Talent.com
No longer accepting applications
Tier 2 Cyber Incident Response Team (CIRT) Analyst

Tier 2 Cyber Incident Response Team (CIRT) Analyst

PeratonBeltsville, MD, United States
13 days ago
Job type
  • Temporary
Job description

Tier 2 Cyber Incident Response Team (CIRT) Analyst

Job Locations

US-MD-Beltsville

Requisition ID

2025-159550

Position Category

Information Technology

Clearance

Secret

Responsibilities

Peraton is seeking an experienced Tier 2 Cyber Incident Response Team (CIRT) Analyst to join Peraton's Department of State (DOS) Diplomatic Security Cyber Mission (DSCM) program, which provides leading cyber and technology security expertise to enable innovative, effective, and secure business processes that protect our nation's diplomatic missions worldwide.

Location : Beltsville, MD

Work Hours : Mids Shift, 2200 - 0600 EST, TUE-SAT.

In this role, you will :

Detect, classify, process, track, and report on cyber security events and incidents.

  • Perform advanced in-depth analysis of coordinated Tier 1 alert triage and requests in a 24x7x365 environment.
  • Analyze logs from multiple sources (e.g., host logs, EDR, firewalls, intrusion detection systems, servers) to identify, contain, and remediate suspicious activity.
  • Characterize and analyze network traffic to identify anomalous activity and potential threats.
  • Protect against and prevent potential cyber security threats and vulnerabilities.
  • Perform forensic analysis of hosts artifacts, network traffic, and email content.
  • Analyze malicious scripts and code to mitigate potential threats.
  • Conduct malware analysis to generate IOCs to identify and mitigate threats.
  • Collaborate with Department of State teams to analyze and respond to events and incidents.
  • Monitor and respond to the CIRT Security Orchestration and Automation Response (SOAR) platform, hotline, email inboxes.
  • Create tickets and initiate workflows as instructed in technical SOPs.
  • Coordinate and report incident information to the Cybersecurity and Infrastructure Security Agency (CISA).
  • Collaborate with other local, national and international CIRTs as directed.
  • Submit alert tuning requests.

#DSCM

Qualifications

Required Qualifications :

  • Bachelor's degree and at least 2 years of experience or a High School diploma and 6 years of experience.
  • Must possess one of the following certifications prior to start date :
  • A+ CE, CCNA-Security, CND, Network+ CE, SSCP, Security+.

  • Demonstrated experience in the Incident Response lifecycle.
  • Knowledge of SOAR ticketing and automated response systems (e.g. ServiceNow, Splunk SOAR, Microsoft Sentinel).
  • Demonstrated experience with using Security Information and Event Management (SIEM) platforms (e.g. Splunk, Microsoft Sentinel, Elastic, Q-Radar).
  • Demonstrated experience in using Endpoint Detection and Response systems (e.g. MDE, ElasticXDR, CarbonBlack, Crowdstrike).
  • Knowledge of cloud security monitoring and incident response.
  • Knowledge of integrating IOCs and Advanced Persistent Threat actors.
  • Ability to analyze cyber threat intelligence reporting and understanding adversary methodologies and techniques.
  • Knowledge of malware analysis techniques.
  • Knowledge of the MITRE ATT&CK and D3FEND frameworks.
  • U.S. Citizenship required.
  • Active Interim Secret clearance in order to start.
  • Preferred Qualifications :

  • Proficiency with Splunk for security monitoring, alert creation, and threat hunting.
  • Knowledge of Microsoft Azure access and identity management.
  • Proficiency with Microsoft Defender for Endpoint and Identity for security monitoring, response, and alert generations.
  • Experience in using digital forensics collection and analysis tools (e.g. Autopsy, MagnetForensics, Zimmerman-Tools, KAPE, CyLR, Volatility).
  • Experience with using ServiceNow SOAR for ticketing and automated response.
  • Knowledge of Python, PowerShell and BASH scripting languages.
  • Experience with cloud security monitoring and incident response.
  • Demonstrated ability to perform static / dynamic malware analysis and reverse engineering.
  • Experience with integrating cyber threat intelligence and IOC-based hunting.
  • Technical certifications such as : Security+, CySA+, Cloud+, Try Hack Me SAL1, Hack the Box CDSA, CyberDefenders, CCD, Azure SC-900, CCSP, GCIH, CCSK, GSEC, CHFI, GCLD, GCIA.
  • Advanced technical certifications such as : SecurityX / CASP+, PRMP, GREM, GEIR, GNFA, or GCFA.
  • Peraton Overview

    Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world's leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains : land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees do the can't be done by solving the most daunting challenges facing our customers. Visit peraton.com to learn how we're keeping people around the world safe and secure.

    Target Salary Range

    $80,000 - $128,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual's experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.

    EEO

    EEO : Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.

    Create a job alert for this search

    Incident Response • Beltsville, MD, United States

    Related jobs
    • Promoted
    Senior IT Security Engineer

    Senior IT Security Engineer

    VirtualVocationsBaltimore, Maryland, United States
    Full-time
    A company is looking for a Senior IT Security Operations Engineer.Key Responsibilities Monitor, detect, analyze, and respond to security events and incidents using various security tools Conduct...Show moreLast updated: 1 day ago
    • Promoted
    Cyber Security Engineer

    Cyber Security Engineer

    ALTA IT ServicesSpringfield, VA, US
    Full-time
    Job Title : Cyber Security Engineer Location : Springfield, VA Type : Contract To Hire Compensation : Contractor Work Model : Onsite Hours : Add the job’s scheduled days and times (delete if not needed) ...Show moreLast updated: 30+ days ago
    • Promoted
    • New!
    Security GRC Analyst

    Security GRC Analyst

    VirtualVocationsBaltimore, Maryland, United States
    Full-time
    A company is looking for a Security GRC Analyst.Key Responsibilities Lead the strategy, execution, and improvement of the compliance program, including assessments and policy documentation Devel...Show moreLast updated: 14 hours ago
    • Promoted
    Network Firewall Engineer

    Network Firewall Engineer

    VirtualVocationsBaltimore, Maryland, United States
    Full-time
    A company is looking for a Network Operations Firewall Engineer.Key Responsibilities Monitor, manage, and support enterprise firewalls and security appliances Implement firewall rule changes, NA...Show moreLast updated: 1 day ago
    • Promoted
    Network Security Engineer

    Network Security Engineer

    Shimadzu Scientific InstrumentsColumbia, MD, United States
    Full-time
    Established in 1975, Shimadzu Scientific Instruments is one of the largest suppliers of analytical instrumentation, physical testing, and environmental monitoring systems in the world.Ground-breaki...Show moreLast updated: 6 days ago
    • Promoted
    Cyber Security Specialist

    Cyber Security Specialist

    VirtualVocationsAlexandria, Virginia, United States
    Full-time
    A company is looking for a Cyber Security Logistics Specialist SME II.Key Responsibilities Reviews and updates system artifacts and develops baseline impact values for medical devices Documents ...Show moreLast updated: 30+ days ago
    • Promoted
    IGA Engineer with Secret Clearance

    IGA Engineer with Secret Clearance

    VirtualVocationsBaltimore, Maryland, United States
    Full-time
    A company is looking for an IGA Engineer with Active Secret Clearance.Key Responsibilities Design and implement Identity Governance and Administration (IGA) solutions within federal organizations...Show moreLast updated: 1 day ago
    • Promoted
    • New!
    SafeTrace Analyst

    SafeTrace Analyst

    VirtualVocationsBaltimore, Maryland, United States
    Full-time
    A company is looking for a SafeTrace Analyst to support Epic's SafeTrace Tx module.Key Responsibilities Support system build, troubleshooting, and reporting for blood product tracking and transfu...Show moreLast updated: 16 hours ago
    • Promoted
    • New!
    Market Intelligence Data Analyst

    Market Intelligence Data Analyst

    VirtualVocationsBaltimore, Maryland, United States
    Full-time
    A company is looking for a Market Intelligence and Data Analyst - Annuities.Key Responsibilities Gather, analyze, model, and present competitive intelligence data to senior management and stakeho...Show moreLast updated: 22 hours ago
    • Promoted
    • New!
    Cyber Security Engineer / ISSO

    Cyber Security Engineer / ISSO

    VirtualVocationsBaltimore, Maryland, United States
    Full-time
    A company is looking for a Cyber Security Engineer / ISSO.Key Responsibilities Perform day-to-day information assurance and system administration duties for Space Force systems Implement and maint...Show moreLast updated: 18 hours ago
    • Promoted
    FIPS 140 Security Engineer

    FIPS 140 Security Engineer

    ALTA IT ServicesColumbia, MD, US
    Permanent
    Job Title : FIPS 140 Security Engineer Location : Columbia, Maryland Type : Contract To Hire Compensation : $62.Contractor Work Model : Remote Security Clearance : No active clearance is required.Citizen...Show moreLast updated: 4 days ago
    • Promoted
    2026 Internship - Cyber Security - Cyber Dominance

    2026 Internship - Cyber Security - Cyber Dominance

    The Johns Hopkins University Applied Physics LaboratoryLaurel, MD, United States
    Temporary +1
    Interested in Cyber? Are you currently pursing a degree in Computer Science, Cybersecurity, Mathematics, or Engineering? Want to apply what you're learning to real world problems?.We are seeking in...Show moreLast updated: 30+ days ago
    • Promoted
    Security DevOps Engineer

    Security DevOps Engineer

    VirtualVocationsBaltimore, Maryland, United States
    Full-time
    A company is looking for a Security DevOps Engineer with expertise in Azure security and compliance.Key Responsibilities Identify and remediate security vulnerabilities in Azure workloads and dev...Show moreLast updated: 1 day ago
    • Promoted
    • New!
    CISSP Security Architect

    CISSP Security Architect

    VirtualVocationsBaltimore, Maryland, United States
    Full-time
    A company is looking for a MeF Security Architect to lead security architecture and serve as the key point of contact for security-related decisions. Key Responsibilities Develop and extend MeF se...Show moreLast updated: 16 hours ago
    • Promoted
    Cybersecurity Program Analyst

    Cybersecurity Program Analyst

    VirtualVocationsBaltimore, Maryland, United States
    Full-time
    A company is looking for a Cyber Program Maturity Analyst Sr Principal.Key Responsibilities Strengthen EPA's Information Security and Privacy Posture by streamlining cybersecurity procedures and ...Show moreLast updated: 30+ days ago
    • Promoted
    SAP Application Security Engineer

    SAP Application Security Engineer

    VirtualVocationsBaltimore, Maryland, United States
    Full-time +1
    A company is looking for an Application Security Engineer with expertise in SAP systems for a short-term contract.Key Responsibilities Assess and strengthen security configurations within SAP ABA...Show moreLast updated: 1 day ago
    • Promoted
    Senior Cloud Security Architect

    Senior Cloud Security Architect

    VirtualVocationsAlexandria, Virginia, United States
    Full-time
    A company is looking for a Senior Information Security Architect (Remote).Key Responsibilities Develop and implement a comprehensive cloud security strategy aligned with organizational goals and ...Show moreLast updated: 30+ days ago
    • Promoted
    • New!
    Workday Security Architect

    Workday Security Architect

    VirtualVocationsAlexandria, Virginia, United States
    Full-time
    A company is looking for a Workday Security Architect to lead the redesign and optimization of a large enterprise Workday security environment. Key Responsibilities Lead design sessions with stake...Show moreLast updated: 16 hours ago
    • Promoted
    Software Security Engineer

    Software Security Engineer

    VirtualVocationsBaltimore, Maryland, United States
    Full-time
    A company is looking for a Software Security Engineer, Experienced or Senior (Virtual).Key Responsibilities Operationalize the open-source policy and process through automation Independently inv...Show moreLast updated: 1 day ago
    • Promoted
    • New!
    Workday Security Analyst

    Workday Security Analyst

    VirtualVocationsBaltimore, Maryland, United States
    Full-time
    A company is looking for a Workday Security Analyst to configure, maintain, and advise on security within the Workday application ecosystem. Key Responsibilities Manage Workday security configurat...Show moreLast updated: 14 hours ago