386,234open jobs
10,126companies
50,599added this week
Browse all
Salary
$108k – $195k per year
Location
In office (Alexandria)
Seniority
Staff · 8+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Leidos is an American technology and engineering services company created in 2013 when Science Applications International Corporation split in two, with Leidos taking the technical services and solutions business. It is one of the largest suppliers to the United States government, working across defence programmes, intelligence systems, civil agencies including the Federal Aviation Administration, and healthcare services for the Department of Veterans Affairs. Headquartered in Reston, Virginia, the company also builds security detection products for airports and borders, and has concentrated recent investment on trusted artificial intelligence and autonomy for mission environments.

Leidos has a current job opportunity for a Cyber Intelligence Fusion Analyst on the DISA GSM-O II TN24 Penetration Handling, Incident, System Health (PHISH) Support Services II program. This position supports the J361 Security Operations Center (SOC) Fusion mission at the Mark Center, Alexandria, Virginia. The team operates 100% onsite at the Mark Center during normal business hours, Monday through Friday.

Position Summary

The Cyber Intelligence Fusion Analyst serves as the proactive analysis and threat-hunting engine for the J361 SOC. The analyst synthesizes all-source threat reporting to conduct structured threat hunts, perform proactive environment sweeps, and deliver tailored analytical reports and briefings to senior leadership.

The position combines cyber operations, threat intelligence, and analytic tradecraft to identify, characterize, and mitigate threats affecting tenants and subscribers throughout the National Capital Region. Responsibilities include correlating external intelligence with enterprise telemetry, mapping adversary TTPs, recommending detections and countermeasures, and providing threat context during incident investigations across classified, unclassified, and cloud environments.

Primary Responsibilities

  • Ingest, analyze, and synthesize cyber threat reporting from OSINT, government reporting, commercial threat-intelligence platforms, and other authorized sources to identify threats relevant to the environment.
  • Correlate external threat intelligence with enterprise SIEM, EDR, endpoint, network, packet capture (PCAP), NetFlow, proxy, firewall, IDS/IPS, SSL decryption, session, and system-log telemetry to identify and assess malicious activity.
  • Conduct proactive IOC sweeps and hypothesis-driven threat hunts to identify activity associated with emerging adversary campaigns, vulnerabilities, malware, targeted threats, and stealthy or evasive adversary behavior.
  • Characterize adversary infrastructure, malware, tooling, and TTPs using MITRE ATT&CK, Cyber Kill Chain, and other applicable threat-modeling frameworks; assess potential risk to enterprise assets, tenants, and mission operations.
  • Develop hunt plans, adversary profiles, analytic methodologies, detection logic, and complex query strategies; plan, coordinate, and execute ad hoc threat hunts; document findings and recommendations in AARs; and other required mission products.
  • Develop, validate, and recommend countermeasures, including SIEM correlation searches, analytic content, custom signatures, and blocking recommendations, to improve prevention, detection, and response to known adversarial TTPs; technically vet suspicious indicators before submitting detection or blocking nominations.
  • Produce recurring and ad hoc threat reports, intelligence assessments, executive summaries, situational-awareness updates, time-sensitive threat notifications, and strategic threat assessments.
  • Translate technical telemetry, forensics, intelligence reporting, and analytic findings into clear, actionable technical, operational, and executive-level summaries; prepare and deliver recurring and on-demand briefings to leadership, tenant organizations, and mission partners.
  • Serve as a subject matter expert on adversary tradecraft and provide threat context, intelligence support, and analytic recommendations to incident responders and other SOC teams during active investigations.
  • Develop and maintain SOPs, work instructions, hunt methodologies, analytic playbooks, detection use cases, and knowledge-management artifacts; identify capability and workflow gaps, recommend improvements, and enhance automation for enrichment, case management, reporting, dashboards, and metrics.
  • Provide technical leadership on complex hunts and investigations; mentor junior analysts and contribute to team training and professional development.

Basic Qualifications

  • Active Top Secret security clearance with ability to obtain SCI
  • Bachelor’s degree in cybersecurity, information technology, computer science, intelligence studies, or a related technical discipline and 8+ years of relevant experience; additional relevant experience, cybersecurity education, or industry certifications may be substituted for a degree.
  • 4+ years of experience supporting cybersecurity operations, cyber threat intelligence, threat hunting, incident response, cyber network defense, or a closely related cyber mission.
  • Must meet DoD 8140 IAT Level II baseline certification requirements before starting work and possess, or obtain and maintain within the required program timeframe, a DoD 8140 CSSP Analyst (CSSP-A) certification.
  • Demonstrated experience applying MITRE ATT&CK, Cyber Kill Chain, or comparable frameworks to characterize adversary activity, TTPs, attack lifecycles, vulnerabilities, malware behaviors, and indicators.
  • Hands-on experience conducting hypothesis-driven threat hunts, developing detection logic and analytic queries, and pivoting from external threat reporting, IOCs, and OSINT to internal enterprise telemetry.
  • Demonstrated experience querying, analyzing, and correlating high-volume SIEM, EDR, endpoint, network, NetFlow, packet, log, and other host- or network-based security data; working knowledge of TCP/IP, common ports and protocols, network traffic flow, OSI model, system administration, defense-in-depth, and enterprise security architecture.
  • Strong written, verbal, analytical, and collaboration skills, including the ability to produce technical and executive-level reports and briefings; ability to work independently, manage competing priorities, and work effectively with technical and non-technical mission partners.
  • Ability to work 100% onsite at the Mark Center during normal business hours; schedule flexibility may be required to support mission requirements.

Preferred Qualifications

  • TS/SCI eligibility, including eligibility for reciprocal acceptance, preferred.
  • Advanced cybersecurity certifications, such as CISSP, CASP+, CySA+, CEH, GIAC GCIH, GCIA, GCED, GCTI, or comparable credentials.
  • Experience supporting DISA, Department of Defense networks, Cyber Security Service Provider operations, Cyber Protection Teams, or a large enterprise SOC.
  • Experience conducting threat hunting and cyber investigations across NIPRNet, SIPRNet, JWICS, cloud, commercial, or similarly complex enterprise environments.
  • Experience using SIEM, EDR, threat-intelligence, and network-analysis tools-such as Splunk, Elastic, Microsoft Defender for Endpoint, Microsoft Sentinel, Google Threat Intelligence, VirusTotal, Wireshark, PCAP, and NetFlow-to develop or tune correlation searches, detection rules, signatures, threat blocks, analytic queries, dashboards, and automated enrichment workflows.
  • Familiarity with commercial threat-intelligence platforms; malware analysis; digital and network forensics; endpoint telemetry; intrusion detection; vulnerability research; cloud security; and intelligence-driven defense methodologies, including MITRE ATT&CK and Cyber Kill Chain.
  • Familiarity with query languages and scripting tools, such as SPL, KQL, Lucene, SQL, Python, PowerShell, and Unix/Linux command-line utilities.
  • Experience producing intelligence products, operational reports, and executive briefings for senior executives, General Officer/Flag Officer, Senior Executive Service, or equivalent leadership; demonstrated ability to lead complex cyber investigations or threat hunts and mentor junior technical staff.

If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo - because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 - and moving faster than anyone else dares.

Original Posting:

September 3, 2026

For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

Pay Range:

Pay Range $107,900.00 - $195,050.00

The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
386,234 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Alexandria
$73k – $150k per year (Estimated) • Remote/Hybrid • Full-Time • London • Manchester
Cybersecurity
CVE
CVSS
Cyber Kill Chain
MITRE ATT&CK
Apply
$87k – $198k per year • In office • Full-Time • 5+ years exp • Bachelor's Degree • San Diego
DevOps
Azure
Azure DevOps
CI/CD
Terraform
Cybersecurity
FedRAMP
Fortify
Microsoft Defender
Microsoft Defender for Cloud
Microsoft Entra ID
Microsoft Sentinel
MITRE ATT&CK
Sonatype Nexus IQ
Management
ServiceNow
Apply
$19k – $50k per year (Estimated) • Remote • Full-Time • 4+ years exp • Bachelor's Degree • India
Bash
PowerShell
Python
DevOps
AWS
Azure
GCP
Cybersecurity
MITRE ATT&CK
Wireshark
Marketing
LinkedIn
Apply
$98k – $164k per year • In office • Full-Time • 3+ years exp • Bachelor's Degree • United States
C++
Python
Cybersecurity
MITRE ATT&CK
SBOM
STRIDE
Threat Modeling
Zero Trust
Robotics
CANopen
IoT
FreeRTOS
MQTT
OPC UA
Apply
$158k – $312k per year (Estimated) • Remote • 15+ years exp • Master's Degree
Cybersecurity
Defense in Depth
FedRAMP
HIPAA
Least Privilege
Threat Modeling
Zero Trust
Apply
$58k – $105k per year • In office • Full-Time • Bachelor's Degree • Saint Louis
JavaScript
Python
TypeScript
AI/ML
Computer Vision
OCR
OpenCV
Frontend
OpenLayers
React.js
DevOps
AWS
AWS CDK
CI/CD
CloudFormation
Docker
GitLab
Game Dev
Godot
Management
Confluence
Jira
Apply
$87k – $157k per year • In office • Full-Time • 4+ years exp • Master's Degree • San Diego • Huntsville
Cybersecurity
Threat Modeling
Apply
$70k – $126k per year • In office • Full-Time • 2+ years exp • Bachelor's Degree • Huntsville
C++
Python
SQL
TypeScript
JavaScript
C
Python
Flask
C
ZeroMQ
AI/ML
Claude
Claude Code
CUDA
CUDA Toolkit
Frontend
Angular
OpenLayers
Sass
DevOps
CI/CD
SpaceTech
NASA WorldWind
Apply
Software Engineer 1 hour ago
$87k – $157k per year • In office • Full-Time • 4+ years exp • Bachelor's Degree • Huntsville
C++
Python
SQL
TypeScript
JavaScript
C
Python
Flask
C
ZeroMQ
AI/ML
Claude
Claude Code
CUDA
CUDA Toolkit
Frontend
Angular
OpenLayers
Sass
DevOps
CI/CD
SpaceTech
NASA WorldWind
Apply
$87k – $157k per year • In office • Full-Time • 4+ years exp • Bachelor's Degree • Lynnwood
MATLAB
Python
Apply
$55k – $126k per year • In office • Full-Time • Bachelor's Degree • Alexandria
Apply
$220k per year • In office • Full-Time • 5+ years exp • Bachelor's Degree • Alexandria
C++
Java
Python
SQL
C++
PyTorch C++
TensorFlow C++
AI/ML
AI Agents
Anomaly Detection
Edge AI
Embeddings
Function Calling
Human-in-the-Loop
Knowledge Graph
LLM
NLP
PyTorch
RAG
Scikit-learn
Semantic Search
Semantic Search
Spark
Structured Outputs
TensorFlow
Time Series Forecasting
DevOps
AWS
Azure
CI/CD
Docker
Kubernetes
Apply
$92k – $167k per year • In office • Full-Time • 8+ years exp • Bachelor's Degree • Alexandria
Python
SQL
Analytics
ETL/ELT
Power BI
Tableau
Apply
In office • Internship • PhD • Alexandria
C#
C++
C#
.NET
AI/ML
Text-to-Speech
DevOps
CI/CD
Vercel
Management
Google Docs
Stripe
Marketing
LinkedIn
Apply
Data Scientist 2 days ago
$78k – $176k per year • In office • Full-Time • 5+ years exp • Bachelor's Degree • Alexandria
Python
SQL
Databases
Databricks
AI/ML
NLP
DevOps
GitLab
Analytics
Tableau
Apply
See all jobs
This is one of many
386,234 more open roles from verified company boards, updated every day.