Tier 2 Cyber Incident Response Team (CIRT) Analyst

Peraton
Arlington, VA

Program Overview

Encompasses technical, engineering, data analytics, cyber security, management, operational, logistical, and administrative support for Bureau of Diplomatic Security, Cyber and Technology Security Directorate in three key offices/functional areas: Cyber Monitoring and Operations, Cyber Threat and Investigations, and Technology Innovation and Engineering State.

About The Role

Peraton is seeking an experienced Tier 2 Cyber Incident Response Team (CIRT) Analyst to join Peraton's Department of State (DoS) Diplomatic Security Cyber Mission (DSCM) program, which provides leading cyber and technology security expertise to enable innovative, effective, and secure business processes that protect our nation's diplomatic missions worldwide.

Location: Beltsville, MD and Rosslyn, VA

Work Hours: Days Shift 0600 – 1400 EST, TUE-SAT

In this role, you will:

  • Detect, classify, process, track, and report on cyber security events and incidents.
  • Perform advanced in-depth analysis of coordinated Tier 1 alert triage and requests in a 24x7x365 environment.
  • Analyze logs from multiple sources (e.g., host logs, EDR, firewalls, intrusion detection systems, servers) to identify, contain, and remediate suspicious activity.
  • Characterize and analyze network traffic to identify anomalous activity and potential threats.
  • Protect against and prevent potential cyber security threats and vulnerabilities.
  • Perform forensic analysis of hosts artifacts, network traffic, and email content.
  • Analyze malicious scripts and code to mitigate potential threats.
  • Conduct malware analysis to generate IOCs to identify and mitigate threats.
  • Collaborate with Department of State teams to analyze and respond to events and incidents.
  • Monitor and respond to the CIRT Security Orchestration and Automation Response (SOAR) platform, hotline, email inboxes.
  • Create tickets and initiate workflows as instructed in technical SOPs.
  • Coordinate and report incident information to the Cybersecurity and Infrastructure Security Agency (CISA).
  • Collaborate with other local, national and international CIRTs as directed.
  • Submit alert tuning requests.

#DSCM

Qualifications

Required:

  • Bachelor's degree and a minimum of 2 years of relevant experience, or a High School diploma and 6 years of relevant experience.
  • Must possess at least one of the following certifications prior to start date:
    • CCNA-Security, CND, CySA+, GICSP, GSEC, Security+ CE, or SSCP
  • Demonstrated experience in the Incident Response lifecycle.
  • Knowledge of SOAR ticketing and automated response systems (e.g. ServiceNow, Splunk SOAR, Microsoft Sentinel).
  • Demonstrated experience with using Security Information and Event Management (SIEM) platforms (e.g. Splunk, Microsoft Sentinel, Elastic, Q-Radar).
  • Demonstrated experience in using Endpoint Detection and Response systems (e.g. MDE, ElasticXDR, CarbonBlack, Crowdstrike).
  • Knowledge of cloud security monitoring and incident response.
  • Knowledge of integrating IOCs and Advanced Persistent Threat actors.
  • Ability to analyze cyber threat intelligence reporting and understanding adversary methodologies and techniques.
  • Knowledge of malware analysis techniques.
  • Knowledge of the MITRE ATT&CK and D3FEND frameworks.
  • U.S. citizenship required.
  • Active Interim Secret clearance in order to start.

Preferred Qualifications:

  • Proficiency with Splunk for security monitoring, alert creation, and threat hunting.
  • Knowledge of Microsoft Azure access and identity management.
  • Proficiency with Microsoft Defender for Endpoint and Identity for security monitoring, response, and alert generations.
  • Experience in using digital forensics collection and analysis tools (e.g. Autopsy, MagnetForensics, Zimmerman-Tools, KAPE, CyLR, Volatility).
  • Experience with using ServiceNow SOAR for ticketing and automated response.
  • Knowledge of Python, PowerShell and BASH scripting languages.
  • Experience with cloud security monitoring and incident response.
  • Demonstrated ability to perform static/dynamic malware analysis and reverse engineering.
  • Experience with integrating cyber threat intelligence and IOC-based hunting.
  • Technical certifications such as: Security+, CySA+, Cloud+, Try Hack Me SAL1, Hack the Box CDSA, CyberDefenders, CCD, Azure SC-900, CCSP, GCIH, CCSK, GSEC, CHFI, GCLD, GCIA.
  • Advanced technical certifications such as: SecurityX/CASP+, PRMP, GREM, GEIR, GNFA, or GCFA.

SCA / Union / Intern Rate or Range

Details

Target Salary Range: $80,000 - $128,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual’s experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.

EEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.

Posted 2025-08-27

Recommended Jobs

Early Childhood -Lead Preschool Teacher/ Lead Pre-K Teacher

Lightbridge Academy of Virginia Beach
Virginia Beach, VA

Job Description Job Description Summary The Teacher is responsible for developing a cohesive teaching team, coordinating the curriculum, and managing the day-to-day operational activities of…

View Details
Posted 2025-07-25

Cyber Security Specialist

3tg Staffing Solutions
Fort Belvoir, VA

We are seeking a dedicated and experienced Cybersecurity Specialist to join our proactive and mission-driven team at Fort Belvoir, VA. This role is critical in safeguarding our program office’s cyber…

View Details
Posted 2025-09-12

Project Accountant

Vertical Mechanical Group Inc
Sterling, VA

Job Description Job Description Project Accountant At Vertical Mechanical Group (VMG), we are always seeking talented individuals to join our growing team. Our commitment to exceptional custom…

View Details
Posted 2025-09-09

Industrial Master Electrician

Inframark
Hampton, VA

Inframark is a proudly independent, American-owned leader in Water Infrastructure Operations and Management Services. With a team of over 3,000 dedicated professionals, we partner with municipalitie…

View Details
Posted 2025-08-19

HCM Consultant

Resource 1 LLC
Richmond, VA

HCM / PEO business consultant needed for fast-growing provider of HR administration, payroll, and benefits. The Business Consultant will generate new opportunities through networking and using channe…

View Details
Posted 2025-08-29

Warehouse Janitorial Associate

Kellermeyer Bergensons Services
Suffolk, VA

Job Description Job Description Kellermeyer Bergensons Services (KBS) has immediate full-time, permanent openings to join our Warehouse Cleaning/Janitorial crew in Suffolk, VA. If you enjoy wor…

View Details
Posted 2025-08-18

Community Liaison Home Care (Falls Church, VA)

BG healthcare Service
Falls Church, VA

Job Description Job Description Benefits: ~401(k) ~ Bonus based on performance ~ Health insurance ~ Paid time off BG Healthcare Services is seeking a passionate, driven Community Lia…

View Details
Posted 2025-07-28

Technical Lead

Nationwide IT Services
Virginia

Technical Lead Location: US Coast Guard Yard, Baltimore, Maryland Employment Type: Full-Time / 100% On-Site Clearance: Ability to pass a basic background check About the Role Nationwide …

View Details
Posted 2025-08-29

Pediatric Speech Language Pathologist - Daleville

CORA Physical Therapy
Daleville, VA

Speech Language Pathologist - Pediatrics (Full-Time/Part-Time/PRN)   Grow Your Career. Make a Difference. Thrive in Outpatient Care. Looking to build a meaningful career as a Speech Langua…

View Details
Posted 2025-08-07

Laboratory Assistant

Phlow Corp.
Richmond, VA

Job Description Job Description Description: This role contributes to Phlow's mission by supporting laboratory work related to analytical chemistry and process development. The position involves…

View Details
Posted 2025-08-18