Leidos Holdings Inc logo

Cyber Intel Analyst

Leidos Holdings Inc
  • Washington, DC
  • $87,100–$157,450 Per Year
4 days ago
Leidos Holdings Inc

Job Description

Leidos' Digital Sector is seeking Cyber Analysts with backgrounds in Threat Hunting, Threat Intel, and/or Cyber Fusion to join our Defensive Cyber Operations team in Washington, DC in early 2027. These positions will support our DCO team with protecting federal networked systems and services from threats to national security.

These are hybrid roles that are primarily on-site, with up to 20% telework potential. Core hours are 0600-1600, supporting a team of analysts on 24/7 rotating shifts (days, swings, nights); occasional shift or weekend work may be required to cover gaps.

PLEASE NOTE these positions are expected to become available in Winter/Spring 2027. Recruiters will contact qualified applicants as timeline firms up.

Primary Responsibilities

Threat Hunting

  • Develop and execute hypothesis-driven hunt campaigns based on adversary TTPs
  • Query and correlate telemetry across cloud, identity, and network infrastructure to surface "low and slow" attacks
  • Partner with detection engineering to convert hunt findings into automated SIEM/EDR detection rules
  • Build automation for countermeasure deployment and asset isolation
  • Use MITRE ATT&CK to proactively search for APT activity

Threat Intelligence

  • Produce strategic, operational, and tactical intelligence reports on emerging threats and actor motivations
  • Characterize adversary TTPs and build APT profiles using MITRE ATT&CK
  • Manage the intelligence lifecycle: PIRs, collection plans, and dissemination
  • Evaluate and manage IOC/IOB fidelity within a Threat Intelligence Platform (TIP)
  • Deliver Indications & Warnings (I&W) to support hunt and DCO operations

Cyber Fusion

  • Synthesize external threat intelligence with internal hunt telemetry into a unified operational picture
  • Author Fusion Reports blending forensics and strategic intelligence for leadership
  • Correlate global threat activity against internal sensor logs via SIEM/TIP
  • Pair vulnerability data with active threat reporting to prioritize remediation
  • Maintain the team's "single source of truth" for prioritized threat data

Shared across all tracks

  • Maintain situational awareness of the evolving threat landscape and its relevance to the customer enterprise
  • Author clear technical reporting and metrics on findings, gaps, and posture improvements
  • Collaborate across Hunt, Intel, Engineering, and Fusion functions to ensure intelligence drives defensive action

Basic Qualifications

  • Current DoD TS/SCI clearance, and ability to pass additional customer suitability screening prior to start and maintain throughout employment

  • Education and experience depending on job level:

  • Level III: Bachelor's degree in a related discipline and 4+ years of relevant work experience OR Master's degree in a related discipline and 2+ years of relevant work experience. Additional experience may be considered in lieu of degree.

  • Level IV: Bachelor's degree in a related discipline and 8+ years of relevant work experience OR Master's degree in a related discipline and 6+ years of relevant work experience. Additional experience may be considered in lieu of degree.

  • DoD 8570 IAT Level II or higher required to start - e.g., Security+, CySA+, GSEC, SSCP, CASP+ CE, CCNP Security, CISA, GCED, GCIH, or CISSP

  • DoD 8570 CSSP Analyst certification required within 180 days of onboarding - e.g., CySA+, Cloud+, GCIA, CEH

  • DoD 8570 CSSP Infrastructure Support certification required within 180 days of onboarding - e.g., CySA+, Cloud+, CEH, CND, CHFI, GICSP, SSCP

  • Strong knowledge of networking protocols (TCP/IP, DNS, HTTP/S) and security controls (IDS/IPS, next-gen firewalls)

Preferred Skills

  • Query languages: SPL (Splunk), KQL (Kusto), or Elastic DSL for large-scale data analysis
  • Scripting: Python, PowerShell, or Bash for automation and data enrichment
  • Cloud familiarity: AWS, Azure, O365, containerized workloads
  • Framework fluency: MITRE ATT&CK, Cyber Kill Chain, Diamond Model of Intrusion Analysis
  • DFIR experience (packet capture / endpoint log analysis, root-cause reconstruction)
  • Experience with Threat Intelligence Platforms (Anomali, ThreatConnect, MISP) or OSINT/commercial threat portals (Recorded Future, VirusTotal, Mandiant Advantage)
  • Prior work in a Cyber Fusion Center (CFC) or Joint Operations Center (JOC)
  • AI-driven analytics experience for anomaly/behavioral detection
  • Strong analytical writing - translating technical findings into executive-level briefings

#nebo

If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo - because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 - and moving faster than anyone else dares.

Original Posting:

September 15, 2026

For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

Pay Range:

Pay Range $87,100.00 - $157,450.00

The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

Numbers & Facts

LocationWashington, DC
IndustryComputer/IT Services
Salary$87,100–$157,450 Per Year
Company Size10,000 employees or more
Year Founded2013
Websitehttps://jobs.saic.com/

About Company

SAIC is a premier Fortune 500® technology integrator driving our nation's digital transformation. Our robust portfolio of offerings across the defense, space, civilian, and intelligence markets includes secure high-end solutions in engineering, IT modernization, and mission solutions. Using our expertise and understanding of existing and emerging technologies, we integrate the best components from our own portfolio and our partner ecosystem to deliver innovative, effective, and efficient solutions that are critical to achieving our customers' missions. We are a team of 26,000 strong driven by mission, united purpose, and inspired by opportunity. Headquartered in Reston, Virginia, SAIC has annual revenues of approximately $7.1 billion. For more information, visit saic.com.

Skills

  • Amazon Web Services (AWS)unmatched
  • Analysis Skillsunmatched
  • Artificial Intelligence (AI)unmatched
  • Automationunmatched
  • Bash Scriptingunmatched
  • CCNP - Cisco Certified Network Professionalunmatched
  • CISA - Certified Information Systems Auditorunmatched
  • CISSP - Certified Information Systems Security Professionalunmatched
  • Campaignsunmatched
  • Cloud Computingunmatched
  • CompTIA Security+unmatched
  • Computer Network Defense (CND)unmatched
  • Computer Securityunmatched
  • DNS (Domain Name System)unmatched
  • DSL (Digital Subscriber Line)unmatched
  • Data Analysisunmatched
  • Database Programming Languagesunmatched
  • DoD Directive 8140unmatched
  • DoD Directive 8570unmatched
  • Establish Prioritiesunmatched
  • Firewallsunmatched
  • Forensic Scienceunmatched
  • GCIH - GIAC Certified Incident Handlerunmatched
  • GSEC - GIAC Security Essentials Certificationunmatched
  • HTTP (HyperText Transport Protocol)unmatched
  • Huntingunmatched
  • IAT - Information Assurance Technicalunmatched
  • Intel Product Familyunmatched
  • Internet Securityunmatched
  • Intrusion Detection Systemsunmatched
  • Intrusion Prevention Systemsunmatched
  • Inversion of Control (IoC)unmatched
  • Leadershipunmatched
  • Legalunmatched
  • Metricsunmatched
  • Microsoft Windows Azureunmatched
  • Network Administration/Managementunmatched
  • Network Protocolsunmatched
  • Network Systemsunmatched
  • OSINT (Open Source Intelligence)unmatched
  • Onboardingunmatched
  • Operational Strategyunmatched
  • Python Programming/Scripting Languageunmatched
  • Reporting Skillsunmatched
  • Root Cause Analysisunmatched
  • SSCP - Systems Security Certified Practitionerunmatched
  • Scripting (Scripting Languages)unmatched
  • Security Attacksunmatched
  • Security Information and Event Management (SIEM)unmatched
  • Sensitive Compartmented Information (SCI)unmatched
  • Splunkunmatched
  • TCP/IP (Transmission Control Protocol/Internet Protocol)unmatched
  • Tactical Operationsunmatched
  • Team Buildingunmatched
  • Technical Writingunmatched
  • Telemetryunmatched
  • Top Secret Clearanceunmatched
  • United States Department of Defense (DoD)unmatched
  • Windows PowerShellunmatched
  • Writing Skillsunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder