Detection, Monitoring, & Countermeasures Lead

LeidosAlexandria, VirginiaOn-siteFull-timeSenior, 5–8 yearsListed 56 minutes ago

Apply now

About this role

The Detection, Monitoring, and Countermeasures Lead serves as a senior Subject Matter Expert (SME) responsible for the operational management and technical optimization of the Security Operations Center's (SOC) detection, triage, and prevention capabilities. This role leads the continuous monitoring of Pentagon networks, directs the tuning of all security tools to ensure optimal detection, and develops and implements countermeasures to mitigate security risks and prevent adversary actions. The Lead will manage a team of 10-15 staff in a high-pressure, 24/7/365 environment, ensuring the effectiveness and compliance of all detection and prevention systems in accordance with CJCSM 6510.01, DoD/IC directives, and the Performance Work Statement (PWS).

This role involves evaluating current cyber defense technologies, identifying capability gaps, and shaping requirements for future cybersecurity operations (such as Thunderdome and Zeek/Netflow). The Lead will deliver strategic reports that drive tool impact and mission success.

Primary Responsibilities

- Security Monitoring & Detection: Lead the 24x7x365 real-time monitoring and analysis of network and endpoint security data from the J6 Pentagon sensor grid (including IDS/IPS, firewalls, netflow, packet capture, and SIEM). Direct the identification, trending, and correlation of event data to identify malicious cyber activity (including insider threats and APTs) and oversee backbone network monitoring to ensure proper configuration for both signature-based and anomalous activity detection.
- Tool Tuning & Optimization: Lead the Countermeasures Team in the effective tuning and optimization of all security systems (e.g., SIEM, IDS/IPS, End Point Security) to ensure optimal detection and prevention capabilities. Ensure tools are configured with correct data feeds and direct the application of vendor and custom signatures to prevent, detect, and block malicious activity.
- Countermeasure Development: Lead the development and implementation of countermeasures to mitigate potential security risks. Assess the effectiveness of current monitoring capabilities to drive process improvements and develop project plans for government approval to implement recommended detection enhancements.
- Reporting & Metrics: Provide monthly reports to the Government on system uptime, availability, maintenance, and vulnerability mitigation. Provide input for monthly, quarterly, and annual reports detailing tool versions, upgrade plans, and license counts, while maintaining SOPs, after-hours recall rosters, and lifecycle status reports for all managed infrastructure.

Required Qualifications & Skills

- Security Clearance: Must possess an active Top-Secret clearance with SCI eligibility. Access to SCI, NIPRNet, SIPRNet, and JWICS networks is required.
- Education & Experience: Requires a bachelor’s degree in a relevant IT or Cybersecurity field and 12 to 15 years of prior relevant experience; OR a Master’s degree with 10 to 13 years of prior relevant experience. This must include 5+ years in incident handling or SOC operations, extensive experience operating, planning, and managing a SOC/CIRT, and 3+ years of demonstrated experience administering and deploying enterprise network defense tools (e.g., IDS/IPS, Packet Capture, SIEM, Proxy, Web Content Filtering).
- Certifications: Prior to Start: Must meet DoD 8140/8570.01-M requirements for IAT Level II (e.g., Security+ CE, CySA+, CCNA Security, GSEC). Within 180 Days: Must obtain a CSSP Analyst certification (e.g., CEH, CySA+, GCIA, GCIH).
- Enterprise Tool & Infrastructure Expertise (Tool-Agnostic): Subject Matter Expertise in the architecture, engineering, and operations of enterprise SIEM platforms (e.g., Splunk, QRadar, ArcSight), endpoint security solutions (e.g., Trellix, MDE, ACAS), and modern security infrastructure (e.g., Taps, IPS, Zero Trust appliances).
- Defensive Cyber Operations (DCO), Threat Hunting & Forensics: Experience executing and supporting DCO training and operations, to include conducting active threat hunts aligned to the MITRE ATT&CK framework, performing forensic analysis (using log data, IDS events, and network PCAP) to reconstruct attack timelines, and delivering actionable threat insights to operational teams.
- Advanced Network Fundamentals & Complex Problem Solving: Deep understanding of network traffic, the OSI model, defense-in-depth principles, and the network threat lifecycle, with a proven ability to resolve highly complex, multi-dimensional technical problems affecting multiple aspects of a program.
- Technical Leadership & Mentorship: Proven experience serving as a technical lead on large, complex projects; with the agility to pivot between multiple initiatives and track them to completion; while supervising, mentoring, and coaching technical staff across various skill levels.
- Executive Communication & Reporting: Exceptional communication skills with the demonstrated ability to draft comprehensive technical reports and brief senior executive leadership (both internal and client-facing) on operational findings and matters of strategic importance.
- Innovation & Technology Integration: Ability to drive the research, fielding, and integration of new security technologies, leading the collaborative development of innovative products and solutions alongside other industry experts.

If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares.

##

##

## Original Posting:
October 1, 2026

For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

## Pay Range:
Pay Range $131,300.00 - $237,350.00

The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.