Endpoint Security Analyst - Elastic Defend
$107.9k - $195.05kLeidos
The C5ISR Center Cyber Security Service Provider (CSSP) is a premier defensive cyber operations organization supporting the Department of War (DoW). Operating 24x7x365, the CSSP provides continuous monitoring, threat detection, incident response, and vulnerability management across cloud and on-premises environments, including AWS, Azure, GCP, Oracle Cloud, and SaaS platforms.Every day, our team protects the networks, systems, and data that enable critical DoW missions.Leidos has an immediate opportunity for an experienced Endpoint Security Analyst to support a highly visible, strategic Cybersecurity Task Order. In this role, you will provide specialized expertise supporting Elastic Agent and Elastic Defend, helping deploy, configure, optimize, and sustain endpoint protection, telemetry collection, threat detection, and automated response capabilities across the enterprise.You will work closely with threat, engineering, and cybersecurity operations teams to strengthen endpoint defenses, improve visibility, and rapidly identify and respond to emerging cyber threats.Location: Hybrid - 3 days on site at Adelphi, MDClearance: U.S. Citizenship with an active TS/SCI with SAP EligibilityPrimary Responsibilities:Deploy, configure, operate, tune, upgrade, and troubleshoot Elastic Agent, Elastic Defend, and other enterprise endpoint security technologies.Optimize endpoint protection and telemetry collection to maximize security visibility and detection effectiveness while minimizing operational and system performance impacts.Partner with Threat and Detection teams to customize detection rules, develop threat signatures, and align endpoint defenses with emerging threat intelligence and MITRE ATT&CK techniques.Conduct host-based defensive cyber operations to identify, investigate, contain, mitigate, and remediate vulnerabilities and intrusions.Support cyber investigations using advanced endpoint queries, forensic data collection, and rapid containment and response capabilities.Build and maintain queries, dashboards, and reports that provide enterprise security visibility and leadership awareness.Coordinate with engineering teams on endpoint security deployments, patches, hot fixes, upgrades, and other critical security updates.Troubleshoot endpoint security tool issues, performance concerns, and outages.Develop and maintain endpoint security policies, configurations, and Standard Operating Procedures (SOPs).Evaluate emerging endpoint security tools, techniques, and technologies and recommend improvements aligned with enterprise cybersecurity strategy.Basic Qualifications:Bachelor's degree in Science, Technology, Engineering, Mathematics (STEM), cybersecurity, or a related field and 4+ years of relevant cybersecurity experience.Hands-on experience deploying, configuring, operating, or supporting enterprise endpoint security or EDR solutions.Strong understanding of endpoint protection, security telemetry, threat detection, incident investigation, and response.Experience investigating and responding to endpoint security alerts and potential compromises.Knowledge of current cyber threats, attacker techniques, and defensive strategies, including familiarity with the MITRE ATT&CK framework.Strong analytical, troubleshooting, and problem-solving skills.Ability to work effectively across cybersecurity, threat, and engineering teams.Strong written and verbal communication skills.U.S. citizenship and an active TS/SCI with SAP eligibility.At least one of the following certifications:GIAC/SANS: GCIA, GCIH, GCFA, GCFE, GREM, GISF, GXPN, GWEB, GNFA, or GMONOffensive Security: OSCP, OSCE, OSWP, or OSEEISC2: CCFP or CISSPEC-Council: CEH, CHFI, LPT, ECSA, or ECIPreferred Qualifications:Hands-on experience with Elastic Agent and Elastic Defend, including deployment, configuration, policy management, tuning, and troubleshooting.Experience optimizing endpoint telemetry and security controls in large-scale enterprise environments.Experience developing or tuning endpoint detection rules, threat signatures, IOCs, and behavioral detections.Experience using Elastic capabilities for endpoint investigation, advanced querying, forensic data collection, and response actions.Experience with CrowdStrike Falcon, McAfee/Trellix ePO, Tanium, or similar enterprise endpoint security platforms.Experience deploying and configuring CrowdStrike Falcon sensors and creating custom Indicators of Compromise (IOCs) and Indicators of Attack (IOAs).Experience supporting endpoint security operations within large, complex, or mission-critical environments.Relevant endpoint security certifications, such as Elastic, CrowdStrike, or Tanium certifications.If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares.Original Posting:August 25, 2026For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.Pay Range:Pay Range $107,900.00 - $195,050.00The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.SummaryLocation: Adelphi, MDType: Full time
$102.5k - $188.9k
...confidence, and proactively manage to secure success.Cyber threats... .... As a Cyber Exploitation Analyst, you will support cyber defense... ...offering assists clients in defending against advanced threats by transforming... ...prevention systems (IPS), or endpoint detection and response (EDR)...SuggestedWork at office- Job Summary: The Network Security Analyst I is responsible for performing advanced cybersecurity... ...across multiple data sources including endpoints, firewalls, IDS/IPS, cloud services,... ...Detection and Response tools (e.g., Microsoft Defender for Endpoint, CrowdStrike)....SuggestedShift workNight shift
$113k - $188.4k
...with confidence, and proactively manage to secure success. Work You’ll Do As a Project... ...on the project, you will: The Security Analyst will monitor and analyze security events... ...Resilience offering assists clients in defending against advanced threats by transforming...SuggestedLocal area$104k - $166k
...currently seeking to hire an experienced Forensics / Malware Security Analyst for its Federal Strategic Cyber Group.Location: Chandler, AZ... ...Conduct advanced network and digital media forensics, including endpoint, memory, and log analysis.Support incident response handling,...SuggestedContract workCurrently hiringShift work$62k - $141k
COMSEC Security Program AnalystThe Opportunity:Provide technical and financial analytic support to the client’s Communications Security... ...and cybersecurity requirements and capabilities to support and defend the client’s strategic investments.You Have:Experience with COMSEC...SuggestedCivilian ContractorFull timeContract workPart timeWork at officeLocal areaRemote work$129k - $171k
...TEAMAnduril's Detection and Response team is looking for a Security Operations Analyst to be the watchtower for Anduril's critical defense... ...multiple disciplines including, but not limited to, phishing, endpoints, cloud infrastructure and services, and SaaS applicationsBuild...Full timeWork experience placementImmediate start$3,000 per month
...cybersecurity team supporting the U.S. Department of State. As a Security Analyst, you will support day-to-day cybersecurity operations by... ...or other federal civilian agencies. Experience with Microsoft Defender, Microsoft Sentinel, Splunk, ServiceNow, Tenable Nessus, Qualys...Contract workWork from home- ...Position Summary: The Information Security Analyst plays a critical role in protecting the association's member data, proprietary research... ...Support o Maintain and optimize security tools (SIEM, endpoint protection, firewalls). o Assist in evaluating secure...
- Security Operations Center (SOC) Analyst Washington, District of Columbia, United States About the job Security Operations Center (SOC) Analyst Job Description... ..., and response (SOAR) platforms. Familiarity with endpoint detection and response (EDR) tools and technologies....
$70.3k - $114.4k
The Enterprise Security Analyst II is a hands-on Security Operations Center (SOC) role responsible for monitoring alerts, investigating security... ...Response Monitor and manage the SOC alert queue across endpoint, identity, network, email, cloud, and log monitoring platforms...Monday to Friday- ...qualified applicants to apply. We are currently seeking a Senior Security Operations Analyst to support cybersecurity operations within a federal... ...and alerting systems Log analysis across network, endpoint, and cloud environments Threat detection and monitoring tools...Full timeLocal areaShift work
- ...and grow professionally? We can help! We are seeking a IT Security Operations Analyst for the IT Technology Services contract. This project will... ...Enterprise Lifecycle Management Services (ELMS) and Microsoft Endpoint Configuration Manager (MECM). Monitor patching activities...Full timeContract workPart timeWork at officeRemote workMonday to Friday
$98.84k - $148.26k
...radically improve how Washington residents secure health insurance through innovative and... ...SUMMARY\n The Senior Application Security Analyst plays a key role in protecting WAHBE’s... ...Information and Event Management (SIEM) systems, Endpoint Detection & Response\n • Demonstrated...Contract workWork at officeImmediate startRemote workMonday to FridayShift work- ...**CONTINGENT UPON CONTRACT AWARD**Overview: Job Title: Security Operations Analyst – Senior Location : Washington, DC (Due to the nature... ...techniques. ~ Experience analyzing logs, network traffic, and endpoint activity. ~ Familiarity with operating systems (Windows,...Contract work
- ...Contract Compensation: $50.88/HR on W2 Security Clearance: Ability to obtain and maintain... ...point for complex malware and endpoint security incidents, driving rapid restoration... ...McAfee ePO, or Microsoft Security Operations Analyst (preferred). System One, and its...Contract workLocal area
- IT - Information Security/Privacy Analyst I Summary: The CIOCC Tier 1 Analyst shall be responsible for the following, but not limited to: Analyze... ...Systems (IDS), Intrusion Prevention Systems (IPS), Endpoint Security Solutions, Network Access Control (NAC) and other...Shift workAfternoon shift
- ...Job Title: Information Security Analyst Location: Bellevue, WA Type: Contract Contractor Work Model: Onsite Responsibilities... ...suspicious activity and email. Assist in developing and enforcing endpoint security policies for device hardening, removable media...Permanent employmentContract workTemporary workFor contractorsWork experience placementLocal area
$105k - $130k
...mission of AHRI. AHRI has an opening for an Information Security Analyst . This position plays a critical role in protecting the association... ...facing teams. Maintain and optimize security tools (SIEM, endpoint protection, firewalls). Qualifications: Bachelor’s...Full timeWork experience placementFlexible hours- ...clients to improve the lives and ensure the security of all Americans—from soldiers and veteran to kids and the elderly, and defend national interests on the battlefield. Our... ...We are seeking an Information Security Analyst who is responsible for providing security support...Work experience placementRemote work
$132.5k - $221.3k
...Technology, Test & Evaluation, Program Mission Support, Engineering & Analysis, and Training.ResponsibilitiesAs The Security Specialist Security Operations Analyst, you will:Apply structured analysis, business modeling, and process evaluation to improve security operations...For contractorsWork experience placement- ...objectives. The ProSidian Federal Govt. Client’s Mortgage Backed Securities (MBS) programs help to channel funds from the nation's capital... ...economic and industry trends, and customer demand. Financial analysts provide this information by gathering and analyzing data. They...Full timeFor contractorsBank staffInternshipWork at office
$62k - $141k
Crisis Response and Security Program AnalystThe Opportunity: As a Crisis Response and Embassy Security Program Analyst, you support executive-level leadership and drive collaboration across high-performing teams in a fast-paced mission environment. Drawing upon your deep...Full timeContract workPart timeWork at officeLocal areaRemote workOverseas- ...State Government Agencies. Learn More About ProSidian Consulting at DescriptionProSidian seeks a Mid-Level InfoSec Mobile Device Security Analyst Consultant focusing on Cyber-Security/Information Security (INFOSEC) and IT Effectiveness Solution related issues, to support...Full timeFor contractorsWork experience placementInternshipWork at officeMonday to FridayShift work
- ...What You Will Do:Guidehouse is looking for an experienced professional with experience in building, controlling, and supporting the secure configurations of information systems for federal organizations. Your duties will include supporting and controlling secure...Full timeFlexible hours
- ...given the means and mentorship needed to succeed, and your creativity will be rewarded.About the PositionDexis is seeking a Security Assistance Analyst to support anticipated programming with the Department of State. This opportunity will provide program analysis,...Contract work
- DescriptionSAIC is seeking a Security and Facilities Specialist with an active TS/SCI to provide security, facility, and customer support for a diverse team of government, contractor, and SAIC personnel. Complete understanding and wide application of principles, concepts...For contractorsWork at office
$145k - $200k
Washington, D.C.Information Security /Full-time /On-siteA World-Changing CompanyPalantir builds the world’s leading software for data-driven... ...missing children, and more.The RoleAs a Defensive Security Analyst, you are responsible for the security of Palantir’s people and...Full timeWork experience placementWork at officeRemote workWork from homeRelocation package$99k - $225k
Security Specialist & Counterintelligence AnalystThe Opportunity: Deliver mission-critical insight to inform senior-level decisions and ensure protection of U.S. forces, infrastructure, and sensitive operations against foreign intelligence threats. Apply analytical tradecraft...Full timeContract workPart timeWork at officeLocal areaRemote work- ...solutions, tested leadership, and trusted results to enable national security missions worldwide.Job Description*** This position is contingent upon contract award ***OverviewSOSi is seeking a Security Analyst - Forensics/Malware Analysis to support cyber defense and...Contract workWork at officeWorldwideMonday to FridayWeekend workAfternoon shift
$102k - $178.4k
...edge of geopolitics and technology, and shape the future of cloud security? Our team does this every day. We are looking for a security... ...combines the functions of a traditional all-source intelligence analyst with risk manager and operational security advisor. Using these...Temporary workFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Endpoint Security Analyst - Elastic Defend. Be the first to apply!


