Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
SOC Analyst image - Rise Careers
Job details

SOC Analyst

DescriptionAt Leidos, we deliver innovative solutions through the efforts of our diverse and talented people who are dedicated to our customers’ success. We empower our teams, contribute to our communities, and operate sustainable. Everything we do is built on a commitment to do the right thing for our customers, our people, and our community. Our Mission, Vision, and Values guide the way we do business.If this sounds like the kind of environment where you can thrive, keep reading!The Digital Modernization Sector brings together our digital transformation and IT programs, allowing us to better serve our customers through scale and repeatability. Leidos has a critical need for a Tier 1 SOC Analyst.Leidos is seeking a motivated Tier 1 SOC analyst to join our team on a highly visible cyber security single-award IDIQ vehicle. This is a Federal Government program responsible for the prevention, identification, containment, and eradication of cyber threats to IT Enterprise through monitoring, intrusion detection and protective security services. This includes local area networks/wide area networks (LAN/WAN), commercial Internet connection, public facing websites, wireless, mobile/cellular, cloud, security devices, servers and workstations. This Program is responsible for supporting the overall security of Enterprise-wide information systems, and collects, investigates, and reports any suspected and confirmed security violations.The SOC analyst-mid will perform the following:· Coordinate investigation and response efforts throughout the Incident Response lifecycle· Correlate and analyze events and data to determine scope of Cyber Incidents· Acquire and analyze endpoint and network artifacts, volatile memory, malicious files/binaries and scripts· Recognize attacker tactics, techniques, and procedures as potential indicators of compromise (IOCs) that can be used to improve monitoring, analysis and Incident Response.· Develop, document, and maintain Incident Response process, procedures, workflows, and playbooks· Tune and maintain security tools (EDR, IDS, SIEM, etc) to reduce false positives and improve SOC detection capabilities· Document Investigation and Incident Response actions taken in Case Management Systems and prepare formal Incident Reports· Create metrics and determine Key Performance Indicators to drive maturity of SOC operations· Develop security content such as scripts, signatures, and alertsBasic Qualifications:Bachelor’s degree in IT or related field and 4-8 years of experience with cybersecurity, soc analysis and/or incident response. Additional experience and certs may be considered in lieu of a degree.4-8 years as a SOC analyst or similar work roles• In-depth knowledge of each phase of the Incident Response life cycle• Expertise of Operating Systems (Windows/Linux) operations and artifacts• Understanding of Enterprise Network Architectures to include routing/switching, common protocols (DHCP, DNS, HTTP, etc), and devices (Firewalls, Proxies, Load Balancers, VPN, etc)• Ability to recognize suspicious activity/events, common attacker TTPs, and perform logical analysis and research to determine root cause and scope of Incidents• Be familiar with Cyber Kill Chain and have utilized the ATT&CK Framework• Have scripting experience with Python, PowerShell, and/or Bash• Ability to independently prioritize and complete multiple tasks with little to no supervision• Flexible and adaptable self-starter with strong relationship-building skills• Strong problem-solving abilities with an analytic and qualitative eye for reasoningMust have at least one of the following certifications:GCIH, GCFA, GCFE, GREM, GISF, GXPN, GWEB, GNFA, OSCP, OSCE, OSEE, CCFP, CISSP, CCNO, CEH, LPT, SCSA, ENSA, ECIH, ECSS, ECES, CIRCOriginal Posting Date:2024-12-12While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.Pay Range:Pay Range $85,150.00 - $153,925.00The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.
Leidos Glassdoor Company Review
3.8 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
Leidos DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of Leidos
Leidos CEO photo
Tom Bell
Approve of CEO

Average salary estimate

$119537.5 / YEARLY (est.)
min
max
$85150K
$153925K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About SOC Analyst, Leidos

Leidos is on the lookout for a dedicated Tier 1 SOC Analyst to join our vibrant team in Herndon, VA. With a mission to deliver innovative solutions, we believe in empowering our talented individuals and fostering a collaborative environment aimed at customer success. In this role, you’ll dive into the world of cybersecurity, helping to defend against threats while working on a high-stakes federal government initiative. Your key responsibilities will include coordinating investigations across the Incident Response lifecycle, analyzing events and data to identify the scope of cyber incidents, and acquiring artifacts from both endpoints and networks. As a SOC Analyst, you'll become adept at recognizing attacker tactics and techniques, which fuel your ability to provide insightful recommendations for process improvements. You'll also be responsible for tuning security tools to enhance detection capabilities, documenting incidents meticulously, and contributing to the overall maturity of SOC operations through the development of security content. To succeed in this role, a bachelor’s degree in IT or a related field along with 4-8 years of experience in cybersecurity is essential. If you're familiar with operating systems, network architectures, and have a knack for scripting in Python, PowerShell, or Bash, we want to hear from you! Join us at Leidos, where your work will directly contribute to securing enterprise information systems, all while enjoying a vibrant workplace that values community involvement and integrity.

Frequently Asked Questions (FAQs) for SOC Analyst Role at Leidos
What responsibilities does a SOC Analyst at Leidos have?

As a SOC Analyst at Leidos, your primary responsibilities include coordinating the investigation and response efforts throughout the Incident Response lifecycle, analyzing cyber events and data to gauge the extent of incidents, and recognizing potential indicators of compromise. You'll also be tasked with developing and documenting Incident Response processes and tuning security tools to enhance SOC operations.

Join Rise to see the full answer
What qualifications are required for the SOC Analyst position at Leidos?

Candidates for the SOC Analyst position at Leidos should possess a bachelor’s degree in IT or a related field, complemented by 4-8 years of experience in cybersecurity or incident response. Relevant certifications in cybersecurity will also be considered in lieu of degree requirements, along with knowledge of operating systems and network architecture.

Join Rise to see the full answer
What kind of environment does Leidos offer for SOC Analysts?

Leidos promotes a vibrant and engaging work environment for SOC Analysts, focusing on team empowerment, community contribution, and sustainable operations. You'll be joining a diverse team committed to delivering innovative solutions and achieving customer success, alongside a culture that values integrity and collaboration.

Join Rise to see the full answer
What tools and technology does a SOC Analyst at Leidos work with?

SOC Analysts at Leidos work with essential tools such as Security Information and Event Management (SIEM) systems, Endpoint Detection and Response (EDR) software, and Intrusion Detection Systems (IDS). You’ll also engage with various cybersecurity technologies, analyzing data from networks, servers, and security devices to understand and respond to threats effectively.

Join Rise to see the full answer
Are there opportunities for growth as a SOC Analyst at Leidos?

Yes, there are excellent opportunities for growth as a SOC Analyst at Leidos. The organization emphasizes continuous learning and professional development, encouraging you to pursue relevant certifications and enhancing your skills through various initiatives. As you contribute to the team’s success, there is room for advancement within the cybersecurity domain.

Join Rise to see the full answer
Common Interview Questions for SOC Analyst
Can you explain the Incident Response lifecycle as a SOC Analyst?

The Incident Response lifecycle includes several phases: preparation, detection and analysis, containment, eradication, and recovery, followed by post-incident activities. Each phase requires meticulous planning, timely response, and thorough documentation to effectively manage and mitigate cybersecurity incidents.

Join Rise to see the full answer
How do you prioritize and respond to multiple security incidents?

Prioritizing multiple security incidents involves assessing each event based on its severity, impact, and urgency. I leverage existing frameworks to classify the incidents and utilize automation tools to streamline the response process, ensuring critical threats are addressed promptly while maintaining communication with relevant stakeholders.

Join Rise to see the full answer
What methods do you use to analyze and correlate data in a SOC environment?

In a SOC environment, I utilize various analysis techniques including log analysis, threat intelligence feeds, and anomaly detection. I correlate data from different sources such as SIEM systems and network logs to visualize patterns that indicate potential threats or breaches.

Join Rise to see the full answer
Describe how you would handle a detected incident in a live environment.

Upon detecting an incident, I would first contain the threat to prevent further damage, followed by thorough analysis to understand the scope and impact. Active communication is vital as I collaborate with the incident response team to eradicate the threat and initiate recovery processes, documenting each action for future reference.

Join Rise to see the full answer
What cybersecurity certifications do you hold that are relevant to the SOC Analyst role?

I possess several relevant certifications, including GCIH and CEH, which demonstrate my knowledge of incident handling and ethical hacking practices. These certifications not only enhance my understanding of cyber threats but also validate my commitment to continuous learning in the cybersecurity field.

Join Rise to see the full answer
How have you utilized the ATT&CK Framework in your work?

I have utilized the ATT&CK Framework to better understand adversary tactics, techniques, and procedures in my analysis work. This framework helps me identify patterns and potential indicators of compromise within threat data, allowing for more informed decisions and tailored incident response strategies.

Join Rise to see the full answer
What steps do you take to document incidents and response actions?

Documenting incidents and response actions involves thorough record-keeping of each phase of the incident lifecycle. I ensure I note all details, including timestamps, actions taken, and the rationale behind decisions. This documentation serves both as a record for future reference and as a means to improve processes.

Join Rise to see the full answer
Can you give an example of a time you recognized a sophisticated attack?

Certainly! I identified a sophisticated attack during a routine monitoring session. By recognizing unusual patterns in user behavior and network traffic, I was able to compute an estimated timeline and alert the team, which led to prompt containment of the threat before any significant damage occurred.

Join Rise to see the full answer
How do you stay updated with the latest cybersecurity threats and trends?

I regularly follow industry news, participate in webinars, and engage with professional communities online. Additionally, I subscribe to threat intelligence services and cybersecurity blogs which help me stay informed about emerging threats, vulnerabilities, and best practices in incident response.

Join Rise to see the full answer
What role does teamwork play in your effectiveness as a SOC Analyst?

Teamwork is crucial for a SOC Analyst's effectiveness. Collaborating with my colleagues enables us to leverage diverse perspectives, share insights, and coordinate responses more efficiently. This collaborative approach greatly enhances our overall security posture and enables more robust incident response.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Leidos Remote Alexandria, AL
Posted 11 days ago
Photo of the Rise User
Posted 11 days ago
Photo of the Rise User
Boldr Remote No location specified
Posted 10 days ago
Photo of the Rise User
Posted 2 days ago
Photo of the Rise User
Posted 6 days ago
Photo of the Rise User
Posted 12 days ago
Quantum Dynamics, Inc. Hybrid Chamberlain Ave, Fort Eisenhower, GA, United States
Posted 9 days ago

Everything we do is built on a commitment to do the right thing for our customers, our people, and our community. Our Mission, Vision, and Values guide the way we do business. At Leidos, our mission is to make the world safer, healthier, and mor...

382 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, on-site
DATE POSTED
December 14, 2024

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!