Security Operations Center (SOC) Analyst
Shiloh, OH - USA
Job Summary
We are seeking proactive defenders for a critical role safeguarding the nations most sensitive digital landscapes. As a Security Operations Center (SOC) Analyst on our 24x7 front-line security operations team you will be directly responsible for defending mission environments against the worlds sophisticated and persistent cyber threats. This role demands exceptional critical thinking a deep-seated adversary mindset and a self-motivated drive to excel in a high-stakes mission.
Primary Responsibilities:
Conduct investigation and triage of security alerts from endpoints IDS/IPS NetFlow and custom sensors to identify and neutralize threats within our mission spaces.
Perform deep-dive analysis of extensive highly-classified log files pivoting between disparate datasets and correlating evidence to support complex incident investigations against nation-state actors.
Produce detailed technical findings and reports for high-level stakeholders documenting adversary tactics techniques and procedures (TTPs).
Integrate and operationalize highly-classified threat intelligence feeds and Indicators of Compromise (IOCs) into security sensors and SIEM platforms.
Collaborate closely with specialized incident response teams and ensure timely precise communication of security incidents to mission partners.
Key Skillsets We Are Looking For:
SOC Experience: You understand the operational flow high tempo demands and rigorous standards of a 24x7 Security Operations Center particularly those operating at the highest classification levels.
Critical Thinking & Adversary Mindset: You possess the ability to look beyond the surface of an alert to uncover the TTPs of advanced persistent threats (APTs). You excel at correlating disparate data points analyzing raw packet data and conducting deep-dive investigations of complex security events.
Demonstrated Self-Motivation: You are a self-starter who takes active ownership of your professional development. Whether pursuing advanced certifications researching emerging threat vectors or mastering new tools you drive your own growth to stay ahead of the adversary.
Thrives on Change: The threat landscape and tactical priorities shift constantly. You demonstrate high operational adaptability viewing unexpected shifts as opportunities to excel and seamlessly pivot to adopt new processes security tools and analytical methodologies.
Shift & Operational Requirements:
Predictable Work-Life Balance: To support your well-being we utilize a predictable five-day 8-hour shift structure.
Shift Options to Fit Your Lifestyle: Our 24x7 mission requires continuous coverage but it also provides the opportunity to align your work hours with your personal routine. Key coverage windows include:
Day Shift: 8:00 AM - 4:00 PM
Swing Shift: 4:00 PM - 12:00 AM
Mid Shift: 12:00 AM - 8:00 AM
Flexibility: We highly value your work-life balance and make every effort to honor your shift preferences whenever possible. While final assignments must ensure critical program requirements are met we strive to manage scheduling with a balanced approach that respects our team members personal needs alongside mission readiness.
Required Qualifications:
Clearance: Must have an active DoD Top Secret security clearance.
Baseline Certification: Current DoD 8570 IAT Level II (or higher) certification such as CompTIA Security CE ISC2 SSCP or SANS GSEC (or equivalent 8140 requirements).
Specialized Certification: Ability to obtain a DoD 8570 CSSP-Analyst level certification (e.g. CEH CySA GCIA or equivalent) within 180 days of hire.
Technical Core: Solid foundation in networking principles including packet analysis common ports/protocols traffic flow the OSI model and defense-in-depth architecture.
Experience & Education:
Bachelors degree and 4 years of relevant experience (Equivalent professional work or military experience will be considered in lieu of a degree)
Location: Commutable distance (within 2 hours) or ability to self-relocate to Scott AFB IL.
Preferred Qualifications:
Prior experience working within a TS/SCI operational environment DISA or other specialized DoD agencies.
Experience applying intelligence-driven defense strategies utilizing the MITRE ATT&CK or Cyber Kill Chain frameworks against known APT intrusion sets.
In-depth experience utilizing SIEM/SOAR platforms to perform behavioral and statistical analysis across multiple log types within a classified network.
Knowledge or experience in defending classified cloud environments (e.g. AWS Secret/Top Secret Azure Government Secret/Top Secret).
Basic scripting and programming skills (e.g. Python PowerShell) to automate routine analytical tasks.
If youre looking for comfort keep scrolling. At Leidos we outthink outbuild and outpace the status quo because the mission demands it. Were not hiring followers. Were recruiting the ones who disrupt provoke and refuse to fail. Step 10 is ancient history. Were already at step 30 and moving faster than anyone else dares.
For U.S. Positions: While subject to change based on business needs Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.
The Leidos pay range for this job level is a general guideline onlyand not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job education experience knowledge skills and abilities as well as internal equity alignment with market data applicable bargaining agreement (if any) or other law.
Required Experience:
IC
About Company
Leidos is an innovation company rapidly addressing the world's most vexing challenges in national security and health. Our 47,000 employees collaborate to create smarter technology solutions for customers in these critical markets.