368,634open jobs
9,437companies
50,578added this week
Browse all
Salary
$108k – $195k per year
Location
In office (Washington, Ashburn)
Seniority
Staff · 8+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Leidos is a defense, intelligence, civil, and health information technology enterprise. Headquartered in Reston, Virginia, the Fortune 500 company (NYSE: LDOS) operates as one of the primary IT, scientific research, and systems integration contractors for the U.S. federal government, allied defense agencies, and commercial infrastructure entities.

At Leidos, we deliver innovative solutions through the efforts of our diverse and talented people who are dedicated to our customers’ success. We empower our teams, contribute to our communities, and operate sustainable. Everything we do is built on a commitment to do the right thing for our customers, our people, and our community. Our Mission, Vision, and Values guide the way we do business.

If this sounds like the kind of environment where you can thrive, keep reading!

The Digital Modernization Sector brings together our digital transformation and IT programs, allowing us to better serve our customers through scale and repeatability.

Leidos is seeking an Incident Response Lead to join our team on a highly visible cyber security single-award IDIQ vehicle that provides security operations center (SOC) support, cyber analysis, application development, and a 24x7x365 support staff.

Department of Homeland Security (DHS), Security Operations Center (SOC) Support Services is a US Government program responsible to monitor, detect, analyze, mitigate, and respond to cyber threats and adversarial activity on the DHS Enterprise. The DHS SOC has primary responsibility for monitoring and responding to security events and incidents detected at the Trusted Internet Connection (TIC) and Policy Enforcement Point (PEP) and is responsible for directing and coordinating detection and response activities performed by each Component SOC. Direction and coordination are achieved through a shared DHS incident tracking system and other means of coordination and communication.

Primary Responsibilities

  • In-depth knowledge of each phase of the Incident Response life cycle

  • Expertise in Operating Systems (Windows/Linux) operations and artifacts

  • Understanding of Enterprise Network Architectures to include routing/switching, common protocols (DHCP, DNS, HTTP, etc), and devices (Firewalls, Proxies, Load Balancers, VPN, etc)

  • Ability to recognize suspicious activity/events, common attacker TTPs, perform logical analysis and research to determine root cause and scope of Incidents

  • Drive implementation and improvement of new tools, capabilities, frameworks, and methodologies

  • Instill and reinforce industry best practices in the domains of incident response, cybersecurity analysis, case and knowledge management, and SOC operations

  • Promote and drive implementation of automation and process efficiencies

  • Familiarity with Cyber Kill Chain and ATT&CK Framework and how to leverage in Security Operations

  • Provide guidance and mentorship to improve analyst skill sets and ensure delivery of high quality analysis and work products

  • Establish trust and business relationships with customer and other relevant stakeholders

Bachelor's Degree and 8-12 years of experience in a technical discipline.

  • 4+ years of supervising and/or managing teams

  • 5+ years of intrusion detection and/or incident handling experience

  • CISSP and SANS GCIH or GCIA required upon start

  • Advanced knowledge in planning, directing, and managing Computer Incident Response Team (CIRT) and/or Security Operations Center (SOC) operations for a large and complex Enterprise

  • Significant experience supervising and leading employees of various labor categories and technical skill levels in efforts similar in size and scope to a mature Security Operation

  • Mature understanding of industry accepted standards for incident response actions and best practices related to SOC operations;

  • Strong written and verbal communication skills, and the ability to create technical reports based on analytical findings.

  • Strong analytical and troubleshooting skills.

  • Must be a US Citizen.

  • Must hold active TS/SCI security clearance to be considered

Preferred Qualifications

  • Deep technical understanding of core current cybersecurity technologies as well as emerging capabilities.

  • Hands-on cybersecurity experience (Protect, Detect, Respond and Sustain) within a Computer Incident Response organization including prior experience performing large-scale incident response.

  • Demonstrated understanding of the life cycle of cybersecurity threats, attacks, attack vectors and methods of exploitation with an understanding of intrusion set tactics, techniques and procedures (TTPs).

If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo - because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 - and moving faster than anyone else dares.

Original Posting:

August 25, 2026

For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

Pay Range:

Pay Range $107,900.00 - $195,050.00

The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,634 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Washington
SOC Lead 4 days ago
$131k – $237k per year • In office • Full-Time • 10+ years exp • Bachelor's Degree • Alexandria
Cybersecurity
Cyber Kill Chain
MITRE ATT&CK
Apply
$19k – $46k per year (Estimated) • Remote • Bachelor's Degree • Moscow
Bash
PowerShell
Python
DevOps
Docker
Kubernetes
VMWare
Cybersecurity
MITRE ATT&CK
Apply
$150k – $200k per year • Remote • Full-Time • 11+ years exp
YARA
Databases
Apache Kafka
ElasticSearch
OpenSearch
AI/ML
AI Agents
Embeddings
RAG
Semantic Search
GraphRAG
Knowledge Graph
Semantic Search
DevOps
Kubernetes
Vector
Cybersecurity
MITRE ATT&CK
STIX
TAXII
YARA
Apply
$23k – $53k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • Hyderabad
PowerShell
Python
DevOps
AWS
Azure
GCP
Splunk
Cybersecurity
Cortex XSOAR
Crowdstrike
MITRE ATT&CK
MITRE D3FEND
Apply
Remote • Full-Time • 5+ years exp
PowerShell
Python
SQL
DevOps
Splunk
Cybersecurity
MITRE ATT&CK
Sophos
Apply
$92k – $167k per year • In office • Full-Time • 10+ years exp • Bachelor's Degree • Laurel
Apply
Security Engineer 4 days ago
In office • Full-Time • Canberra • Melbourne
Apply
$91k – $185k per year (Estimated) • In office • Full-Time • 8+ years exp • Bachelor's Degree • San Antonio
DevOps
AWS
Azure
CI/CD
GCP
Hyper-V
KVM
VMWare
Management
Confluence
Jira
Apply
Business Analyst 4 days ago
In office • Full-Time • Canberra
Management
Confluence
Jira
Apply
Solution Architect 4 days ago
$103k – $135k per year • Remote/Hybrid • Full-Time • London • Farnborough
DevOps
AWS
Azure
Apply
$99k – $135k per year • In office • Full-Time • 10+ years exp • Bachelor's Degree • Washington
JavaScript
TypeScript
DevOps
Azure
Azure DevOps
CI/CD
Management
Power Apps
Power Automate
QA
Playwright
Apply
$118k – $162k per year • Remote • Full-Time • 10+ years exp • Bachelor's Degree • Louisville • Fort Lauderdale • Washington • Chicago • Tampa
DevOps
Azure
GCP
Cybersecurity
HIPAA
Apply
$81k – $122k per year • Remote/Hybrid • Full-Time • PhD • Atlanta • Washington
JavaScript
SQL
AI/ML
AI Agents
Agentforce
Marketing
Salesforce
Apply
$171k – $273k per year • In office • Full-Time • 8+ years exp • PhD • San Francisco • Washington
AI/ML
A2A
Agentforce
AI Agents
Model Context Protocol
DevOps
AWS
GCP
Marketing
Salesforce
Apply
Data Scientist 3 hours ago
$113k – $188k per year • In office • Full-Time • 5+ years exp • Bachelor's Degree • Arlington • Washington
Python
Databases
Databricks
DevOps
AWS
Azure
Analytics
ETL/ELT
Power BI
Apply
See all jobs
This is one of many
368,634 more open roles from verified company boards, updated every day.