Cybersecurity Analyst!!
saxon globalFort Meade (MD)
About the role
Cybersecurity Analyst
Location: Fort Meade, MD Clearance: Active TS/
SCIPosition Summary:
Leidos provides network operations and cyber defense support to the Defense Information Systems Agency (DISA) in support of Department of War (DoW) and Combatant Commands (COCOMs). The Cyber Fusion Analyst will support incident response, threat detection, network analysis, cyber intelligence operations, vulnerability assessment, and enterprise cyber defense activities to identify, assess, and mitigate threats across the enterprise.
Key Responsibilities:
Analyze network traffic and security telemetry including Net Flow, custom application logs, intrusion detection system (IDS) alerts, and full packet capture (PCAP) data to identify malicious activity and emerging threats. Conduct cyber threat hunting and investigations using intelligence reporting, open-source intelligence (OSINT), threat feeds, and vulnerability data. Identify, investigate, and analyze indicators of compromise (IOCs), adversary tactics, techniques, and procedures (TTPs), and potential security incidents. Correlate data from SIEMs, sensors, system logs, and intelligence sources to detect adversary campaigns, anomalous behavior, and enterprise threats. Develop written analytical products, risk assessments, and recommendations to improve the organization's security posture and reduce attack surface exposure. Support the creation and refinement of Cyber Fusion Standard Operating Procedures (SOPs), methodologies, and operational frameworks. Assess threats and vulnerabilities impacting enterprise networks and recommend mitigation strategies and countermeasures. Produce attack lifecycle visualizations and technical briefings to communicate findings to stakeholders. Monitor cyber trends, collect operational metrics, and provide situational awareness reporting to leadership. Support continuous improvement efforts by leveraging industry best practices, government guidance, and evolving threat intelligence.
Required Qualifications:
Active TS/SCI clearance with eligibility for polygraph. Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related discipline; additional relevant experience may be considered in lieu of a degree. Security+ certification or equivalent DoD 8570 IAT Level II certification. Strong understanding of: Network protocols (TCP/IP, OSI Model)Cyber vulnerabilities and exploitation techniques Threat actor methodologies and attack frameworks Incident response and cyber defense operations Experience utilizing cyber analysis and threat intelligence tools such as: Splunk Arc Sight Wireshark Recorded Future Virus Total Passive DNSWHOISThreat intelligence platforms Experience analyzing network data including Net Flow, PCAPs, IDS/IPS alerts, and custom application logs. Experience leveraging commercial and open-source intelligence resources to identify, assess, and mitigate cyber threats.
Preferred Qualifications:
Experience supporting DISN or other DoD enterprise networks. Experience building cybersecurity dashboards, metrics, analytics, and trend reporting. Knowledge of intelligence-driven defense methodologies, MITRE ATT&CK, and Cyber Kill Chain concepts. Experience briefing senior government leadership, including SES and GO/FO personnel. IAT Level III and/or IAM Level II/III certifications (CASP+, CISSP, GSLC, etc.).
Before you apply
Applying takes about a minute. These four things decide how fast it moves after that.
Your profile is current
It's what we read first. Occupations, seniority and locations matter more than a long history.
Two examples you can talk through
Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.
A number in mind
What you're on now and what would make you move. We negotiate better when we know both.
Your notice period
Employers plan around it, and it's the question that stalls offers most often.
Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.
More like this
