Cyber Real-Time Analyst

Leidos Holding$69K — $125K *
Aerospace & Defense
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Active Top Secret security clearance with SCI eligibility
  • Bachelor's degree with 2+ years experience (or equivalent military service) for Level II, 4+ years for Level III
  • Cyber Defense Analyst certification compliant with DoD 8140
  • Experience with Computer Network Defense operations
  • Strong networking fundamentals and experience with IDS/IPS, firewalls, and packet analysis
  • Willingness to work rotating shifts including some after-hours support

Responsibilities

  • Monitor and analyze cyber threats across DODIN/DISN using network monitoring tools
  • Perform real-time triage of security incidents to confirm malicious activity
  • Conduct deep analysis of subtle security threats that automated tools may overlook
  • Utilize SIEM platforms for event investigation and correlate data for threat detection
  • Develop custom detection signatures and recommend countermeasures for emerging threats
  • Document findings in DoD reporting systems and coordinate with relevant agencies
  • Support the establishment and operation of a new SOC focused on JFN security

Benefits

  • Opportunity to participate in high-impact missions defending critical infrastructure
  • Chance to build new SOC capabilities alongside an existing mature operation
  • Collaboration with key leaders in cyber defense, enhancing professional visibility
  • Long-term program stability with established team and multi-year task order
Full Job Description
Leidos is hiring Real Time Analysts to join the Network Assurance Team supporting DISA Pacific (DNC-PAC) at Ford Island, Joint Base Pearl Harbor-Hickam. This team serves as the Security Operations Center (SOC) for USPACOM and the broader DoD Information Network (DODIN/DISN), standing watch 24/7/365 to detect, analyze, and respond to threats against the boundary of the Department of Defense's global network. You'll work at the intersection of two missions: the established DISA SOC boundary defense operation that protects the DODIN's Pacific footprint, and the emerging Joint Fires Network (JFN) Security Operations Center supporting a next generation, TS/SCI-level sensor and detection environment being stood up at the same location. It's a rare opportunity to defend mature, mission-critical infrastructure while helping build a brand-new SOC capability from the ground up. What You'll Do: Boundary Cyber Defense & SOC Operations • Monitor, detect, and analyze intrusions, incidents, and threats across the DODIN/DISN boundary - Internet Access Points, Boundary Cloud Access Points, and related infrastructure - using DoD-approved network monitoring and traffic analysis tools on a 24/7/365 basis. • Perform near real-time triage of security events, correlating alerts, netflow, IDS/IPS output, and raw packet captures to confirm or refute malicious activity. • Conduct deep-dive analysis of "low and slow" activity to uncover unauthorized access that automated tools miss. • Investigate and analyze events using SIEM platforms including Splunk, Elastic, and Microsoft Sentinel, and correlate sensor data through the ThunderDome cybersecurity suite. • Apply the MITRE ATT&CK framework to characterize adversary tactics, techniques, and procedures, and to guide incident analysis and threat-hunting. • Develop, tune, and recommend custom detection signatures and countermeasures to prevent or mitigate emerging threats. • Document analysis and findings in the DoD-mandated incident reporting/ticketing system, and issue Situational Awareness Reports and TIPPERs to mission partners. • Coordinate directly with the DISA Joint Operations Center (DJOC), USCYBERCOM, and peer SOCs to synchronize threat intelligence and incident response across the DODIN. Joint Fires Network (JFN) SOC Support • Support stand-up and sustainment of a 24x7x365 Security Operations Center for the JFN IL-6 environment, focused on threat detection and continuous monitoring across JFN nodes. • Conduct Syslog review and Elastic stack alerting to identify anomalies, and tune advanced sensors such as Corelight as the SOC matures. • Triage, escalate, and track incidents through JIRA using standardized SOC intake and escalation processes. • Handle TS/SCI-level incidents in accordance with DIA-aligned requirements, ensuring spills, breaches, or anomalies are reported through authorized channels within mandated timelines. • Develop threat-hunting playbooks focused on behavioral anomalies and traffic pattern analysis as the mission matures from initial monitoring into full detection and response. • Work from a Sensitive Compartmented Information Facility (SCIF) at DISA Pacific, Ford Island. What You'll Need for Success: • Active Top Secret security clearance with eligibility/ability to obtain SCI • Education and experience requirements depending on job level, as follows: - Level II: Bachelor's degree and 2+ years of relevant experience; equivalent work experience and/or military service may be considered in lieu of a degree. - Level III: Bachelor's degree and 4+ years of relevant experience; equivalent work experience and/or military service may be considered in lieu of a degree. • Qualifications/credentials compliant with DoD 8140 DCWF Code 531, Cyber Defense Analyst at the Intermediate proficiency level. • Hands-on experience with Computer Network Defense duties - protect, defend, respond, and sustain. • Strong networking fundamentals, including communication protocols and common security tooling (IDS/IPS, firewalls). • Experience evaluating packet captures and analyzing raw network traffic. • Willingness and ability to work rotating shifts in support of 24/7/365 operations, including some after-hours and surge support. Preferred Qualifications • AI capability development and implementation to automate analysis and detection tasks. • Working knowledge of adversary tactics, techniques, and procedures (TTPs), and familiarity with MITRE ATT&CK and the Cyber Kill Chain. • Direct experience with Splunk, Elastic, or similar SIEM/detection platforms. • Familiarity with JIRA-based incident workflows and/or SOC intake and escalation processes. • Understanding of software exploits, and experience analyzing packed or obfuscated code. Why This Role? • Direct, high-visibility mission impact defending USPACOM and DODIN/DISN infrastructure in a strategically critical theater. • Ground-floor opportunity to help build a new SOC capability alongside an established, mature SOC operation. • Daily collaboration with DISA, USCYBERCOM, and Government leadership - direct exposure to enterprise-level cyber defense decision-making. • Long-term program stability: multi-year task order (base plus four option years) with an established incumbent team. Original Posting: August 10, 2026 For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above. Pay Range: Pay Range $69,550.00 - $125,725.00 The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

About Leidos Holding

Leidos Holding Careers

Joining Leidos Holding presents an unparalleled opportunity to advance one's career with a leader in innovation and technology. The company offers a plethora of job opportunities aimed at fostering professional growth and development in a diverse and inclusive environment.

Explore Career Opportunities

Leidos Holding is actively seeking skilled professionals who are passionate about leveraging their expertise to drive innovation and leadership in their fields. With a variety of open positions, Leidos Holding provides a platform for individuals to challenge themselves in a dynamic work environment.

Innovation and Professional Growth

At Leidos Holding, innovation is at the core of everything they do. Employees are encouraged to think creatively and push boundaries. The company supports this drive for innovation through comprehensive professional development and diversity training programs that are designed to enhance skills and foster leadership.

Commitment to Diversity and Inclusion

Leidos Holding is committed to creating a workplace where diversity is not only recognized but celebrated. With a culture that values and promotes diversity, Leidos Holding ensures that all team members have the opportunity to contribute, learn, and grow.

Internship Programs

For those starting their career, Leidos Holding offers internship programs that provide a robust foundation in the industry. Internships are a great way to develop essential skills, gain valuable work experience, and build professional networks.

Benefits and Culture

Employees at Leidos Holding enjoy a range of benefits designed to support their professional and personal lives. The company culture is built on a foundation of respect and integrity, providing a supportive and collaborative environment where every team member is valued.

Join the Team

Leidos Holding is hiring! Explore job opportunities that match your skills and interests. Leidos Holding looks for driven, curious, and innovative individuals to join their team. Positions are available across various disciplines and experience levels.

Stay Connected

Stay informed with the latest career tips, industry insights, and company news from Leidos Holding. Subscribe to receive updates and be the first to know about new job opportunities, company developments, and more.

Prepare for Your Interview

To prepare for an interview at Leidos Holding, candidates should familiarize themselves with the company's missions and values, update their resumes, and be ready to discuss how their background and skills align with the position they are applying for.

Networking and Career Advancement

Leidos Holding encourages its employees to engage in networking within the company to discover new opportunities for career advancement. The leadership team at Leidos Holding is dedicated to supporting employees in their career paths with ample opportunities for networking and growth.

Explore Leidos Holding Jobs and Careers

Discover the exciting career opportunities at Leidos Holding today. With a commitment to employee growth, innovation, and diversity, Leidos Holding is the perfect place to advance your career. Check out the latest job listings and find your perfect fit at Leidos Holding.

SEARCH LEIDOS HOLDING JOBS

READ CAREERS BLOG

Job Alert Emails

Customize your subscription to receive job alerts and insider tips tailored to your preferences from Leidos Holding. See what exciting and rewarding opportunities await in your professional journey.
Learn more about Leidos Holding

Similar Jobs

More Jobs at Leidos Holding

More Aerospace & Defense Jobs

Find similar Cyber Real-Time Analyst jobs: