Cyber Real-Time Analyst

LeidosPearl City, HI
$69,550 - $125,725Onsite

About The Position

Leidos is hiring Real Time Analysts to join the Network Assurance Team supporting DISA Pacific (DNC-PAC) at Ford Island, Joint Base Pearl Harbor-Hickam. This team serves as the Security Operations Center (SOC) for USPACOM and the broader DoD Information Network (DODIN/DISN), standing watch 24/7/365 to detect, analyze, and respond to threats against the boundary of the Department of Defense's global network. You'll work at the intersection of two missions: the established DISA SOC boundary defense operation that protects the DODIN's Pacific footprint, and the emerging Joint Fires Network (JFN) Security Operations Center supporting a next generation, TS/SCI-level sensor and detection environment being stood up at the same location. It's a rare opportunity to defend mature, mission-critical infrastructure while helping build a brand-new SOC capability from the ground up.

Requirements

  • Active Top Secret security clearance with eligibility/ability to obtain SCI
  • Level II: Bachelor's degree and 2+ years of relevant experience; equivalent work experience and/or military service may be considered in lieu of a degree.
  • Level III: Bachelor's degree and 4+ years of relevant experience; equivalent work experience and/or military service may be considered in lieu of a degree.
  • Qualifications/credentials compliant with DoD 8140 DCWF Code 531, Cyber Defense Analyst at the Intermediate proficiency level.
  • Hands-on experience with Computer Network Defense duties — protect, defend, respond, and sustain.
  • Strong networking fundamentals, including communication protocols and common security tooling (IDS/IPS, firewalls).
  • Experience evaluating packet captures and analyzing raw network traffic.
  • Willingness and ability to work rotating shifts in support of 24/7/365 operations, including some after-hours and surge support.

Nice To Haves

  • AI capability development and implementation to automate analysis and detection tasks.
  • Working knowledge of adversary tactics, techniques, and procedures (TTPs), and familiarity with MITRE ATT&CK and the Cyber Kill Chain.
  • Direct experience with Splunk, Elastic, or similar SIEM/detection platforms.
  • Familiarity with JIRA-based incident workflows and/or SOC intake and escalation processes.
  • Understanding of software exploits, and experience analyzing packed or obfuscated code.

Responsibilities

  • Monitor, detect, and analyze intrusions, incidents, and threats across the DODIN/DISN boundary — Internet Access Points, Boundary Cloud Access Points, and related infrastructure — using DoD-approved network monitoring and traffic analysis tools on a 24/7/365 basis.
  • Perform near real-time triage of security events, correlating alerts, netflow, IDS/IPS output, and raw packet captures to confirm or refute malicious activity.
  • Conduct deep-dive analysis of “low and slow” activity to uncover unauthorized access that automated tools miss.
  • Investigate and analyze events using SIEM platforms including Splunk, Elastic, and Microsoft Sentinel, and correlate sensor data through the ThunderDome cybersecurity suite.
  • Apply the MITRE ATT&CK framework to characterize adversary tactics, techniques, and procedures, and to guide incident analysis and threat-hunting.
  • Develop, tune, and recommend custom detection signatures and countermeasures to prevent or mitigate emerging threats.
  • Document analysis and findings in the DoD-mandated incident reporting/ticketing system, and issue Situational Awareness Reports and TIPPERs to mission partners.
  • Coordinate directly with the DISA Joint Operations Center (DJOC), USCYBERCOM, and peer SOCs to synchronize threat intelligence and incident response across the DODIN.
  • Support stand-up and sustainment of a 24x7x365 Security Operations Center for the JFN IL-6 environment, focused on threat detection and continuous monitoring across JFN nodes.
  • Conduct Syslog review and Elastic stack alerting to identify anomalies, and tune advanced sensors such as Corelight as the SOC matures.
  • Triage, escalate, and track incidents through JIRA using standardized SOC intake and escalation processes.
  • Handle TS/SCI-level incidents in accordance with DIA-aligned requirements, ensuring spills, breaches, or anomalies are reported through authorized channels within mandated timelines.
  • Develop threat-hunting playbooks focused on behavioral anomalies and traffic pattern analysis as the mission matures from initial monitoring into full detection and response.
  • Work from a Sensitive Compartmented Information Facility (SCIF) at DISA Pacific, Ford Island.

Benefits

  • Direct, high-visibility mission impact defending USPACOM and DODIN/DISN infrastructure in a strategically critical theater.
  • Ground-floor opportunity to help build a new SOC capability alongside an established, mature SOC operation.
  • Daily collaboration with DISA, USCYBERCOM, and Government leadership — direct exposure to enterprise-level cyber defense decision-making.
  • Long-term program stability: multi-year task order (base plus four option years) with an established incumbent team.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service