×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

Endpoint Security Analyst – Elastic Defend

Job in Hyattsville, Prince George's County, Maryland, 20783, USA
Listing for: Leidos
Full Time position
Listed on 2026-08-30
Job specializations:
  • IT/Tech
    Cybersecurity
Job Description & How to Apply Below

Endpoint Security Analyst

The C5

ISR Center Cyber Security Service Provider (CSSP) is a premier defensive cyber operations organization supporting the Department of War (DoW). Operating 24x7x365, the CSSP provides continuous monitoring, threat detection, incident response, and vulnerability management across cloud and on-premises environments, including AWS, Azure, GCP, Oracle Cloud, and SaaS platforms.

Every day, our team protects the networks, systems, and data that enable critical DoW missions.

Leidos has an immediate opportunity for an experienced Endpoint Security Analyst to support a highly visible, strategic Cybersecurity Task Order. In this role, you will provide specialized expertise supporting Elastic Agent and Elastic Defend, helping deploy, configure, optimize, and sustain endpoint protection, telemetry collection, threat detection, and automated response capabilities across the enterprise.

You will work closely with threat, engineering, and cybersecurity operations teams to strengthen endpoint defenses, improve visibility, and rapidly identify and respond to emerging cyber threats.

Location:

Hybrid - 3 days on site at Adelphi, MD

Clearance: U.S. Citizenship with an active TS/SCI with SAP Eligibility

Primary Responsibilities:
  • Deploy, configure, operate, tune, upgrade, and troubleshoot Elastic Agent, Elastic Defend, and other enterprise endpoint security technologies.
  • Optimize endpoint protection and telemetry collection to maximize security visibility and detection effectiveness while minimizing operational and system performance impacts.
  • Partner with Threat and Detection teams to customize detection rules, develop threat signatures, and align endpoint defenses with emerging threat intelligence and MITRE ATT&CK techniques.
  • Conduct host-based defensive cyber operations to identify, investigate, contain, mitigate, and remediate vulnerabilities and intrusions.
  • Support cyber investigations using advanced endpoint queries, forensic data collection, and rapid containment and response capabilities.
  • Build and maintain queries, dashboards, and reports that provide enterprise security visibility and leadership awareness.
  • Coordinate with engineering teams on endpoint security deployments, patches, hot fixes, upgrades, and other critical security updates.
  • Troubleshoot endpoint security tool issues, performance concerns, and outages.
  • Develop and maintain endpoint security policies, configurations, and Standard Operating Procedures (SOPs).
  • Evaluate emerging endpoint security tools, techniques, and technologies and recommend improvements aligned with enterprise cybersecurity strategy.

Basic Qualifications:

  • Bachelor's degree in Science, Technology, Engineering, Mathematics (STEM), cybersecurity, or a related field and 4+ years of relevant cybersecurity experience.
  • Hands-on experience deploying, configuring, operating, or supporting enterprise endpoint security or EDR solutions.
  • Strong understanding of endpoint protection, security telemetry, threat detection, incident investigation, and response.
  • Experience investigating and responding to endpoint security alerts and potential compromises.
  • Knowledge of current cyber threats, attacker techniques, and defensive strategies, including familiarity with the MITRE ATT&CK framework.
  • Strong analytical, troubleshooting, and problem-solving skills.
  • Ability to work effectively across cybersecurity, threat, and engineering teams.
  • Strong written and verbal communication skills.
  • U.S. citizenship and an active TS/SCI with SAP eligibility.
  • At least one of the following certifications :
    • GIAC/SANS: GCIA, GCIH, GCFA, GCFE, GREM, GISF, GXPN, GWEB, GNFA, or GMON
    • Offensive Security: OSCP, OSCE, OSWP, or OSEE
    • ISC2: CCFP or CISSP
    • EC-Council: CEH, CHFI, LPT, ECSA, or ECI

Preferred Qualifications:

  • Hands-on experience with Elastic Agent and Elastic Defend, including deployment, configuration, policy management, tuning, and troubleshooting.
  • Experience optimizing endpoint telemetry and security controls in large-scale enterprise environments.
  • Experience developing or tuning endpoint detection rules, threat signatures, IOCs, and behavioral detections.
  • Experience using Elastic capabilities for endpoint…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary