Tier 2 Cyber Incident Response Team (CIRT) Analyst
Responsibilities
Peraton is seeking an experienced Tier 2 Cyber Incident Response Team (CIRT) Analyst to join Peraton's Department of State (DoS) Diplomatic Security Cyber Mission (DSCM) program, which provides leading cyber and technology security expertise to enable innovative, effective, and secure business processes that protect our nation's diplomatic missions worldwide.
Location: Beltsville, MD and Rosslyn, VA
Work Hours: Days Shift 0600 – 1400 EST, TUE-SAT
In this role, you will:
- Detect, classify, process, track, and report on cyber security events and incidents.
- Perform advanced in-depth analysis of coordinated Tier 1 alert triage and requests in a 24x7x365 environment.
- Analyze logs from multiple sources (e.g., host logs, EDR, firewalls, intrusion detection systems, servers) to identify, contain, and remediate suspicious activity.
- Characterize and analyze network traffic to identify anomalous activity and potential threats.
- Protect against and prevent potential cyber security threats and vulnerabilities.
- Perform forensic analysis of hosts artifacts, network traffic, and email content.
- Analyze malicious scripts and code to mitigate potential threats.
- Conduct malware analysis to generate IOCs to identify and mitigate threats.
- Collaborate with Department of State teams to analyze and respond to events and incidents.
- Monitor and respond to the CIRT Security Orchestration and Automation Response (SOAR) platform, hotline, email inboxes.
- Create tickets and initiate workflows as instructed in technical SOPs.
- Coordinate and report incident information to the Cybersecurity and Infrastructure Security Agency (CISA).
- Collaborate with other local, national and international CIRTs as directed.
- Submit alert tuning requests.
#DSCM
Qualifications
Required:
- Bachelor's degree and a minimum of 2 years of relevant experience, or a High School diploma and 6 years of relevant experience.
- Must possess at least one of the following certifications prior to start date:
- CCNA-Security, CND, CySA+, GICSP, GSEC, Security+ CE, or SSCP
- Demonstrated experience in the Incident Response lifecycle.
- Knowledge of SOAR ticketing and automated response systems (e.g. ServiceNow, Splunk SOAR, Microsoft Sentinel).
- Demonstrated experience with using Security Information and Event Management (SIEM) platforms (e.g. Splunk, Microsoft Sentinel, Elastic, Q-Radar).
- Demonstrated experience in using Endpoint Detection and Response systems (e.g. MDE, ElasticXDR, CarbonBlack, Crowdstrike).
- Knowledge of cloud security monitoring and incident response.
- Knowledge of integrating IOCs and Advanced Persistent Threat actors.
- Ability to analyze cyber threat intelligence reporting and understanding adversary methodologies and techniques.
- Knowledge of malware analysis techniques.
- Knowledge of the MITRE ATT&CK and D3FEND frameworks.
- U.S. citizenship required.
- Active Interim Secret clearance in order to start.
Preferred Qualifications:
- Proficiency with Splunk for security monitoring, alert creation, and threat hunting.
- Knowledge of Microsoft Azure access and identity management.
- Proficiency with Microsoft Defender for Endpoint and Identity for security monitoring, response, and alert generations.
- Experience in using digital forensics collection and analysis tools (e.g. Autopsy, MagnetForensics, Zimmerman-Tools, KAPE, CyLR, Volatility).
- Experience with using ServiceNow SOAR for ticketing and automated response.
- Knowledge of Python, PowerShell and BASH scripting languages.
- Experience with cloud security monitoring and incident response.
- Demonstrated ability to perform static/dynamic malware analysis and reverse engineering.
- Experience with integrating cyber threat intelligence and IOC-based hunting.
- Technical certifications such as: Security+, CySA+, Cloud+, Try Hack Me SAL1, Hack the Box CDSA, CyberDefenders, CCD, Azure SC-900, CCSP, GCIH, CCSK, GSEC, CHFI, GCLD, GCIA.
- Advanced technical certifications such as: SecurityX/CASP+, PRMP, GREM, GEIR, GNFA, or GCFA.
Peraton Overview
Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world’s leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees do the can’t be done by solving the most daunting challenges facing our customers. Visit peraton.com to learn how we’re keeping people around the world safe and secure.
Target Salary Range
$80,000 - $128,000. This represents the typical salary range for this position based on experience and other factors.
EEO
EEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.
Recommended Jobs
Helper
Job Description Job Description Company Overview: Patriot Disposal is the area’s leading waste company, providing essential services to our communities year-round. As a fast-growing company with…
Ship Fitter (Local Only)
Job Description Job Description Hutco, Inc. Position: Shipfitter J3 - J4 (Local Only) Location: Norfolk, VA Shift: ALL Shifts (Five openings for 1st Shift: 6:00 AM – 2:45 PM, with a 45…
Logistician - Navy Ship Repair
Job Description Job Description CTR Group is seeking a Logistician for a Navy Ship Repair Contractor in the Virginia Beach, VA area. Must have DoD clearance or be clearance eligible. PAY RA…
Senior SAR Integration Engineer
Responsibilities Overview: We are seeking an experienced Senior SAR Integration Engineer to lead enterprise-level integration efforts across mission-critical programs. This role focuses on ens…
HVAC Manufacturing Opportunities
Job Description Job Description DMI Companies/Linx Industries, 2600 Airline Blvd, Portsmouth, VA 23701 COMPANY PROFILE DMI Companies, founded in 1978, is a leading manufacturer of HVAC acces…
Operations Associate
Sephora is seeking an Operations Associate in Richmond, United States. This part-time role requires ensuring smooth store operations, accurate order fulfillment, and maintaining inventory. Ideal candi…
Crisis Stabilization Specialist (Licensed QMHP)
Location: Richmond, VA 23224 Date Posted: 07/30/2025 Category: Community Based Education: Bachelor's Degree With over 35 years in business, the Delta- T Group has built a reputation for ref…
Operations Manager
Job Summary: The Operations Manager will be responsible for managing the accounting processes, office operations, and human resources functions. This role combines financial oversight with administr…
Sheet Metal Mechanic - Commercial Construction
Job Description Job Description At ACI we build our company and our culture not by counting people, but by making our people count! Atlantic Constructors is seeking dynamic, motivated, career …
Veterinarian
Animal Medical Care Center , located in Yorktown, Virginia , is actively seeking a GP, Small Animal Veterinarian to join our team! Do you have the desire to grow & build within a practice? …