Detection, Monitoring, & Countermeasures Lead

Posted 2 Days Ago
Be an Early Applicant
Alexandria, VA, USA
In-Office
131K-237K Annually
Expert/Leader
Information Technology • Software
The Role
Leads a 24/7/365 SOC detection, monitoring, triage, and countermeasures team supporting Pentagon networks. Oversees security-tool tuning, threat detection, incident analysis, threat hunting, forensic investigations, countermeasure development, and cybersecurity capability improvements. Manages 10–15 staff, evaluates technology gaps, directs enterprise defensive cyber operations, maintains operational documentation, and delivers technical and strategic reports to government and executive stakeholders.
Summary Generated by Built In

The Detection, Monitoring, and Countermeasures Lead serves as a senior Subject Matter Expert (SME) responsible for the operational management and technical optimization of the Security Operations Center's (SOC) detection, triage, and prevention capabilities. This role leads the continuous monitoring of Pentagon networks, directs the tuning of all security tools to ensure optimal detection, and develops and implements countermeasures to mitigate security risks and prevent adversary actions. The Lead will manage a team of 10-15 staff in a high-pressure, 24/7/365 environment, ensuring the effectiveness and compliance of all detection and prevention systems in accordance with CJCSM 6510.01, DoD/IC directives, and the Performance Work Statement (PWS).


This role involves evaluating current cyber defense technologies, identifying capability gaps, and shaping requirements for future cybersecurity operations (such as Thunderdome and Zeek/Netflow). The Lead will deliver strategic reports that drive tool impact and mission success.


Primary Responsibilities
  • Security Monitoring & Detection: Lead the 24x7x365 real-time monitoring and analysis of network and endpoint security data from the J6 Pentagon sensor grid (including IDS/IPS, firewalls, netflow, packet capture, and SIEM). Direct the identification, trending, and correlation of event data to identify malicious cyber activity (including insider threats and APTs) and oversee backbone network monitoring to ensure proper configuration for both signature-based and anomalous activity detection.
  • Tool Tuning & Optimization: Lead the Countermeasures Team in the effective tuning and optimization of all security systems (e.g., SIEM, IDS/IPS, End Point Security) to ensure optimal detection and prevention capabilities. Ensure tools are configured with correct data feeds and direct the application of vendor and custom signatures to prevent, detect, and block malicious activity.
  • Countermeasure Development: Lead the development and implementation of countermeasures to mitigate potential security risks. Assess the effectiveness of current monitoring capabilities to drive process improvements and develop project plans for government approval to implement recommended detection enhancements.
  • Reporting & Metrics: Provide monthly reports to the Government on system uptime, availability, maintenance, and vulnerability mitigation. Provide input for monthly, quarterly, and annual reports detailing tool versions, upgrade plans, and license counts, while maintaining SOPs, after-hours recall rosters, and lifecycle status reports for all managed infrastructure.

Required Qualifications & Skills
  • Security Clearance: Must possess an active Top-Secret clearance with SCI eligibility. Access to SCI, NIPRNet, SIPRNet, and JWICS networks is required.
  • Education & Experience: Requires a bachelor’s degree in a relevant IT or Cybersecurity field and 12 to 15 years of prior relevant experience; OR a Master’s degree with 10 to 13 years of prior relevant experience. This must include 5+ years in incident handling or SOC operations, extensive experience operating, planning, and managing a SOC/CIRT, and 3+ years of demonstrated experience administering and deploying enterprise network defense tools (e.g., IDS/IPS, Packet Capture, SIEM, Proxy, Web Content Filtering).
  • Certifications: Prior to Start: Must meet DoD 8140/8570.01-M requirements for IAT Level II (e.g., Security+ CE, CySA+, CCNA Security, GSEC). Within 180 Days: Must obtain a CSSP Analyst certification (e.g., CEH, CySA+, GCIA, GCIH).
  • Enterprise Tool & Infrastructure Expertise (Tool-Agnostic): Subject Matter Expertise in the architecture, engineering, and operations of enterprise SIEM platforms (e.g., Splunk, QRadar, ArcSight), endpoint security solutions (e.g., Trellix, MDE, ACAS), and modern security infrastructure (e.g., Taps, IPS, Zero Trust appliances).
  • Defensive Cyber Operations (DCO), Threat Hunting & Forensics: Experience executing and supporting DCO training and operations, to include conducting active threat hunts aligned to the MITRE ATT&CK framework, performing forensic analysis (using log data, IDS events, and network PCAP) to reconstruct attack timelines, and delivering actionable threat insights to operational teams.
  • Advanced Network Fundamentals & Complex Problem Solving: Deep understanding of network traffic, the OSI model, defense-in-depth principles, and the network threat lifecycle, with a proven ability to resolve highly complex, multi-dimensional technical problems affecting multiple aspects of a program.
  • Technical Leadership & Mentorship: Proven experience serving as a technical lead on large, complex projects; with the agility to pivot between multiple initiatives and track them to completion; while supervising, mentoring, and coaching technical staff across various skill levels.
  • Executive Communication & Reporting: Exceptional communication skills with the demonstrated ability to draft comprehensive technical reports and brief senior executive leadership (both internal and client-facing) on operational findings and matters of strategic importance.
  • Innovation & Technology Integration: Ability to drive the research, fielding, and integration of new security technologies, leading the collaborative development of innovative products and solutions alongside other industry experts.

If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares.

Original Posting:October 1, 2026

For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

Pay Range:Pay Range $131,300.00 - $237,350.00

The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

Skills Required

  • Active Top Secret security clearance with SCI eligibility and access to SCI, NIPRNet, SIPRNet, and JWICS networks
  • Bachelor’s degree in a relevant IT or Cybersecurity field with 12–15 years of relevant experience, or a master’s degree with 10–13 years of relevant experience
  • At least 5 years of incident handling or SOC operations experience
  • Extensive experience operating, planning, and managing a SOC or CIRT
  • At least 3 years administering and deploying enterprise network defense tools, including IDS/IPS, packet capture, SIEM, proxy, or web content filtering technologies
  • DoD 8140/8570.01-M IAT Level II certification before starting, such as Security+ CE, CySA+, CCNA Security, or GSEC
  • CSSP Analyst certification within 180 days, such as CEH, CySA+, GCIA, or GCIH
  • Subject matter expertise with enterprise SIEM, endpoint security, and modern security infrastructure
  • Experience with defensive cyber operations, MITRE ATT&CK-aligned threat hunting, forensic analysis, log analysis, IDS events, and network PCAP
  • Deep understanding of network traffic, the OSI model, defense-in-depth, and the network threat lifecycle
  • Experience serving as a technical lead on large, complex projects and supervising, mentoring, and coaching technical staff
  • Exceptional technical writing, executive communication, reporting, and briefing skills
  • Ability to research, integrate, and field new cybersecurity technologies

Leidos Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Leidos and has not been reviewed or approved by Leidos.

  • Healthcare Strength — Healthcare coverage is described as comprehensive, with multiple plan options, low office-visit copays in some plans, and access to mental health and wellness support tools. The availability of HSA/FSA options and employer contributions is positioned as a meaningful part of the total package.
  • Retirement Support — Retirement benefits are framed as a strong component of total rewards, highlighted by a 401(k) match and immediate vesting in the standard package. The Employee Stock Purchase Plan is also presented as an additional long-term wealth-building feature.
  • Wellbeing & Lifestyle Benefits — Wellbeing and lifestyle supports extend beyond core insurance, including wellness programs, fitness-related stipends, and assistance resources. Work flexibility and related perks are also included as part of the broader rewards experience.

Leidos Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Reston, VA
27,104 Employees
Year Founded: 1969

What We Do

We Are Leidos For 50 years we have been tackling some of the biggest problems that face our nation and our world. OUR MISSION Through our culture of innovation and history of performance, we develop deep customer trust built on integrity and create enduring solutions that improve our world. Leidos is a science and technology solutions leader working to address some of the world’s toughest challenges in the defense, intelligence, homeland security, civil, and healthcare markets. The company’s 43,000 employees support vital missions for government and commercial customers. Headquartered in Reston, Va., Leidos reported annual revenues of approximately $11.09 billion for the fiscal year ended January 3, 2020. Leidos was cited for the meaningful work employees perform that is challenging, impactful, and aligned with our customers’ missions as reasons professionals want to work and stay at our company. Leidos has also been named to lists including Forbes’ Best Employers for Diversity, Forbes’ America’s Best Employers for Women, Military Times Best for Vets Employers, and Ethisphere Institute’s World's Most Ethical Companies®. Employees enjoy career enrichment opportunities available through mobility and development and experience rewarding relationships with supportive supervisors and talented colleagues and customers. Employees appreciate our flexible work environment, allowing for and encouraging a true work-life balance. Our professionals are also excited about our Employee Resource Groups, like the newly launched Collaborative Outreach with Remote and Embedded Employees (CORE), which strives to create an environment where every employee, regardless of location, feels fully engaged as a valued employee of Leidos. Your most important work is ahead.

Similar Jobs

Babylist Logo Babylist

Senior Data Engineer

eCommerce • Healthtech • Kids + Family • Retail • Social Media
Easy Apply
Remote or Hybrid
United States
300 Employees
186K-222K Annually
In-Office or Remote
2 Locations
175633 Employees
100K-193K Annually
In-Office or Remote
2 Locations
175633 Employees
116K-218K Annually

BAE Systems, Inc. Logo BAE Systems, Inc.

Intelligence Analyst - Full Motion Video [ FMV

Aerospace • Hardware • Information Technology • Security • Software • Cybersecurity • Defense
Hybrid
Northern District, VA, USA
40000 Employees
65K-110K Annually

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel Thumbnail
Aerospace • Hardware • Robotics • Software
Marina Del Rey, California
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account