Detection, Monitoring, & Countermeasures Lead
$131.3k - $237.35kLeidos
The Detection, Monitoring, and Countermeasures Lead serves as a senior Subject Matter Expert (SME) responsible for the operational management and technical optimization of the Security Operations Center's (SOC) detection, triage, and prevention capabilities. This role leads the continuous monitoring of Pentagon networks, directs the tuning of all security tools to ensure optimal detection, and develops and implements countermeasures to mitigate security risks and prevent adversary actions. The Lead will manage a team of 10-15 staff in a high-pressure, 24/7/365 environment, ensuring the effectiveness and compliance of all detection and prevention systems in accordance with CJCSM 6510.01, DoD/IC directives, and the Performance Work Statement (PWS).
This role involves evaluating current cyber defense technologies, identifying capability gaps, and shaping requirements for future cybersecurity operations (such as Thunderdome and Zeek/Netflow). The Lead will deliver strategic reports that drive tool impact and mission success.
Primary Responsibilities
- Security Monitoring & Detection: Lead the 24x7x365 real-time monitoring and analysis of network and endpoint security data from the J6 Pentagon sensor grid (including IDS/IPS, firewalls, netflow, packet capture, and SIEM). Direct the identification, trending, and correlation of event data to identify malicious cyber activity (including insider threats and APTs) and oversee backbone network monitoring to ensure proper configuration for both signature-based and anomalous activity detection.
- Tool Tuning & Optimization: Lead the Countermeasures Team in the effective tuning and optimization of all security systems (e.g., SIEM, IDS/IPS, End Point Security) to ensure optimal detection and prevention capabilities. Ensure tools are configured with correct data feeds and direct the application of vendor and custom signatures to prevent, detect, and block malicious activity.
- Countermeasure Development: Lead the development and implementation of countermeasures to mitigate potential security risks. Assess the effectiveness of current monitoring capabilities to drive process improvements and develop project plans for government approval to implement recommended detection enhancements.
- Reporting & Metrics: Provide monthly reports to the Government on system uptime, availability, maintenance, and vulnerability mitigation. Provide input for monthly, quarterly, and annual reports detailing tool versions, upgrade plans, and license counts, while maintaining SOPs, after-hours recall rosters, and lifecycle status reports for all managed infrastructure.
Required Qualifications & Skills
- Security Clearance: Must possess an active Top-Secret clearance with SCI eligibility. Access to SCI, NIPRNet, SIPRNet, and JWICS networks is required.
- Education & Experience: Requires a bachelor’s degree in a relevant IT or Cybersecurity field and 12 to 15 years of prior relevant experience; OR a Master’s degree with 10 to 13 years of prior relevant experience. This must include 5+ years in incident handling or SOC operations, extensive experience operating, planning, and managing a SOC/CIRT, and 3+ years of demonstrated experience administering and deploying enterprise network defense tools (e.g., IDS/IPS, Packet Capture, SIEM, Proxy, Web Content Filtering).
- Certifications: Prior to Start: Must meet DoD 8140/8570.01-M requirements for IAT Level II (e.g., Security+ CE, CySA+, CCNA Security, GSEC). Within 180 Days: Must obtain a CSSP Analyst certification (e.g., CEH, CySA+, GCIA, GCIH).
- Enterprise Tool & Infrastructure Expertise (Tool-Agnostic): Subject Matter Expertise in the architecture, engineering, and operations of enterprise SIEM platforms (e.g., Splunk, QRadar, ArcSight), endpoint security solutions (e.g., Trellix, MDE, ACAS), and modern security infrastructure (e.g., Taps, IPS, Zero Trust appliances).
- Defensive Cyber Operations (DCO), Threat Hunting & Forensics: Experience executing and supporting DCO training and operations, to include conducting active threat hunts aligned to the MITRE ATT&CK framework, performing forensic analysis (using log data, IDS events, and network PCAP) to reconstruct attack timelines, and delivering actionable threat insights to operational teams.
- Advanced Network Fundamentals & Complex Problem Solving: Deep understanding of network traffic, the OSI model, defense-in-depth principles, and the network threat lifecycle, with a proven ability to resolve highly complex, multi-dimensional technical problems affecting multiple aspects of a program.
- Technical Leadership & Mentorship: Proven experience serving as a technical lead on large, complex projects; with the agility to pivot between multiple initiatives and track them to completion; while supervising, mentoring, and coaching technical staff across various skill levels.
- Executive Communication & Reporting: Exceptional communication skills with the demonstrated ability to draft comprehensive technical reports and brief senior executive leadership (both internal and client-facing) on operational findings and matters of strategic importance.
- Innovation & Technology Integration: Ability to drive the research, fielding, and integration of new security technologies, leading the collaborative development of innovative products and solutions alongside other industry experts.
If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares.
Original Posting:
October 1, 2026For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.
Pay Range:
Pay Range $131,300.00 - $237,350.00The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.
- ...Position Title Lead Monitor Technician Job Description Purpose & Scope: The Lead Monitor Technician is responsible for overseeing the daily operations of both the Cardiac Telemetry Monitoring and Remote Safety Monitoring (Avasys) programs. This role requires...SuggestedRemote work
- ...services millions depends on. Job Description Monitoring & Event Management Team Lead Advance how our customer operates while you advance... ...documentation, and continuous improvement. Manage event detection, validation, correlation, automated ticket generation...SuggestedFor contractors
$26.54 per hour
...Job Description Job Description CORPS: Everett POSITION TITLE: (EVNSC) Everett New Start Center Shelter Monitor Lead STATUS: Regular Full-Time/Non-exempt COMPENSATION: $26.54 REPORTS TO: EVNSC Site Manager This position will support shelter operations...SuggestedFull timeTemporary workLocal areaShift workNight shift- J&J Worldwide Services seeks an experienced RCM Manager to lead a reliability team and drive condition monitoring programs for critical equipment. You will guide data-driven analyses across vibration, thermography, ultrasound, and other CM tools to identify failures and...SuggestedWorldwide
- Apex Systems is seeking an A&A Lead to drive RMF strategy and execution across multiple systems and enclaves. You will develop, review... ...artifacts such as SSP, SAP/SAR, POA&M, and Continuous Monitoring Strategy while managing risk statements for executive audiences...Suggested
- AT&T Global Public Sector is seeking a Consolidated Systems Monitoring Administrator to provide 24x7 monitoring of server and network operations in a strictly on-site role at McLean, VA. The position requires a TS/SCI clearance with polygraph and a rotating Panama schedule...Rotating shift
$63.34 per hour
...Job Description Job Description Monitoring Lead- Application Hosting Location : Washington, DC Type: Contract Compensation : $63.34/h Onsite – onsite Security Clearance : Public Trust Required Overview You’ll lead monitoring for application hosting-...Contract workLocal area$160k - $185k
...protect our nation’s vital interests. Title : Insider Threat Monitoring Lead (CBP) Clearance : Active Top Secret with SCI Eligibility,... ...4: Improve what the program watches for over time Detection logic gets tuned based on what real cases actually looked like...Temporary workImmediate startRelocation package$36 per hour
...POSITION SUMMARY The Alarm Monitor position provides physical security, by monitoring a detection, intrusion monitoring system. Close Circuit TV (CCTV) monitoring; dispatch; visitor processing; and administrative services. PAY TRANSPARENCY $36.00 PER HOUR RESPONSIBILITIES...Hourly payWork at officeFlexible hours- ...Position Title SOC Operations Lead / Managed Detection & Response (MDR) Lead Position Overview The SOC Operations Lead will oversee... ...incident responders, and MDR personnel responsible for security monitoring, alert triage, incident analysis, escalation, containment...Full time
$131.3k - $237.35k
...opportunity for a Security Operations Center (SOC) Lead on the DISA GSM-O program in Alexandria,... ...actions in support of J6 to prevent, detect, respond and recover from adversarial... ...non-compliance reporting, user activity monitoring, and malware and forensic analysis. Furthermore...Contract workWork experience placement$19 - $27.96 per hour
...Cardiac Monitor Tech – Be the Heart of Medically Complex Care BridgePoint Continuing Care Hospital - Capitol Hill | Washington, DC Position... ...rhythm patterns, monitors heart rhythm pattern of patients to detect abnormal pattern variances using telemetry equipment; reviews...Hourly payDaily paidFull timePart timeReliefLive outShift workNight shift- ...Purpose & Scope The Monitor Technician is responsible for the accurate identification of cardiac rhythms and dysrhythmias for all patients on the telemetry monitoring service. He / she must demonstrate the ability to work cooperatively and communicate effectively with...Hourly payShift work
$138k - $209k
...projects that matter, alongside industry‑leading experts, in an environment that fosters... ...incident response teams responsible for detecting, analyzing, containing, and eradicating... ...strategies to strengthen cybersecurity controls, monitoring, and detection capabilities. Design,...Contract workTemporary work- ...access control, credentialing, security monitoring, escort activities, and roving patrol functions... ...CCTV, alarm systems, intrusion detection systems, and access control platforms.... ...Minimum of 1-2 years of supervisory, team lead, or shift lead experience preferred....For contractorsWork at officeShift workRotating shift
- ...Incomplete applications will not be considered. The Department of Parks and Recreation (DPR) is seeking seasonal/temporary Facility Monitors to work in our facilities to support programs and facility operations. Facilities include all community centers and Arlington...Temporary workPart timeSeasonal workWork at officeNight shift
- ...where children grow into joyful and confident learners. About the Role The Goddard School is seeking a dedicated Quality Assurance Monitor to support our commitment to delivering a safe, nurturing, and high-quality early childhood education experience. In this role, you...Weekend work
- PathForward in Arlington, VA is seeking a Part-time/ Seasonal Hypothermia Shelter Monitor to help supervise residents, enforce rules, and support case managers in developing housing plans. This role requires weekend/overnight availability, onboarding trainings, and on-call...Part timeSeasonal workShift workNight shiftWeekend work
$28 per hour
Job Title Location Confidential, Arlington, VA, 22202, United States Base Pay $28.00 / Hour Other Compensation H&W: $5.00/hr Employee Type FT Non-Exempt Description Requirements Summary CenCore LLC- Guidehouse is seeking a Monitoring and Evaluation (M&E) Analyst to support Department of State security assistance programs, with emphasis on FMF and IMET. You will strengthen evidence-based decision-making and improve program oversight across the Bureau’s portfolio. The...Work at office
- Inova Specialty Hospital in Alexandria, VA seeks a Telemetry Technician to monitor patient rhythms and respond to alarms in a fast-paced, inpatient setting. You will perform EKG interpretation, verify rhythm data with nursing staff, and ensure timely escalation when abnormalities...Hourly payFull time
- ...insights related to trends, risks, implementation challenges, and opportunities for enhanced effectiveness. Develop fit‑for‑purpose monitoring frameworks, including drafting indicators, data‑collection strategies, and verification approaches tailored to the specific...Temporary workWork at officeFlexible hours
- ...LLC is seeking a dependable and detail-oriented Dispatch / Alarm Monitor to support security operations at assigned locations. This... ...government assets Responsibilities Monitor CCTV, intrusion detection, fire alarm, duress alarm, and early warning systems....Work at office
$104k - $166k
...Cyber Incident Response Team (CIRT) Shift Lead to join Peratons' Federal Strategic Cyber... ...Tuesday - SaturdayIn this role, you will:Detect, classify, process, track, and report on... ...analyze and respond to events and incidents.Monitor and respond to the CIRT Security...Contract workLocal areaAll shiftsShift workDay shift$107.9k - $195.05k
...and repeatability. Leidos is seeking an Incident Response Lead to join our team on a highly visible cyber security single-award... ...) Support Services is a US Government program responsible to monitor, detect, analyze, mitigate, and respond to cyber threats and adversarial...$165k - $200k
...vital interests. Title : Threat Hunt Lead (CBP) Clearance : Active Top Secret... ...behind that mission are watched by automated detection around the clock, and automated... ...includes host and network-based security monitoring using cybersecurity capabilities. Applicant...Temporary workImmediate startRelocation package- ...responsible for the overall security defense and monitoring of the enterprise environment of... ...assurance program. Experience leading defensive cyber operations teams or coordinating... ...after a cyber-attack ~ Experience detecting and mitigating insider threat ~ Provides...Temporary workWork experience placementLocal areaImmediate start
- ...Description: Seeking an experienced Cross Domain Solution CDS Program Lead to serve as the technical and programmatic lead for the... ...testing of the CDS environment Manage continuous monitoring of the CDS environment Qualifications: ~ Bachelor's of Science...Remote workFlexible hours
- ...Overview We are seeking an experienced Network Operations Shift Lead to support the Compartmented Enterprise Services Office (CESO)... ...shift, providing technical direction to the operations team. Monitor enterprise networks, servers, applications, cloud services, and...Work at officeImmediate startFlexible hoursShift workNight shiftWeekend work
- ...Position Title Insider Threat Program Lead Position Overview The Insider... ...design, mature, and oversee insider threat detection, analysis, and investigative support capabilities... .... The Lead will integrate user activity monitoring, behavioral analytics, threat...Full time
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Detection, Monitoring, & Countermeasures Lead. Be the first to apply!




