Cyber Intrusion Analyst

San Antonio

Onsite$69,550

Requirements - ----------- ### Must have: ### - We require the ability to obtain a Secret clearance and the ability to reach TS/SCI level. - We prefer a bachelors degree, although relevant work experience and/or military service may substitute for the degree. - We need strong knowledge of networking, including TCP/IP fundamentals, network traffic analysis, Wireshark, and Cisco Packet Tracer. - We need programming familiarity with Python, Java, JavaScript, and HTML. - We expect experience with Linux, operating systems concepts, computer architecture, and MySQL. - We need a solid background in security monitoring, threat detection, SIEM concepts, risk mitigation, and NIST framework concepts. - We require experience working with Department of Defense or government environments. - We need strong computing systems knowledge, especially communication protocols, IDS/IPS systems, and firewalls. - Preferred qualifications include an active Department of Defense Secret clearance. - Preferred qualifications include CompTIA Security , TCP/IP networking, Linux systems, Cisco Packet Tracer, and Wireshark experience. - Preferred qualifications include familiarity with military regulations and security compliance procedures. - Preferred qualifications include experience in both CONUS and OCONUS threat environments supporting Department of War facilities. - Preferred qualifications include command-line scripting skills such as PERL, Python, or shell scripting to automate analysis tasks. - Preferred qualifications include knowledge of hacker tactics, techniques, and procedures, as well as advanced threat actor TTPs. - Preferred qualifications include familiarity with MITRE ATT\&CK and the Cyber Kill Chain frameworks. - Preferred qualifications include experience monitoring intrusion detection and cyber defense tools such as Splunk and Elastic, along with alert analysis. - Preferred qualifications include understanding of software exploits. Responsibilities: - ---------------- - We lead and develop the IMCOM HHA team, providing hands-on guidance and mentoring to improve inspection effectiveness and operational performance. - We ensure compliance with Army quality and regulatory standards as part of the IMCOM HHA team. - We perform computer network inspections to help prevent incidents and detect, correlate, identify, and characterize anomalous activity that may indicate threats to the enterprise. - We monitor security tools and applications for malicious activity, investigate alerts and indicators, and recommend mitigation actions. - We analyze low-level and slow-moving events to uncover unauthorized activity using exploratory problem-solving and self-learning techniques. - We carry out event triage and analysis, which may support network traffic validation or a mission partner incident report. - We use approved monitoring policies and procedures, along with DoD-approved network monitoring and traffic analysis tools, to identify suspicious or malicious traffic on a 24/7/365 basis. - We review logs promptly to detect intruders and notify mission partners through formal reporting or incident reporting processes. - We develop, tune, distribute, and optimize countermeasures or guidance to reduce the impact of cyber events whenever possible. - We analyze network traffic using raw packet data, netflow, IDS, IPS, and custom sensor outputs in support of communications network security. - We apply our understanding of attack signatures, tactics, techniques, and procedures associated with advanced threats. - We document each event and its analysis in a ticketing system for review and action. - We communicate frequently with teammates and customers, including regular face-to-face coordination throughout the day. - ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- Company: - ------- We are Leidos, an industry and technology leader delivering smarter, more efficient digital and mission solutions to government and commercial customers. Our Defense Sector is hiring a Cyber Intrusion Analyst supporting the IMCOM HHA team with an active Secret clearance requirement. We offer a competitive pay range of $69,550 to $125,725, along with benefits including health and wellness programs, income protection, paid leave, and retirement. We are headquartered in Reston, Virginia, and employ 47,000 people globally. We also emphasize our commitment to fair hiring and non-discrimination, and we want people who are ready to challenge the status quo and move fast in mission-critical work. - ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------

Leidos

Leidos