Leidos

Data Security Engineer

Leidos Adelphi, Maryland, United States · $87K–$157K/yr

Defense and Space Manufacturing · 10,001+ employees

Yesterday
security Senior (5-10 yrs) Full-time United States
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The Data Security Engineer will design, maintain, and optimize scalable cybersecurity data pipelines to support defensive operations. They will also automate workflows and troubleshoot dependencies across Elastic, Kafka, and CI/CD systems to ensure reliable data for threat detection.

What they look for

Data Engineering Cybersecurity Elastic Stack Kafka Python Bash CI/CD Data Ingestion Data Normalization Threat Detection Incident Response Vulnerability Management Cloud Security Elastic Common Schema Automation

Requirements

Candidates must have a bachelor's degree with 4-8 years of experience or equivalent, along with proficiency in data engineering and cybersecurity technologies. The role requires U.S. Citizenship and an active TS/SCI clearance.

Full description

The C5ISR Center Cyber Security Service Provider (CSSP) delivers 24x7x365 defensive cyber operations supporting critical Department of War (DoW) missions. Our team provides continuous monitoring, threat detection, incident response, and vulnerability management across cloud and on-premises environments, including AWS, Azure, GCP, Oracle Cloud, and SaaS platforms.

Leidos is seeking a Data Security Engineer to build, optimize, and sustain the cybersecurity data pipelines that power these defensive operations. You will ingest, normalize, enrich, and manage high-volume security telemetry within Elastic; optimize data performance and quality; automate workflows; and troubleshoot dependencies across Elastic, Kafka, and CI/CD systems. You will partner with cyber teams to ensure analysts and defenders have reliable, analytics-ready data for threat detection and response.

This position is hybrid on-site 3 days/week in Adelphi, Maryland and requires U.S. Citizenship and an active TS/SCI clearance.

Primary Responsibilities:

  • Design, maintain, and optimize scalable cybersecurity data ingestion and normalization pipelines.
  • Develop transformations and enrichments for diverse security log and telemetry sources.
  • Configure and optimize Elasticsearch, Logstash, Kibana, and Fleet for high-volume, high-availability operations.
  • Maintain index templates, mappings, schemas, and data models supporting analytics and detection logic.
  • Implement data validation, deduplication, and quality controls to ensure data integrity.
  • Automate ingestion, transformation, and engineering workflows using Python, Bash, and related tools.
  • Monitor pipeline and indexing performance, troubleshoot data-flow issues, and optimize throughput, storage, and query performance.
  • Maintain traceability and troubleshoot dependencies across Kafka, Elastic, and CI/CD tooling.
  • Partner with Detection Engineering, Threat Analysis, Endpoint, and other cyber teams to support operational requirements.
  • Maintain technical documentation, SOPs, and engineering artifacts.

Basic Qualifications:

  • Bachelor's degree and 4–8 years of relevant experience, or additional experience may substitute in lieu of degree.
  • 3+ years of data engineering, data analysis, cybersecurity data engineering, or related experience.
  • Experience with data ingestion, transformation, normalization, or high-volume data-processing pipelines.
  • Experience with relevant technologies such as Elastic Stack, Kafka, Python, Bash, and CI/CD tooling.
  • Familiarity with Elastic Common Schema (ECS) or similar cybersecurity data models.
  • Required DoD 8570/8140-aligned and CSSP Analyst certifications, as applicable to the position.
  • U.S. Citizenship with an active TS/SCI clearance.
  • Strong written and verbal communication skills.

Preferred Qualifications:

  • Experience onboarding and normalizing high-volume cybersecurity telemetry and log sources.
  • Experience with Kafka, Python/Bash automation, CI/CD, or DevSecOps practices.
  • Experience supporting AWS, Azure, GCP, Oracle Cloud, hybrid-cloud, or multi-cloud environments.
  • Knowledge of cybersecurity operations, including SIEM, threat detection, incident response, and security monitoring.
  • Experience supporting a DoD CSSP, SOC, or other large-scale defensive cyber operations environment.
  • Strong troubleshooting skills across complex data pipelines and interconnected systems.

If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares.

Original Posting:

August 13, 2026

For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

Pay Range:

Pay Range $87,100.00 - $157,450.00

The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

Similar roles