Enter a job title or keyword

Cyber Intel Analyst

Leidos


Job Location:

Washington, DC - USA

Yearly Salary: USD 87100 - 157450
Posted: 29 September 2026 (Yesterday)
Application Deadline: 27 December 2026
Vacancies: 1 Vacancy

Job Summary

Leidos Digital Sector is seeking Cyber Analysts with backgrounds in Threat Hunting Threat Intel and/or Cyber Fusion to join our Defensive Cyber Operations team in Washington DC in early 2027. These positions will support our DCO team with protecting federal networked systems and services from threats to national security.

These are hybrid roles that are primarily on-site with up to 20% telework potential. Core hours are supporting a team of analysts on 24/7 rotating shifts (days swings nights); occasional shift or weekend work may be required to cover gaps.

PLEASE NOTE these positions are expected to become available in Winter/Spring 2027. Recruiters will contact qualified applicants as timeline firms up.

Primary Responsibilities

Threat Hunting

  • Develop and execute hypothesis-driven hunt campaigns based on adversary TTPs
  • Query and correlate telemetry across cloud identity and network infrastructure to surface low and slow attacks
  • Partner with detection engineering to convert hunt findings into automated SIEM/EDR detection rules
  • Build automation for countermeasure deployment and asset isolation
  • Use MITRE ATT&CK to proactively search for APT activity

Threat Intelligence

  • Produce strategic operational and tactical intelligence reports on emerging threats and actor motivations
  • Characterize adversary TTPs and build APT profiles using MITRE ATT&CK
  • Manage the intelligence lifecycle: PIRs collection plans and dissemination
  • Evaluate and manage IOC/IOB fidelity within a Threat Intelligence Platform (TIP)
  • Deliver Indications & Warnings (I&W) to support hunt and DCO operations

Cyber Fusion

  • Synthesize external threat intelligence with internal hunt telemetry into a unified operational picture
  • Author Fusion Reports blending forensics and strategic intelligence for leadership
  • Correlate global threat activity against internal sensor logs via SIEM/TIP
  • Pair vulnerability data with active threat reporting to prioritize remediation
  • Maintain the teams single source of truth for prioritized threat data

Shared across all tracks

  • Maintain situational awareness of the evolving threat landscape and its relevance to the customer enterprise
  • Author clear technical reporting and metrics on findings gaps and posture improvements
  • Collaborate across Hunt Intel Engineering and Fusion functions to ensure intelligence drives defensive action

Basic Qualifications

  • Current DoD TS/SCI clearance and ability to pass additional customer suitability screening prior to start and maintain throughout employment
  • Education and experience depending on job level:
    • Level III: Bachelors degree in a related discipline and 4 years of relevant work experience OR Masters degree in a related discipline and 2 years of relevant work experience. Additional experience may be considered in lieu of degree.
    • Level IV: Bachelors degree in a related discipline and 8 years of relevant work experience OR Masters degree in a related discipline and 6 years of relevant work experience. Additional experience may be considered in lieu of degree.
  • DoD 8570 IAT Level II or higher required to start e.g. Security CySA GSEC SSCP CASP CE CCNP Security CISA GCED GCIH or CISSP
  • DoD 8570 CSSP Analyst certification required within 180 days of onboarding e.g. CySA Cloud GCIA CEH
  • DoD 8570 CSSP Infrastructure Support certification required within 180 days of onboarding e.g. CySA Cloud CEH CND CHFI GICSP SSCP
  • Strong knowledge of networking protocols (TCP/IP DNS HTTP/S) and security controls (IDS/IPS next-gen firewalls)

Preferred Skills

  • Query languages: SPL (Splunk) KQL (Kusto) or Elastic DSL for large-scale data analysis
  • Scripting: Python PowerShell or Bash for automation and data enrichment
  • Cloud familiarity: AWS Azure O365 containerized workloads
  • Framework fluency: MITRE ATT&CK Cyber Kill Chain Diamond Model of Intrusion Analysis
  • DFIR experience (packet capture / endpoint log analysis root-cause reconstruction)
  • Experience with Threat Intelligence Platforms (Anomali ThreatConnect MISP) or OSINT/commercial threat portals (Recorded Future VirusTotal Mandiant Advantage)
  • Prior work in a Cyber Fusion Center (CFC) or Joint Operations Center (JOC)
  • AI-driven analytics experience for anomaly/behavioral detection
  • Strong analytical writing translating technical findings into executive-level briefings

#nebo

If youre looking for comfort keep scrolling. At Leidos we outthink outbuild and outpace the status quo because the mission demands it. Were not hiring followers. Were recruiting the ones who disrupt provoke and refuse to fail. Step 10 is ancient history. Were already at step 30 and moving faster than anyone else dares.

Original Posting:
September 15 2026

For U.S. Positions: While subject to change based on business needs Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

Pay Range:
Pay Range $87100.00 - $157450.00

The Leidos pay range for this job level is a general guideline onlyand not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job education experience knowledge skills and abilities as well as internal equity alignment with market data applicable bargaining agreement (if any) or other law.


Required Experience:

IC


About Company

Company Logo

Leidos is an innovation company rapidly addressing the world's most vexing challenges in national security and health. Our 47,000 employees collaborate to create smarter technology solutions for customers in these critical markets.

View Profile View Profile