Leidos Logo

Leidos

Cyber Operations Lead

Posted 24 Days Ago
Be an Early Applicant
Colorado Springs, CO
105K-189K Annually
Senior level
Colorado Springs, CO
105K-189K Annually
Senior level
Leidos seeks a Cyber Operations Lead to drive improvements in cyber defense tools, manage a team, and provide Tier II analysis for C5ISR Center DCO.
The summary above was generated by AI

Leidos is seeking a Cyber Operations Lead in Colorado Springs, CO. This position provides Tier II Cyber Security Analysis to C5ISR Center Defensive Cyber Solutions Branch (DCSB) Defensive Cyber Operations (DCO). Beyond advising and guiding technical matters, this position is tasked with driving implementation and adoption of new tools, research, capabilities, frameworks, and methodologies while ensuring those already in use are implemented, utilized properly, and improved.

Primary Responsibilities:

  • Identify and offer solutions to gaps in capabilities and visibility
  • Promote and drive research and implementation of automation and process efficiencies
  • Intermediate command line experience that includes chaining Linux utilities such as tcpdump, sed, awk, and grep together
  • Intermediate IDS (Snort, Bro/Zeek, etc.) creation and tuning, to include performing impact analysis on customer environments and review and correction of Tier I rules 
  • Analysis of alert traffic plus surrounding traffic to provide context to inform analysis
  • Ability to consume open and closed source and search indicators in customer data, then generate new IDS configurations for future detection
  • Basic hunt experience that includes sifting non-alert-based traffic and deriving meaningful results in the absence of corresponding OSINT
  • Basic vulnerability awareness and able to determine applicability to customer environments, using data to establish attack attempts and success/failure
  • Maintaining current threat awareness
  • Ability to analyze complex (multipacket, multi-vector, multi-exploit, large volume) traffic and derive meaningful conclusions
  • Self-directed research, development, customization, or other contributions to process improvement
  • Continual enrichment of IDS and moderate ability to tune on the fly
  • Ability to self-educate with non-comprehensive or incomplete documentation on new concepts, protocols, and data formats
  • Work a 2-2-3 non-standard schedule and 12-hour shifts; For example, week 1: Monday, Tuesday, Friday, Saturday, and Sunday; week 2: Wednesday and Thursday.
  • Serve as the operational point of contact for the assigned shift, ensuring seamless execution of activities.
  • Provide leadership, mentorship, and management of up to six personnel, including real-time training and performance coaching, with the flexibility to adjust your schedule as needed to support team development and operational effectiveness.
  • Delegate tasks and ensure analysts remain actively engaged throughout the shift, optimizing efficiency.
  • Review and ensure quality control of team reports and communications before release.
  • Monitor and enforce adherence to operational procedures, continuously updating and administering the Joint Qualification Requirements (JQR).
  • Identify and escalate significant threats, operational issues, or performance concerns to the Team Lead in a timely manner.
  • Foster a high-performance culture by setting expectations, providing feedback, and recognizing team contributions.
  • Ensure effective knowledge transfer and training of new analysts to maintain team readiness.
  • Drive continual process improvement and enhance detection capabilities through collaboration and proactive adjustments.

Basic Qualifications:

  • Requires BS and 8+ years of prior relevant experience or Masters with 6+ years of prior relevant experience, additional years of experience will be accepted in lieu of a degree. 
  • Hands-on cybersecurity network defense experience (Detect and Respond) within a Computer Incident Response organization.
  • 3+ years of hands-on experience with the Army C5ISR/DCSB Security Information and Event Management tool ‘Interrogator’
  • Fluent in computer network Packet Capture (PCAP) analysis
  • DoD 8570 IAT-II and CSSP-Analyst certifications required prior to starting
  • Advanced knowledge of solution development techniques and best practices related to demonstration, pilot, and test management and operations.
  • Demonstrated advanced knowledge of industry accepted standards.
  • Demonstrated experience with researching and fielding new and innovative technology.
  • Motivated self-starter with strong written and verbal communication skills, and the ability to create complex technical reports on analytic finding.
  • Strong analytical and troubleshooting skills.
  • 5+ years’ experience working in a SOC environment
  • Candidate must possess an active TS/SCI and be approved customer SAP read-ons
  • Must be a US Citizen

Preferred Qualifications:

  • Deep technical understanding of core current cybersecurity technologies as well as emerging capabilities.
  • Demonstrated understanding of the life cycle of cybersecurity threats, attacks, attack vectors and methods of exploitation with an understanding of intrusion set tactics, techniques and procedures (TTPs).
  • Motivated self-starter with strong written and verbal communication skills, and the ability to create complex technical reports on analytic findings.
  • Familiarity or experience in Intelligence Driven Defense, Cyber Kill Chain methodology, and/or MITRE ATT&CK framework.

Original Posting Date:2025-02-10

While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

Pay Range:Pay Range $104,650.00 - $189,175.00

The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

Top Skills

Awk
Bro/Zeek
Grep
Ids
Linux Utilities
Open Source Intelligence
Security Information And Event Management
Sed
Snort
Tcpdump

Similar Jobs

Yesterday
Hybrid
Denver, CO, USA
140K-200K
Senior level
140K-200K
Senior level
Security • Software • Cybersecurity
The Senior Application Security Engineer will ensure application security by developing secure code, conducting threat modeling, and engaging in security audits and customer support.
Top Skills: Application SecurityCloud InfrastructureHTTPMulti-Threaded ApplicationsRestSecure Coding PracticesTcp/IpVulnerability Testing
Yesterday
Hybrid
5 Locations
135K-190K Annually
Senior level
135K-190K Annually
Senior level
Cloud • Information Technology • Security • Software • Cybersecurity
Consult with enterprise clients on Zero Trust Services/SASE, managing projects, creating service offerings, and leading marketing efforts for the Professional Services team.
Top Skills: APIsCdnsDdos ProtectionLoad BalancingNetworkingSaseSecurityWafZero Trust Services
Yesterday
Hybrid
6 Locations
159K-224K Annually
Senior level
159K-224K Annually
Senior level
Cloud • Information Technology • Security • Software • Cybersecurity
As a Professional Services Consultant for Zero Trust, you will implement security solutions for enterprise customers, ensuring they maximize their investment in Cloudflare technologies through planning, execution, and troubleshooting.
Top Skills: AdfsBot ManagementCasbCloudflareData Loss PreventionDlpDnsEmail SecurityFirewallsHTTPLdapMplsSAMLSaseSd-WanSsoSwgTcp/IpTlsVpnsWafsZtna

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account