Cyber/Indications and Warnings Analyst

Job Number:
Job Category:
Cyber Security
Yes, 10% of the time
Day Job
Potential for Teleworking:
Clearance Level Must Currently Possess:
Top Secret/SCI with Polygraph
Clearance Level Must Be Able to Obtain:
Top Secret/SCI with Polygraph

Job Description:


The Advanced Solutions Group (ASG) at Leidos currently has an opening for a Cyber/Indications and Warnings Analyst to work at our San Antonio, Texas location. This is an exciting opportunity to use your experience supporting an important, fast-paced, mission critical program.


Job Summary:

This individual is responsible for performing Security Incident and Event Handling for a critical DoD operational system. The successful candidate will demonstrate strong skills in Incident Response and Handling, Forensic Analysis, and the ability to quickly relay critical information to team members and management clearly, completely, and concisely.


Primary Roles and Responsibilities:

As the Attack, Sensing, Warning, and Response (ASWR) analyst, the successful candidate will analyze collected data and derive facts, inferences, and projections to determine if the systems being monitored are operating normally or being attacked by an adversary. This individual will also analyze this collected data to detect an Insider Threat. The successful candidate will develop new dashboards and analytics to refine existing reports and create new reports. He/she will also work with System Engineers and System Administrators to better define the audit data being collected to eliminate false positives and false negatives from the data.

External Referral Eligible


Basic Qualifications:

To be considered for this position, you must minimally meet the knowledge, skills, and abilities listed below:

• A Bachelor’s Degree in Information Assurance or related field plus 8 years of related experience.  Additional years of experience can be considered in lieu of degree.
• At least 2 years of experience with an Indications and Warnings monitoring tool
• Experience with one or more of the following: StealthWatch, TripWire, Zenoss, and ArcSight
• Experience tuning audit data to reduce number of false positives and false negatives
• Experience in responding to detected security incidents
• Must possess excellent troubleshooting skills
• Must have a solid understanding of network intrusion detection methods and techniques
• Must be able to work 0600-1400 or 1400-2200 shifts.

Preferred Qualifications:

Candidates with these desired skills will be given preferential consideration:

• Network Security Operations Center (SOC) experience preferred
• Experience creating Dashboards and Analytics within SEIM (Security Information and Event Management) Tool
• Experience creating workflows for Incident Response within a SEIM (Security Information and Event Management) Tool
• CISSP Certification
• GIAC Certified Incident Handler Certification
• GIAC Cyber Threat Intelligence Certification

Leidos Overview:
Leidos is a global science and technology solutions leader working to solve the world’s toughest challenges in the defense, intelligence, homeland security, civil, and health markets. The company’s 33,000 employees support vital missions for government and commercial customers. Headquartered in Reston, Virginia, Leidos reported pro forma annual revenues of approximately $10 billion for the fiscal year ended January 1, 2016 after giving effect to the recently completed combination of Leidos with Lockheed Martin's Information Systems & Global Solutions business (IS&GS). For more information, visit www.Leidos.com. The company’s diverse employees support vital missions for government and commercial customers. Qualified women, minorities, individuals with disabilities and protected veterans are encouraged to apply. Leidos will consider qualified applicants with criminal histories for employment in accordance with relevant Laws. Leidos is an Equal Opportunity Employer.
Other Locations:  
Link for schema