C2 Network Security Operations Center – Cyber Threat Hunter
LeidosAbout the role
The Multi-Domain Solutions Division at Leidos currently has openings for a Cyber Security Engineer / Information Systems Security Engineer (ISSE). Our team supports the Advanced Battle Management System’s (ABMS) Digital Infrastructure (DI) Network Manager program. In this mission we support the Department of the Air Force (DAF) to field and operate the ABMS Digital Infrastructure, which is foundational in creating a unified command-and-control infrastructure connecting/ integrating sensors, data streams, and weapon systems across all domains (air, land, sea, cyber, and space). This will ultimately allow U.S. forces from all services — as well as allies and partners — to sense, make sense and act upon a vast array of data and information faster than adversaries can detect and respond to. The Cyber Threat Hunter will work to proactively identify and investigate suspicious activity, analyze threat intelligence to stay ahead of emerging attacker tactics, and translate findings into actionable security improvements protecting our client’s assets. This role requires a deep understanding of advanced threat detection techniques, strong analytical skills, and the ability to work collaboratively with other security professionals. Specific duties include, but are not limited to, the following:
Responsibilities include:
Conduct proactive threat hunting activities to identify suspicious activity and potential cyber threats, preventing escalation.
Apply independent critical thinking to analyze threat intelligence data, emerging attack techniques, tactics, and procedures (TTPs) to determine the best response and remediation actions.
Conduct analysis of log data from various internal data sources (e.g., firewalls, hosts, EDR, IDS/IPS) to identify suspicious activity and assess potential threats impacting the organization.
Respond to the customers’ RFIs and conduct investigations within defined time and scope parameters, using all available tools and techniques to uncover new information.
Working knowledge of Information Security controls including system-level controls, network controls, and security operations, across Endpoint, Cloud, SaaS, and Identity.
Experience with Endpoint Detection and Response (EDR) capabilities.
Background in investigating and analyzing alerts and threats for anomalous, suspicious, or malicious activity.
Develop countermeasures such as custom SIEM and IDS rules/signatures and strengthen the organization’s ability to prevent and detect attacks against assets and data.
Perform Incident Handling Tasks (e.g., triage, response activities, documentation, reporting, lessons learn, etc.).
Educate and empower customers by providing context on various threats and advising on best practices.
Analyze ongoing attacks, such as phishing, DDoS, data leakage, and ransomware, to assess their origin, purpose, and impact on our customers.
Track and engage with threat actors across the clear, deep, and dark web to gather unique insights and intelligence.
Serve as a leading source of knowledge in threat intelligence, providing support to the customer with your diverse skills and expertise.
Develop and deploy security monitoring content, including dashboards and alerts within the organizations SIEM and other security tools to detect threats, suspicious activities, aiding in incident investigation efforts.
Regularly review, evaluate, and optimize custom and default detection content to ensure it supports internal and SOC operations effectively.
Create and maintain technical documents including, but not limited to content creation, content/rule review process, queries for disparate log sources, network/security visibility issues, detection gaps, and monitoring strategies.
Identify areas for improvement in security monitoring and propose enhancements to strengthen the organization’s detection and response capabilities.
Mentor and guide fellow security team members, assisting with project execution and promoting skill development in tactical security practices.
Directly interface and mentor the SOC.
Developing strategies to handle security incidents and coordinating responses to security breaches.
Required Qualifications and Skills:
Must have a DoD TS/SCI Clearance.
Must have a current security certification in accordance with DoD 8140 and be able to get an appropriate computing environment certification within 6 months.
Bachelor’s degree with 6 years of prior experience in the Cybersecurity technical/professional discipline. Additional years of experience and/or certifications may be considered in lieu of a degree/prior wor
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s