Full-Time

Insider Threat & Cyber Forensics SME

Posted on 8/8/2025

Leidos

Leidos

10,001+ employees

Defense, intelligence, and civil IT solutions

Compensation Overview

$126.1k - $227.9k/yr

No H1B Sponsorship

Ashburn, VA, USA

In Person

US Top Secret Clearance Required

Category
IT & Security (1)
Required Skills
Linux/Unix
Requirements
  • Requires BS degree and 12 or more years of direct relevant experience.
  • Degree in computer science, IT, Information/Cyber Security field from an accredited college or university.
  • Flexible and adaptable self-starter with strong relationship-building skills
  • Effective communication skills with emphasis on attention to detail, ability to accurately capture and document technical remediation details, and ability to brief stakeholders on incident statuses, recovery and root causes.
  • Demonstrable experience performing forensic analysis, digital media analysis, and in-depth system & network log analysis in support of forensic investigations.
  • Ability to generate forensically sound cyber analysis reports detailing forensically sound analysis procedures, findings, and recommendations from incident investigations.
  • Strong problem-solving abilities with an analytic and qualitative eye for reasoning under pressure.
  • Ability to independently prioritize and complete multiple tasks with little to no supervision.
  • Must be a US Citizen
Responsibilities
  • Provide support to CBP OIT’s Cyber Defense Forensics (CDF) team in support of insider threat and security operations according to established policies, handbooks, and CBP CDF Standard Operating Procedures (SOPs).
  • Monitor activities, conduct threat analysis, investigate policy violations, identify mitigation and/or remediation courses of action, and assess risk posed by trusted insiders.
  • Work with the OIT tools to process incidents, investigate potential insider threats, spillages of multiple types of classified and/or controlled data, conduct root cause analyses into suspicious or malicious activity, and assist with SOC incidents / OPR investigations as needed.
  • Conduct formal digital forensic investigations supporting insider threat investigations and document findings in formal, forensically sound investigation reports.
  • Provide recommendations for Information Spillage Incident Response efforts on handling and sanitization methods pursuant to industry best practices, NIST 800-88 recommendations, and Federal guidelines.
  • Conduct enterprise and system(s) endpoint analysis (e.g., Windows, Linux, Mac, Cloud, and mobile systems) and network based digital forensic analysis.
  • Perform email hygiene activities in support of CBP investigations.
  • Support enterprise recovery efforts as necessary to ensure that security events and incidents are properly remediated prior to restitution.
  • Utilize state of the art forensic tools(FTK/Encase,etc.) to perform computer, mobile phone forensics and memory analysis (volatility, rekall) in support of incident response.
  • Conduct reverse engineering of suspicious files utilizing dynamic, automated and static analysis.
  • Properly preserve evidence, maintain chain of custody and write malware analysis or forensic reports.
  • Recognize attacker and APT activity, tactics, and procedures (TTPs) and Indicators of Compromise (IOCs) that can be used to improve monitoring, analysis, and incident response.
  • Install, secure, maintain and recommend forensic software and hardware within a Forensic Lab environment while following established configuration management processes.
  • Develop and build security content, scripts, tools, or methods to enhance forensic processes and insider threat investigations.
  • Effectively investigate and identify root cause findings then communicate findings to stakeholders including technical staff, and leadership.
  • Develop and maintain Standard Operating Procedures (SOPs) and playbooks as deemed necessary.
Desired Qualifications
  • SANS GREM certification
  • Previous experience contributing to or leading insider threat investigations in support of Federal Government, DOD, or Law Enforcement environments.
  • Experience performing computer forensics in Federal Government, DOD or Law Enforcement environments.
  • Ability to script in one more of the following computer languages Python, Bash, Visual Basic or PowerShell.
  • Knowledge of the Cyber Kill Chain and MITRE ATT&CK framework
  • Advanced understanding of multiple Operating Systems, monitoring and detection techniques and methods, and Incident Response Lifecycle.
  • Prior experience with CBP/DHS
  • Between 2-3 years of experience in two or more of these specialized areas: Insider Threat, Digital Media Forensics, Incident Response

Leidos is a large technology and engineering company that serves defense, intelligence, healthcare, and civil government customers. It provides scientific, engineering, and IT solutions to help ensure safety, health, and efficiency, from upgrading air traffic control to strengthening cybersecurity for critical missions. The company delivers integrated systems and services—software, research, cyber defense, and digital modernization—through programs that span government and commercial clients. Leidos stands out through its long history as SAIC’s split-off and rapid growth via major acquisitions, creating a broad, mission-focused portfolio across defense, space, intelligence, and civilian sectors. Its overarching goal is to help customers solve hard problems with advanced technology, enabling safer operations and better public services.

Company Size

10,001+

Company Stage

IPO

Headquarters

Reston, Virginia

Founded

1969

Simplify Jobs

Simplify's Take

What believers are saying

  • Leidos won $2.7B US Army hypersonic weapons contract in 2026 accelerating production.
  • Leidos secured $869M AI contract for battlefield decision-making across domains.
  • Leidos raised 2026 revenue guidance to $18.2B after Q1 $4.4B beat.

What critics are saying

  • Amadeus acquires Idemia PS for $1.4B, disrupting Leidos biometric partnership within 6 months.
  • CFIUS blocks Hanwha Ocean partnership, forfeiting Leidos multi-billion Navy contracts in 12 months.
  • TSA diverts $12B funds, delaying Leidos eGates deployments and causing revenue shortfalls in 3 months.

What makes Leidos unique

  • Leidos' Gibbs & Cox designed 70% of U.S. Navy surface combatants since WWII.
  • Leidos merged with Lockheed Martin IS&GS in 2016, creating largest defense IT provider.
  • Leidos originated as employee-owned SAIC founded by J. Robert Beyster in 1969.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Medical, dental, & vision insurance

Health Savings account

Income protection

PTO

Paid parental leave

Jury duty pay

Bereavement leave

401(k) Retirement Plan

Employee Stock Purchase Plan

Family Benefits

Company News

Yahoo Finance
Mar 31st, 2026
Leidos raises $1.39B in notes to fund Entrust acquisition, secures $454.9M Air Force cloud contract

Leidos Holdings raised $1.39 billion through senior notes maturing in 2029 and 2036 to fund its acquisition of KENE Parent, the owner of Entrust. The notes include a special mandatory redemption clause at 101% of principal if the transaction isn't completed by mid-August 2026. The Virginia-based defence and technology company also secured a $454.9 million contract to modernise the US Air Force's Cloud One platform, partnering with Amazon and Google to enhance security and automation. Founded in 1969, Leidos serves defence, intelligence, civil and health markets, offering solutions in cybersecurity, data analytics and systems engineering. The company maintains strategic flexibility to use the note proceeds for general corporate purposes if needed.

Stock Titan
Mar 30th, 2026
Leidos (NYSE: LDOS) doubles energy reach with $2.4B Entrust deal.

Leidos (NYSE: LDOS) doubles energy reach with $2.4B Entrust deal. Filing Impact Filing Sentiment Rhea-AI Filing summary. Leidos Holdings, Inc., through its subsidiary Leidos, Inc., has completed its acquisition of KENE Parent, Inc., known as ENTRUST Solutions Group, for $2,400,000,000 in cash under a previously announced Stock Purchase Agreement. The deal transfers all issued and outstanding Entrust shares to Leidos, with the price subject to customary cash, debt, expense and net working capital adjustments. ENTRUST adds more than 3,100 professionals focused on electric grid engineering and natural gas infrastructure and effectively doubles Leidos' presence in the energy infrastructure market. Leidos highlights that ENTRUST broadens its power delivery engineering capabilities, expands its base of utility customers, and supports the energy growth pillar of its NorthStar 2030 strategy. Leidos reported approximately $17.2 billion in annual revenue for the fiscal year ended January 2, 2026. Insights. Leidos closes a sizable, strategic $2.4B energy infrastructure acquisition. The company has finalized its all-cash $2,400,000,000 purchase of ENTRUST Solutions Group, acquiring all outstanding shares under a Stock Purchase Agreement. ENTRUST brings more than 3,100 specialists in electric grid and natural gas infrastructure, immediately expanding Leidos' capabilities and customer reach in utility markets. Management states the deal effectively doubles Leidos' presence in the energy infrastructure market and supports the energy growth pillar of its NorthStar 2030 strategy. With Leidos reporting about $17.2 billion in annual revenue for the year ended January 2, 2026, this is a meaningful bolt-on transaction, though financial accretion, synergies and integration progress are not quantified in this disclosure. 8-K event classification. 4 items: 1.01, 2.01, 7.01, 9.01 03/30/2026 - 06:09 AM Faq. What did Leidos (LDOS) acquire in this 8-K filing? Leidos, through its subsidiary, acquired all outstanding shares of KENE Parent, Inc., known as ENTRUST Solutions Group. ENTRUST provides engineering, consulting, design and data solutions for utilities and operators, strengthening Leidos' energy infrastructure and grid modernization capabilities across North America. How much did Leidos (LDOS) pay to acquire ENTRUST Solutions Group? Leidos paid approximately $2,400,000,000 in cash to acquire ENTRUST, with the price subject to customary adjustments for cash, debt, transaction expenses and net working capital. The consideration is all-cash and transfers all issued and outstanding shares of ENTRUST to Leidos' subsidiary. When did Leidos (LDOS) complete the ENTRUST acquisition? Leidos completed the ENTRUST acquisition on March 27, 2026, when its subsidiary closed the previously announced Stock Purchase Agreement. A related press release dated March 30, 2026, announced the closing and described how the deal fits within Leidos' long-term NorthStar 2030 energy strategy. How does the ENTRUST acquisition affect Leidos' energy infrastructure business? The acquisition effectively doubles Leidos' presence in the energy infrastructure market by adding more than 3,100 professionals with electric grid and natural gas expertise. It broadens power delivery engineering capabilities and expands Leidos' utility customer base, supporting its energy-focused growth pillar. How large is Leidos compared with the ENTRUST transaction value? Leidos reported approximately $17.2 billion in annual revenue for the fiscal year ended January 2, 2026. Against this backdrop, the roughly $2.4 billion all-cash ENTRUST acquisition represents a significant but not transformational investment in its energy infrastructure strategy. Filing exhibits & attachments. 4 documents Press releases.

GovCon Wire
Mar 27th, 2026
Christopher Craige joins Leidos as VP, USAF strategic account executive.

Christopher Craige joins Leidos as VP, USAF strategic account executive. The latest appointment at Leidos underscores the growing focus on strengthening Air Force partnerships and advancing air and space priorities across the defense sector. Attend the 2026 Air and Space Summit to join the conversation shaping next-generation air and space capabilities. Register now! In a LinkedIn post, the company said Craige will help strengthen its relationship with the Department of the Air Force and support air and space strategic initiatives. Who is christopher Craige? Craige most recently served as chief operating officer at Business Executives for National Security. He is a distinguished graduate of the U.S. Air Force Academy with over three decades of leadership experience. He served as a command pilot flying the F-15E, C-130 and MC-12, including combat operations in Iraq and Afghanistan. He held senior roles across joint service commands and worked with military branches, federal agencies and congressional stakeholders. He commanded operations at Incirlik Air Base in Turkey during NATO's response to the Syrian civil war and later led an Air Expeditionary Wing in Kabul, Afghanistan. Craige also served as a combatant command strategist focused on Africa, chief of staff for a major command overseeing Europe and Africa operations, and the Air Force's military aide to the vice president. How does Leidos support Air Force operations? Leidos supports the Air Force through cloud modernization, managed IT services and mission systems support. The company secured a task order worth up to $455 million to provide Cloud One architecture and shared services. In addition, Leidos won a $149 million contract from the service to provide managed services for Project Night Owl, including network, application, infrastructure and security support for a critical national security system. The company has also partnered with the Air Force to launch an IT help desk facility at the Pentagon.

Condé Nast
Mar 12th, 2026
DOGE operative accused of taking Social Security data to $1.5B contractor job

John Solly, a former Department of Government Efficiency operative, has been identified as the individual accused in a whistleblower complaint of planning to share sensitive Social Security Administration data with his new employer. Multiple sources confirmed Solly's identity to WIRED. Since October, Solly has served as chief technology officer for the health IT division of government contractor Leidos, which holds contracts with SSA potentially worth up to $1.5 billion. The complaint alleges Solly told colleagues he stored SSA's Numerical Identification System and death master file data on a thumb drive and sought help transferring it to a personal computer. Solly, through legal counsel, denied any wrongdoing. Leidos also stated it found no evidence supporting the allegations. At SSA, Solly supported DOGE initiatives including Digital SSN and death master file cleanup.

Airforce Technology
Mar 12th, 2026
Leidos secures $454.9m contract to modernise USAF Cloud One platform

Leidos secures $454.9m contract to modernise USAF Cloud One platform. Leidos will partner with AWS, Azure, Google Cloud, and Oracle to modernise the US Air Force's multi-cloud environment. Leidos has secured a $454.9m contract to upgrade the US Air Force's Cloud One platform, a central technology resource supporting mission-critical operations across the Department of Defense (DoD). The initiative involves collaboration with major cloud service providers, including Amazon Web Services (AWS), Microsoft Azure, Google Cloud Platform, and Oracle Cloud Infrastructure. The project aims to enhance the security and automation of the platform while streamlining operations and reducing costs for Air Force teams managing cloud environments. According to Leidos, these improvements are expected to facilitate quicker management of cloud operations and simplify the adoption and scaling of cloud services across additional Air Force units. The Cloud One programme aims to accelerate cloud adoption throughout the Air Force globally, bolster cyber defences, and support operational readiness. Leidos digital modernisation division president Steve Hull said: "Modernising Cloud One helps the Air Force deploy mission-critical operations faster and defend them more effectively. It also creates a secure, repeatable cloud foundation that other Department of War organisations can adopt, helping to remove barriers to cloud adoption and enabling teams to move faster and more securely to help meet mission demands and maintain a strategic edge." GlobalData Strategic Intelligence US tariffs are shifting - will you react or anticipate? Don't let policy changes catch you off guard. Stay proactive with real-time data and expert analysis. By GlobalData Cloud One serves as the primary platform providing secure access to cloud technologies and services from leading vendors such as AWS, Microsoft Azure, Oracle Cloud Infrastructure, and Google Cloud. Within this programme, Leidos provides solutions that facilitate the Air Force's move to cloud-based systems. The company states that this project is consistent with its NorthStar 2030 strategy, which prioritises large-scale technology and cybersecurity modernisation efforts for the federal government. Last month, Oracle received an $88m firm-fixed price task order from the US Department of the Air Force to supply Oracle Cloud Infrastructure services specifically for the programme.

INACTIVE