Security Infrastructure Engineer

LeidosAlexandria, VA
$107,900 - $195,050Hybrid

About The Position

Leidos is seeking an AI & Security Infrastructure Integration Engineer to join their team. This role involves operating, maintaining, and evolving network security infrastructure for a 24x7x365 mission-critical security operations team. The primary focus is on transforming manual workflows into automated pipelines using Python, developing API integrations, and exploring AI/LLM orchestration to enhance threat detection and response capabilities. The position requires a strong understanding of traditional security infrastructure and modern programmatic defense. The company culture emphasizes innovation and a proactive approach to problem-solving, seeking individuals who are disruptive and refuse to fail.

Requirements

  • Active DoD Secret Required with DoD TS/SCI Eligibility
  • Must have DoD 8570 IAT II certification OR meet DoD 8140 Intermediate Cyber Defense Infrastructure Support Specialist requirements prior to start
  • Must obtain DOD-8570 CSSP Infrastructure Support certification within 6 months of hire.
  • Bachelor's degree with 8+ years of professional experience (additional relevant military or work experience may be considered in lieu of a degree).
  • 2+ years of hands-on experience deploying and maintaining cybersecurity tools (especially IDS/IPS, SIEM, or firewalls).
  • Strong, practical knowledge of network protocols, traffic analysis, and routing/switching.
  • Proficiency in Linux administration and shell scripting (Bash).

Nice To Haves

  • Strong proficiency in Python (specifically writing scripts for system automation, network interaction, and data parsing).
  • Demonstrated experience working with RESTful APIs, JSON/YAML data structures, and webhooks to integrate security platforms.
  • Exposure utilizing or fine-tuning AI/ML models, prompt engineering, or integrating AI APIs into operational workflows.
  • Hands-on experience with automation/orchestration frameworks (e.g., Ansible, Terraform, Puppet, or Chef).
  • Practical familiarity with Intelligence-Driven Defense, the Cyber Kill Chain, and mapping controls to the MITRE ATT&CK framework.
  • Prior experience working as or directly supporting a Security Operations Center (SOC) analyst team.

Responsibilities

  • Develop and maintain Python-based tools, scripts, and frameworks to automate routine security infrastructure tasks, policy deployments, and system health checks.
  • Design, build, and integrate custom APIs to connect disparate cybersecurity tools (SIEM, IDS/IPS, Netflow, and threat intelligence feeds) into a cohesive, orchestrated ecosystem.
  • Evaluate and integrate AI/ML technologies and LLM-based solutions to optimize alert triage, automate playbook generation, and accelerate incident analysis for the SOC team.
  • Operate, maintain, and upgrade core cybersecurity capabilities (IDS/IPS, Netflow, SIEM, Snort, Linux, and Virtualization environments).
  • Manage high-priority tasks, infrastructure outages, and routine patching/updates.
  • Maintain precise network topology and elevation diagrams for all managed security equipment.
  • Ensure strict adherence to government compliance standards and coordinate changes through official Change Control Boards (CCB).
  • Advise and strategize with program and government leadership on engineering modern, code-driven security infrastructure solutions.

Benefits

  • Partial telework
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service