Cyber Security Analyst

Leidos

$87K — $157K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree with 4-8 years of cyber or IT experience.
  • Hands-on experience in cybersecurity network defense within a Computer Incident Response organization.
  • Fluent in Packet Capture (PCAP) analysis.
  • DoD 8570 IAT-II and CSSP-Analyst certifications required prior to starting.
  • Strong written and verbal communication skills for complex technical reporting.
  • Active TS/SCI clearance with customer SAP read-ons required.
  • 3+ years' experience in a SOC environment.

Responsibilities

  • Identify solutions to gaps in cyber capabilities and visibility.
  • Drive research and implementation of automation and process efficiencies.
  • Utilize intermediate command line skills for Linux utilities like tcpdump, sed, awk, and grep.
  • Create and tune Intrusion Detection Systems (IDS) such as Snort or Bro/Zeek.
  • Analyze alerts and surrounding network traffic for remediation context.
  • Generate new IDS configurations from consumed open and closed source data.
  • Maintain current threat awareness and derive conclusions from complex traffic analysis.

Benefits

  • Work in a Tier II Cyber Security analysis role with significant growth potential.
  • Engage in diverse and current cybersecurity technologies and methodologies.
  • Opportunity to research and implement new tools and frameworks.
  • Partake in the adoption of automation and process enhancements.
  • Potential for schedule rotation from night shift to day shift.
Full Job Description
Leidos is seeking a Cyber Security Analyst in San Antonio, TX. This position provides Tier II Cyber Security Analysis to C5ISR Center Defensive Cyber Solutions Branch (DCSB) Defensive Cyber Operations (DCO). Beyond advising and guiding technical matters, this position is tasked with driving implementation and adoption of new tools, research, capabilities, frameworks, and methodologies while ensuring those already in use are implemented, utilized properly, and improved.

Schedule: Day/Night Panama schedule- primarily hiring for night shift with the possibility to rotate to days

Primary Responsibilities

  • Identify and offer solutions to gaps in capabilities and visibility
  • Promote and drive research and implementation of automation and process efficiencies
  • Intermediate command line experience that includes chaining Linux utilities such as tcpdump, sed, awk, and grep together
  • Intermediate IDS (Snort, Bro/Zeek, etc.) creation and tuning, to include performing impact analysis on customer environments and review and correction of Tier I rules
  • Analysis of alerts plus surrounding network traffic to provide remediation context
  • Ability to consume open and closed source and search indicators in customer data, then generate new IDS configurations for future detection
  • Basic hunt experience that includes sifting non-alert-based traffic and deriving meaningful results in the absence of corresponding OSINT
  • Vulnerability awareness and able to determine applicability to customer environments, using data to establish attack attempts and success/failure
  • Maintaining current threat awareness
  • Ability to analyze complex (multipacket, multi-vector, multi-exploit, large volume) traffic and derive meaningful conclusions
  • Self-directed research, development, customization, or other contributions to process improvement
  • Continual enrichment of IDS and moderate ability to tune on the fly
  • Ability to self-educate with non-comprehensive or incomplete documentation on new concepts, protocols, and data formats


Basic Qualifications

Bachelor's Degree and 4-8 years of cyber or previous IT experience.
  • Hands-on cybersecurity network defense experience (Detect and Respond) within a Computer Incident Response organization. Hands-on experience with a Security Information and Event Management tool (ArcSight, Security Onion, etc.)
  • Fluent in computer network Packet Capture (PCAP) analysis
  • DoD 8570 IAT-II and CSSP-Analyst certifications required prior to starting
  • Demonstrated advanced knowledge of industry accepted standards.
  • Motivated self-starter with strong written and verbal communication skills, and the ability to create complex technical reports on analytic finding.
  • Strong analytical and troubleshooting skills.
  • Must be a US Citizen
  • Candidate must possess an active TS/SCI and be approved customer SAP read-ons
  • 3+ years' experience working in a SOC environment


Preferred Qualifications

  • Deep technical understanding of core current cybersecurity technologies as well as emerging capabilities.
  • Demonstrated understanding of the life cycle of cybersecurity threats, attacks, attack vectors and methods of exploitation with an understanding of intrusion set tactics, techniques and procedures (TTPs).
  • Familiarity or experience in Intelligence Driven Defense, Cyber Kill Chain methodology, and MITRE ATT&CK framework.


Original Posting:
June 4, 2026

For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

Pay Range:
Pay Range $87,100.00 - $157,450.00

The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

Similar Jobs

More Jobs at Leidos

More Information Technology Jobs

Find similar Cyber Security Analyst jobs: