Summary
Leidos is a technology and mission-services company supporting government and commercial customers, including the Defense Manpower Data Center CyberPRIMES program. The Tier 2 Security Operations Center Analyst performs advanced cybersecurity event analysis, incident triage and containment, evidence preservation, troubleshooting, reporting, and coordination with cybersecurity teams in a 24x7 security operations environment.
Responsibilities
- Perform advanced analysis of cybersecurity events escalated from Tier 1 analysts or identified through endpoint, user-activity, network, and other enterprise monitoring capabilities
- Correlate alerts, security telemetry, and supporting technical data to determine the nature, scope, severity, and potential impact of cybersecurity activity
- Distinguish legitimate activity, false positives, policy violations, suspicious behavior, and potential cybersecurity incidents
- Determine appropriate next actions based on approved SOC procedures, playbooks, and escalation criteria
- Recommend or initiate authorized actions to contain or mitigate identified threats
- Support cybersecurity incident triage, escalation, and containment in coordination with the incident-response team
- Preserve relevant technical evidence and supporting information required for further investigation and incident response
- Document investigative actions, analysis, findings, and conclusions in Government-approved systems
- Maintain complete and accurate event records, tickets, timelines, and supporting evidence
- Contribute to required SOC event reporting and operational status information
- Perform Tier 2 troubleshooting of cybersecurity tools, alerts, security data, and related technical issues
- Use approved Commercial-Off-The-Shelf (COTS) security-analysis tools to investigate cybersecurity events
- Support security testing, mitigation activities, and cybersecurity compliance checking as required by SOC operations
- Coordinate analysis with incident responders, network engineers, endpoint-security personnel, cybersecurity-tool teams, system administrators, and other cybersecurity stakeholders
- Identify recurring false positives, detection gaps, or ineffective alerting and recommend improvements to monitoring and detection capabilities
- Support tuning of cybersecurity monitoring capabilities to improve detection accuracy and analyst effectiveness
- Contribute to SOC procedure, playbook, and process improvements based on operational experience and lessons learned
- Support knowledge transfer across SOC analysts to improve consistent analysis and response within the 24x7 operating environment
Skills
- • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related technical discipline and 2-4 years of relevant cybersecurity experience or a Masters with less than 2 years. Specific experience, education and training may be considered in lieu of degree
- • Experience performing cybersecurity event analysis, SOC operations, cyber defense, incident triage, or security monitoring
- • Experience analyzing and correlating alerts from multiple cybersecurity monitoring capabilities
- • Experience investigating endpoint, network, user-activity, or other cybersecurity events
- • Experience determining the scope, severity, and potential impact of suspicious cybersecurity activity
- • Experience supporting cybersecurity incident escalation, containment, mitigation, or evidence preservation
- • Experience using enterprise security-analysis or cybersecurity monitoring tools
- • Experience performing Tier 2 cybersecurity troubleshooting
- • Working knowledge of cybersecurity attack techniques, network-security concepts, endpoint security, event analysis, and incident-response processes
- • Ability to document investigations, findings, actions, and conclusions clearly and accurately
- • Ability to work effectively within a team-based 24x7 security operations environment
- • U.S. Citizenship required
- • Active Secret security clearance required at time of consideration
- • Experience supporting a Department of Defense or Federal Security Operations Center
- • Experience working in a 24x7 SOC or Cybersecurity Service Provider environment
- • Experience with Security Information and Event Management (SIEM) platforms and enterprise cybersecurity monitoring tools
- • Experience analyzing endpoint, network, identity, user-activity, intrusion-detection, or other cybersecurity telemetry
- • Experience supporting cybersecurity incident response and digital-evidence preservation
- • Experience tuning security alerts, detection logic, or monitoring capabilities to reduce false positives and improve detection quality
- • Experience developing or refining SOC procedures, playbooks, or escalation criteria
- • Experience with cybersecurity mitigation, compliance checking, or security testing
- • Familiarity with Department of Defense cybersecurity requirements and Risk Management Framework processes
- • Familiarity with DHRA, DMDC, or comparable Department of Defense enterprise environments
Qualifications
Must Haves
- • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related technical discipline and 2-4 years of relevant cybersecurity experience or a Masters with less than 2 years. Specific experience, education and training may be considered in lieu of degree
- • Experience performing cybersecurity event analysis, SOC operations, cyber defense, incident triage, or security monitoring
- • Experience analyzing and correlating alerts from multiple cybersecurity monitoring capabilities
- • Experience investigating endpoint, network, user-activity, or other cybersecurity events
- • Experience determining the scope, severity, and potential impact of suspicious cybersecurity activity
- • Experience supporting cybersecurity incident escalation, containment, mitigation, or evidence preservation
- • Experience using enterprise security-analysis or cybersecurity monitoring tools
- • Experience performing Tier 2 cybersecurity troubleshooting
- • Working knowledge of cybersecurity attack techniques, network-security concepts, endpoint security, event analysis, and incident-response processes
- • Ability to document investigations, findings, actions, and conclusions clearly and accurately
- • Ability to work effectively within a team-based 24x7 security operations environment
- • U.S. Citizenship required
- • Active Secret security clearance required at time of consideration
Nice to Haves
- • Experience supporting a Department of Defense or Federal Security Operations Center
- • Experience working in a 24x7 SOC or Cybersecurity Service Provider environment
- • Experience with Security Information and Event Management (SIEM) platforms and enterprise cybersecurity monitoring tools
- • Experience analyzing endpoint, network, identity, user-activity, intrusion-detection, or other cybersecurity telemetry
- • Experience supporting cybersecurity incident response and digital-evidence preservation
- • Experience tuning security alerts, detection logic, or monitoring capabilities to reduce false positives and improve detection quality
- • Experience developing or refining SOC procedures, playbooks, or escalation criteria
- • Experience with cybersecurity mitigation, compliance checking, or security testing
- • Familiarity with Department of Defense cybersecurity requirements and Risk Management Framework processes
- • Familiarity with DHRA, DMDC, or comparable Department of Defense enterprise environments
Benefits
- Health and Wellness programs
- Income Protection
- Paid Leave
- Retirement