Skip to content

Cybersecurity Analyst
Company | Leidos |
---|
Location | Scott AFB, IL, USA |
---|
Salary | $67600 – $122200 |
---|
Type | Full-Time |
---|
Degrees | Bachelor’s |
---|
Experience Level | Junior, Mid Level |
---|
Requirements
- Bachelor’s degree and 2+ years of prior relevant experience (related DISA customer experience and Cyber courses/certifications may be substituted in place of degree)
- Active DoD 8570, IAT Level II Certification, and CSSP-Analyst1 certification at your start date
- Demonstrated understanding of the life cycle of network threats, attacks, attack vectors, and methods of exploitation with an understanding of intrusion set tactics, techniques, open-source, and procedures (TTPs)
- Demonstrated understanding of TCP/IP, common networking ports and protocols, traffic flow, system administration, OSI model, defense-in-depth and common security elements
- Experience and proficiency with any of the following: Anti-Virus, HIPS, ID/PS, Full Packet Capture, Host-Based Forensics, Network Forensics
- Experience with malware analysis concepts and methods
- Familiarity or experience in Intelligence Driven Defense
- Willing to perform rotating shift work
Responsibilities
- Review DoD and open-source intelligence for threats
- Identify Indicators of Compromise (IOCs) and integrate those into sensors and SIEMs
- Triage and review system alerts to identify malicious actors on customer networks
- Assist T1 analysts with triage and analysis
- Complete moderate-level analysis of potential cybersecurity events that could threaten IT Systems
- Report incidents to customers and USCYBERCOM
- Create complex technical reports on analytic findings
Preferred Qualifications
- Advanced certifications such as SANS GIAC/GCIA/GCIH, CISSP or CASP and/or SIEM-specific training and certification (Security+ CE, CISSP or equivalent)
- Demonstrated commitment to training, self-study, and maintaining proficiency in the technical cyber security domain
- CND experience (Protect, Detect, Respond and Sustain) within a Computer Incident Response organization or Security Operations Center
- In-depth knowledge of architecture, engineering, and operations of at least one enterprise SIEM platform (e.g. Nitro/McAfee Enterprise Security Manager, ArcSight, QRadar, LogLogic, Splunk)