Endpoint Security Analyst - Elastic Defend
$107.9k - $195.05kLeidos
The C5ISR Center Cyber Security Service Provider (CSSP) is a premier defensive cyber operations organization supporting the Department of War (DoW). Operating 24x7x365, the CSSP provides continuous monitoring, threat detection, incident response, and vulnerability management across cloud and on-premises environments, including AWS, Azure, GCP, Oracle Cloud, and SaaS platforms.Every day, our team protects the networks, systems, and data that enable critical DoW missions.Leidos has an immediate opportunity for an experienced Endpoint Security Analyst to support a highly visible, strategic Cybersecurity Task Order. In this role, you will provide specialized expertise supporting Elastic Agent and Elastic Defend, helping deploy, configure, optimize, and sustain endpoint protection, telemetry collection, threat detection, and automated response capabilities across the enterprise.You will work closely with threat, engineering, and cybersecurity operations teams to strengthen endpoint defenses, improve visibility, and rapidly identify and respond to emerging cyber threats.Location: Hybrid - 3 days on site at Adelphi, MDClearance: U.S. Citizenship with an active TS/SCI with SAP EligibilityPrimary Responsibilities:Deploy, configure, operate, tune, upgrade, and troubleshoot Elastic Agent, Elastic Defend, and other enterprise endpoint security technologies.Optimize endpoint protection and telemetry collection to maximize security visibility and detection effectiveness while minimizing operational and system performance impacts.Partner with Threat and Detection teams to customize detection rules, develop threat signatures, and align endpoint defenses with emerging threat intelligence and MITRE ATT&CK techniques.Conduct host-based defensive cyber operations to identify, investigate, contain, mitigate, and remediate vulnerabilities and intrusions.Support cyber investigations using advanced endpoint queries, forensic data collection, and rapid containment and response capabilities.Build and maintain queries, dashboards, and reports that provide enterprise security visibility and leadership awareness.Coordinate with engineering teams on endpoint security deployments, patches, hot fixes, upgrades, and other critical security updates.Troubleshoot endpoint security tool issues, performance concerns, and outages.Develop and maintain endpoint security policies, configurations, and Standard Operating Procedures (SOPs).Evaluate emerging endpoint security tools, techniques, and technologies and recommend improvements aligned with enterprise cybersecurity strategy.Basic Qualifications:Bachelor's degree in Science, Technology, Engineering, Mathematics (STEM), cybersecurity, or a related field and 4+ years of relevant cybersecurity experience.Hands-on experience deploying, configuring, operating, or supporting enterprise endpoint security or EDR solutions.Strong understanding of endpoint protection, security telemetry, threat detection, incident investigation, and response.Experience investigating and responding to endpoint security alerts and potential compromises.Knowledge of current cyber threats, attacker techniques, and defensive strategies, including familiarity with the MITRE ATT&CK framework.Strong analytical, troubleshooting, and problem-solving skills.Ability to work effectively across cybersecurity, threat, and engineering teams.Strong written and verbal communication skills.U.S. citizenship and an active TS/SCI with SAP eligibility.At least one of the following certifications:GIAC/SANS: GCIA, GCIH, GCFA, GCFE, GREM, GISF, GXPN, GWEB, GNFA, or GMONOffensive Security: OSCP, OSCE, OSWP, or OSEEISC2: CCFP or CISSPEC-Council: CEH, CHFI, LPT, ECSA, or ECIPreferred Qualifications:Hands-on experience with Elastic Agent and Elastic Defend, including deployment, configuration, policy management, tuning, and troubleshooting.Experience optimizing endpoint telemetry and security controls in large-scale enterprise environments.Experience developing or tuning endpoint detection rules, threat signatures, IOCs, and behavioral detections.Experience using Elastic capabilities for endpoint investigation, advanced querying, forensic data collection, and response actions.Experience with CrowdStrike Falcon, McAfee/Trellix ePO, Tanium, or similar enterprise endpoint security platforms.Experience deploying and configuring CrowdStrike Falcon sensors and creating custom Indicators of Compromise (IOCs) and Indicators of Attack (IOAs).Experience supporting endpoint security operations within large, complex, or mission-critical environments.Relevant endpoint security certifications, such as Elastic, CrowdStrike, or Tanium certifications.If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares.Original Posting:August 25, 2026For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.Pay Range:Pay Range $107,900.00 - $195,050.00The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.SummaryLocation: Adelphi, MDType: Full time
- .... is seeking an experienced Security Authorization / Information System... ...Security Officer (ISSO) Analyst to support federal cybersecurity... ...activities for a large-scale endpoint-management and endpoint-... ...endpoint-platform, Microsoft Defender, program-management, and Government...SuggestedFull timeContract workLocal areaRemote work
- Job Summary: The Network Security Analyst 2 is responsible for monitoring, analyzing, and responding... .... Analyze network traffic and endpoint data using NDR and EDR tools to detect... ...Engineer Associate, or Microsoft 365 Defender-related certifications. Additional...SuggestedShift work
$63k - $83.8k
Back System Security Analyst Cloud/Infrastructure Rockville , Maryland Sep 3, 2026 Senior System Security Analyst Remote... ...experience with monitoring tools like Splunk and endpoint security solutions such as Microsoft Defender. Familiarity with incident response and intrusion...SuggestedTemporary workRemote workNight shiftAfternoon shift- ...years of relevant information security experience (or 3+ years in IT... .../Unix, macOS; networks and endpoints. Experience with vulnerability... ...container security (GKE). Azure: Defender for Cloud, Microsoft Sentinel... ...& Logging: MS Sentinel, MDE, Elastic; Endpoint management/log...SuggestedLocal areaRelocation
$102.5k - $188.9k
...confidence, and proactively manage to secure success. Cyber threats... .... As a Cyber Exploitation Analyst, you will support cyber... ...offering assists clients in defending against advanced threats by transforming... ...prevention systems (IPS), or endpoint detection and response (EDR)...SuggestedWork at office$129k - $171k
...TEAMAnduril's Detection and Response team is looking for a Security Operations Analyst to be the watchtower for Anduril's critical defense... ...multiple disciplines including, but not limited to, phishing, endpoints, cloud infrastructure and services, and SaaS applicationsBuild...Full timeWork experience placementImmediate start$62k - $141k
COMSEC Security Program AnalystThe Opportunity:Provide technical and financial analytic support to the client’s Communications Security... ...and cybersecurity requirements and capabilities to support and defend the client’s strategic investments.You Have:Experience with COMSEC...Civilian ContractorFull timeContract workPart timeWork at officeLocal areaRemote work$104k - $166k
...currently seeking to hire an experienced Forensics / Malware Security Analyst for its Federal Strategic Cyber Group.Location: Chandler, AZ... ...Conduct advanced network and digital media forensics, including endpoint, memory, and log analysis.Support incident response handling,...Contract workCurrently hiringShift work$3,000 per month
...cybersecurity team supporting the U.S. Department of State. As a Security Analyst, you will support day-to-day cybersecurity operations by... ...or other federal civilian agencies. Experience with Microsoft Defender, Microsoft Sentinel, Splunk, ServiceNow, Tenable Nessus, Qualys...Contract workWork from home- RedSky is seeking an experienced Declassification Analyst to review and classify archival materials for DISA records at the National Archives. You will determine declassification eligibility in line with EO 13526, DoD guidance, and agency policies, collaborating with archivists...
- ...Contract Compensation: $50.88/HR on W2 Security Clearance: Ability to obtain and maintain... ...point for complex malware and endpoint security incidents, driving rapid restoration... ...McAfee ePO, or Microsoft Security Operations Analyst (preferred). System One, and its...Contract workLocal area
- ...and grow professionally? We can help! We are seeking a IT Security Operations Analyst for the IT Technology Services contract. This project... ...Enterprise Lifecycle Management Services (ELMS) and Microsoft Endpoint Configuration Manager (MECM). Monitor patching...Full timeContract workPart timeWork at officeRemote workMonday to Friday
$98.84k - $148.26k
...radically improve how Washington residents secure health insurance through innovative and... ...SUMMARY\n The Senior Application Security Analyst plays a key role in protecting WAHBE’s... ...Information and Event Management (SIEM) systems, Endpoint Detection & Response\n • Demonstrated...Contract workWork at officeImmediate startRemote workMonday to FridayShift work- ...**CONTINGENT UPON CONTRACT AWARD**Overview: Job Title: Security Operations Analyst – Senior Location : Washington, DC (Due to the nature... ...techniques. ~ Experience analyzing logs, network traffic, and endpoint activity. ~ Familiarity with operating systems (Windows,...Contract work
- Security Operations Center (SOC) Analyst Washington, District of Columbia, United States About the job Security Operations Center (SOC) Analyst Job Description... ..., and response (SOAR) platforms. Familiarity with endpoint detection and response (EDR) tools and technologies....
- ...qualified applicants to apply. We are currently seeking a Senior Security Operations Analyst to support cybersecurity operations within a federal... ...and alerting systems Log analysis across network, endpoint, and cloud environments Threat detection and monitoring tools...Full timeLocal areaShift work
$105k - $130k
...mission of AHRI. AHRI has an opening for an Information Security Analyst . This position plays a critical role in protecting the association... ...facing teams. Maintain and optimize security tools (SIEM, endpoint protection, firewalls). Qualifications: Bachelor’s...Work experience placementFlexible hours- ...Job Title: Information Security Analyst Location: Bellevue, WA Type: Contract Contractor Work Model: Onsite Responsibilities... ...suspicious activity and email. Assist in developing and enforcing endpoint security policies for device hardening, removable media...Permanent employmentContract workTemporary workFor contractorsWork experience placementLocal area
- IT - Information Security/Privacy Analyst I Summary: The CIOCC Tier 1 Analyst shall be responsible for the following, but not limited to: Analyze... ...Systems (IDS), Intrusion Prevention Systems (IPS), Endpoint Security Solutions, Network Access Control (NAC) and other...Shift workAfternoon shift
- ...Institute (AHRI) in Arlington, VA is seeking an Information Security Analyst to protect member data and proprietary research across our platforms... ...management, risk assessments, security monitoring (SIEM/endpoint), and security tool optimization. #J-18808-Ljbffr The Air-...
- ...clients to improve the lives and ensure the security of all Americans—from soldiers and veteran to kids and the elderly, and defend national interests on the battlefield. Our... ...We are seeking an Information Security Analyst who is responsible for providing security support...Work experience placementRemote work
- ...solutions, tested leadership, and trusted results to enable national security missions worldwide.Job Description*** This position is contingent upon contract award ***OverviewSOSi is seeking a Security Analyst - Forensics/Malware Analysis to support cyber defense and...Contract workWork at officeWorldwideMonday to FridayWeekend workAfternoon shift
- ...IT Cloud Security Analyst Location: Bethesda, MD (Onsite 3–5 days per week) Employment Type: Full-time The National Library of... ...focused on cloud security, administration of Linux and Windows endpoints, strong understanding of network and firewall operations ~...Full timeWork experience placement3 days per week
- ...upon contract award Position Summary TACFI Consulting is seeking a Senior Antiterrorism / Force Protection Analyst to support Air National Guard Security Forces antiterrorism, physical security, mission assurance, compliance, training, assessment, and readiness...Full timeContract workFixed term contractRemote workMonday to FridayFlexible hours
- ...State Government Agencies. Learn More About ProSidian Consulting at DescriptionProSidian seeks a Mid-Level InfoSec Mobile Device Security Analyst Consultant focusing on Cyber-Security/Information Security (INFOSEC) and IT Effectiveness Solution related issues, to support...Full timeFor contractorsWork experience placementInternshipWork at officeMonday to FridayShift work
$45k - $55k
...Job Description Job Description Junior Program Protection Security Analyst Overview: Aether Aerospace is currently seeking a Program Protection Security Analyst, Junior level, to support our government customer at NAS Patuxent River, MD. The candidate must...- ...What You Will Do:Guidehouse is looking for an experienced professional with experience in building, controlling, and supporting the secure configurations of information systems for federal organizations. Your duties will include supporting and controlling secure...Full timeFlexible hours
- ...actively developing the technologies to make this possible, with the ultimate goal of enabling human life on Mars.INDUSTRIAL SECURITY ANALYST (PERSEC)SpaceX is looking for a multidisciplinary Industrial Security Officer (PERSEC) to serve as a Personnel Security Analyst...Work at office
- ...contractor that provides services and solutions in: National Security Programs Professional, Administrative, and Management... ...Time Position Status: Contingent Position Title: Security Analyst Location:Arlington, VA Security Clearance:Secret Duties...Full timeFor contractors
$99k - $225k
Security Specialist & Counterintelligence AnalystThe Opportunity: Deliver mission-critical insight to inform senior-level decisions and ensure protection of U.S. forces, infrastructure, and sensitive operations against foreign intelligence threats. Apply analytical tradecraft...Full timeContract workPart timeWork at officeLocal areaRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Endpoint Security Analyst - Elastic Defend. Be the first to apply!


