Find Jobs
Find Jobs Near You – Available Work in Your Location
Cyber Defense Analyst (3rd Shift)
Job Description
Cyber Defense Analyst (3rd Shift)
Skills
- JWICS
- ATLAS
- Technical Analysis
- Tier 2
- Management
- Issue Tracking
- Wireless Security
- Reporting
- Information Technology
- Information Assurance
- Security Clearance
- Event Management
- SIEM
- Splunk
- Network
- Intrusion Detection
- Palo Alto
- Microsoft
- Scripting
- Python
- Perl
- Ruby
- JavaScript
- Windows PowerShell
- C• C++• Java• Nmap• Burp Suite• Metasploit• Report Writing• Intelligence Collection• Cyber Security• Analytical Skill• Problem Solving• Conflict Resolution• Penetration Testing• CompTIA• Cloud Computing• Certified Ethical Hacker• GCIA• GCIH• Cisco• Recruiting• Market Analysis• Law• JWICS• ATLAS• Technical Analysis• Tier 2• Management• Issue Tracking• Wireless Security• Reporting• Information Technology• Information Assurance• Security Clearance• Event Management• SIEM• Splunk• Network• Intrusion Detection• Palo Alto• Microsoft• Scripting• Python• Perl• Ruby• JavaScript• Windows PowerShell• C• C++• Java• Nmap• Burp Suite• Metasploit• Report Writing• Intelligence Collection• Cyber Security• Analytical Skill• Problem Solving• Conflict Resolution• Penetration Testing• CompTIA• Cloud Computing• Certified Ethical Hacker• GCIA• GCIH• Cisco• Recruiting• Market Analysis• Law•SummaryCyber Defense Analyst (3rd Shift)
Location:
Suitland, MDClearance:
Active TS/SCI3rd
Shift Work Hours:
2330
- 0730Leidos is seeking a Cyber Defense Analyst (3rd Shift) to join a mission focused team supporting the Navy's cybersecurity environment at the Office of Naval Intelligence (ONI) Hopper Global Communications Center (HGCC) in Suitland, MD.
In this role, you will serve on the front line of cyber defense, helping protect critical TS/SCI networks by monitoring and investigating cybersecurity alerts, identifying potential threats, and supporting proactive threat hunting activities. You will apply your experience in the Certified Network Defender (CND) discipline and knowledge of IT systems and networks to analyze security events, manage incident tickets, support intelligence gathering and analysis, and communicate findings to key stakeholders.
Work Schedule:
This is a 3rd shift position with regular work hours of 2330
- 0730.
Occasional floater shifts or coverage outside of these hours may be required based on program and staffing needs.
Primary Responsibilities
- Perform first line monitoring of security tools and conduct initial analysis of alerts for TS/SCI networks, including JWICS, ATLAS, and other networks for which HGCC is responsible.
- Monitor organizational cybersecurity tools for alerts, anomalies, and indicators of compromise.
- Investigate and perform initial technical analysis of cybersecurity alerts and events, escalating potential incidents to Tier 2 as appropriate.
- Create, update, and manage incident and event tickets within the approved ticketing system.
- Conduct proactive threat hunting activities to identify potential malicious activity and emerging threats.
- Perform wireless security scans of facilities and document and report findings.
- Correlate alerts and security events across multiple platforms to identify patterns, trends, and potential threats.
- Prepare and deliver operational and situational awareness briefings.
- Support annual cyber defense exercises.
Required Qualifications
- Bachelor's degree in Cybersecurity, Information Technology, Information Assurance, or a related area of study desired with 4+ years of experience or Master's degree with 2+ years of experience. Additional experience may be considered in lieu of a degree.
- Active TS/SCI security clearance.
- Concentrated experience in the CND discipline, regardless of degree.
- Experience monitoring and investigating alerts from cybersecurity tools.
- Experience with Security Information and Event Management (SIEM) systems such as Splunk and Elastic.
- Experience with Network Intrusion Detection/Prevention Systems (NIDPS), such as Cisco FirePower and Palo Alto NGFW, as well as host-based tools such as Trellix ePO, Microsoft Defender, and Tanium.
- Knowledge of scripting and coding languages such as Python, Perl, Ruby, JavaScript, PowerShell, C, C++, and Java.
- Knowledge of penetration testing and red team tactics, techniques, and procedures, as well as tools such as Kali, SamuraiWTF, Nmap, Burp Suite, sqlmap, and Metasploit.
- Knowledge of ticketing systems, report writing, and intelligence gathering, analysis, and dissemination techniques specific to cybersecurity.
- Strong analytical, conceptual, and problem-solving skills.
Required Certifications
- Must possess one of the following certifications or obtain one within 30 days of accepting an offer: CompTIA CySA+, CompTIA PenTest+, CompTIA Cloud+, EC Council
CEH, GIAC GCIA, GIAC
GCIH, GICSP, or Cisco CyberOps.
NITESONIDABAOPP1If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo
- because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30
- and moving faster than anyone else dares.
Original Posting:
September 15, 2026For U.S.
Positions:
While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.
Pay Range:
Pay Range $87,100.00
- $157,450.
00The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.
Employers have access to artificial intelligence language tools ("AI") that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
Career Insights for Vulnerability Analyst / Penetration Tester
See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.
Scorecard
Based on Maryland data
Review key factors to help you decide if this role fits your goals. How is this calculated?
What they do
A Vulnerability Analyst or Penetration Tester probes for and exploits security vulnerabilities in web-based applications, networks and systems. Penetration Tests are designed to achieve a specific, attacker-simulated goal and should be requested by customers who are already at their desired security posture. A typical goal could be to access the contents of the prized customer database on the internal network, or to modify a record in an HR system. Vulnerability Assessments are designed to yield a prioritized list of vulnerabilities and are generally for clients who already understand they are not where they want to be in terms of security. The customer already knows they have issues and simply need help identifying and prioritizing them.
$121,766 / year median in Maryland
+3% projected growth