts
  • Knowledge of advanced threat actor tactics, techniques, and procedures (TTP)
  • Understanding of software exploits
  • Analyze packed and obfuscated code

Benefits

  • Health and Wellness programs
  • Income Protection
  • Paid Leave
  • Retirement

More jobs like this