Cyber Defense Analyst

  • Leidos
  • Suitland, Maryland
  • 09/15/2026
Full time Information Technology Telecommunications

Job Description

Leidos is seeking a Cyber Defense Analyst to safeguard critical government and commercial systems. You will monitor security events, investigate threats, and respond to incidents across complex networks and cloud environments. Responsibilities include threat hunting, log analysis, tuning security tools, and recommending enhancements to architectures and controls. You'll collaborate with engineering and operations teams, produce clear reports, and support compliance with cybersecurity standards. Leidos offers flexible work options, strong benefits, and extensive training to grow your skills in a mission-driven environment.

Responsibilities

  • Continuously monitor SIEM and security tools to detect suspicious activity and indicators of compromise.
  • Investigate security alerts, perform triage, and lead incident containment, eradication, and recovery.
  • Conduct threat hunting using logs, network data, and endpoint telemetry to identify hidden threats.
  • Analyze vulnerabilities and support remediation planning with infrastructure and application teams.
  • Tune and optimize security tools, detection rules, and playbooks to reduce false positives and improve coverage.
  • Collaborate with engineering, operations, and program teams to design and maintain secure architectures.
  • Document investigations, produce incident reports, and communicate findings to technical and non-technical stakeholders.
  • Support compliance with relevant cybersecurity frameworks and government or commercial standards.
  • Contribute to continuous improvement of security operations processes and automation.
  • Stay current on emerging threats, tools, and best practices and share knowledge with the team.

Required Skills

  • Security Information and Event Management (SIEM)
  • Intrusion detection and prevention
  • Incident response and handling
  • Network security monitoring and analysis
  • Threat hunting and threat intelligence
  • Log and packet analysis
  • Endpoint detection and response (EDR)
  • Cloud security (AWS/Azure)
  • Vulnerability assessment and remediation
  • Scripting/automation (Python, Power
  • Shell)