Talent.com
No se aceptan más aplicaciones
Tier 2 Cyber Incident Response Team (CIRT) Analyst

Tier 2 Cyber Incident Response Team (CIRT) Analyst

PeratonBeltsville, MD, United States
Hace 12 días
Tipo de contrato
  • Temporal
Descripción del trabajo

Tier 2 Cyber Incident Response Team (CIRT) Analyst

Job Locations

US-MD-Beltsville

Requisition ID

2025-159550

Position Category

Information Technology

Clearance

Secret

Responsibilities

Peraton is seeking an experienced Tier 2 Cyber Incident Response Team (CIRT) Analyst to join Peraton's Department of State (DOS) Diplomatic Security Cyber Mission (DSCM) program, which provides leading cyber and technology security expertise to enable innovative, effective, and secure business processes that protect our nation's diplomatic missions worldwide.

Location : Beltsville, MD

Work Hours : Mids Shift, 2200 - 0600 EST, TUE-SAT.

In this role, you will :

Detect, classify, process, track, and report on cyber security events and incidents.

  • Perform advanced in-depth analysis of coordinated Tier 1 alert triage and requests in a 24x7x365 environment.
  • Analyze logs from multiple sources (e.g., host logs, EDR, firewalls, intrusion detection systems, servers) to identify, contain, and remediate suspicious activity.
  • Characterize and analyze network traffic to identify anomalous activity and potential threats.
  • Protect against and prevent potential cyber security threats and vulnerabilities.
  • Perform forensic analysis of hosts artifacts, network traffic, and email content.
  • Analyze malicious scripts and code to mitigate potential threats.
  • Conduct malware analysis to generate IOCs to identify and mitigate threats.
  • Collaborate with Department of State teams to analyze and respond to events and incidents.
  • Monitor and respond to the CIRT Security Orchestration and Automation Response (SOAR) platform, hotline, email inboxes.
  • Create tickets and initiate workflows as instructed in technical SOPs.
  • Coordinate and report incident information to the Cybersecurity and Infrastructure Security Agency (CISA).
  • Collaborate with other local, national and international CIRTs as directed.
  • Submit alert tuning requests.

#DSCM

Qualifications

Required Qualifications :

  • Bachelor's degree and at least 2 years of experience or a High School diploma and 6 years of experience.
  • Must possess one of the following certifications prior to start date :
  • A+ CE, CCNA-Security, CND, Network+ CE, SSCP, Security+.

  • Demonstrated experience in the Incident Response lifecycle.
  • Knowledge of SOAR ticketing and automated response systems (e.g. ServiceNow, Splunk SOAR, Microsoft Sentinel).
  • Demonstrated experience with using Security Information and Event Management (SIEM) platforms (e.g. Splunk, Microsoft Sentinel, Elastic, Q-Radar).
  • Demonstrated experience in using Endpoint Detection and Response systems (e.g. MDE, ElasticXDR, CarbonBlack, Crowdstrike).
  • Knowledge of cloud security monitoring and incident response.
  • Knowledge of integrating IOCs and Advanced Persistent Threat actors.
  • Ability to analyze cyber threat intelligence reporting and understanding adversary methodologies and techniques.
  • Knowledge of malware analysis techniques.
  • Knowledge of the MITRE ATT&CK and D3FEND frameworks.
  • U.S. Citizenship required.
  • Active Interim Secret clearance in order to start.
  • Preferred Qualifications :

  • Proficiency with Splunk for security monitoring, alert creation, and threat hunting.
  • Knowledge of Microsoft Azure access and identity management.
  • Proficiency with Microsoft Defender for Endpoint and Identity for security monitoring, response, and alert generations.
  • Experience in using digital forensics collection and analysis tools (e.g. Autopsy, MagnetForensics, Zimmerman-Tools, KAPE, CyLR, Volatility).
  • Experience with using ServiceNow SOAR for ticketing and automated response.
  • Knowledge of Python, PowerShell and BASH scripting languages.
  • Experience with cloud security monitoring and incident response.
  • Demonstrated ability to perform static / dynamic malware analysis and reverse engineering.
  • Experience with integrating cyber threat intelligence and IOC-based hunting.
  • Technical certifications such as : Security+, CySA+, Cloud+, Try Hack Me SAL1, Hack the Box CDSA, CyberDefenders, CCD, Azure SC-900, CCSP, GCIH, CCSK, GSEC, CHFI, GCLD, GCIA.
  • Advanced technical certifications such as : SecurityX / CASP+, PRMP, GREM, GEIR, GNFA, or GCFA.
  • Peraton Overview

    Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world's leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains : land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees do the can't be done by solving the most daunting challenges facing our customers. Visit peraton.com to learn how we're keeping people around the world safe and secure.

    Target Salary Range

    $80,000 - $128,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual's experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.

    EEO

    EEO : Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.

    Crear una alerta de empleo para esta búsqueda

    Incident Response • Beltsville, MD, United States

    Ofertas relacionadas
    Senior Consultant, Cyber Incident Response

    Senior Consultant, Cyber Incident Response

    Control RisksWashington, DC, US
    A tiempo completo +1
    Quick Apply
    The Senior Consultant is responsible for delivering Incident Response support to our clients by helping them investigate and remediate the impacts of cyber attacks quickly and comprehensively.This ...Mostrar másÚltima actualización: hace más de 30 días
    • Oferta promocionada
    Mission Assurance Cyber Analyst

    Mission Assurance Cyber Analyst

    Leidos IncOdenton, MD, United States
    A tiempo completo
    The Senior Analyst will support the DISA Joint Operations Center (DJOC) on Ft Meade, MD, and participate in all facets of DISA Mission Relevant Terrain - Cyber (MRT-C) mapping.Their responsibilitie...Mostrar másÚltima actualización: hace más de 30 días
    Senior Cyber Intrusion Detection Analyst

    Senior Cyber Intrusion Detection Analyst

    Vets HiredWashington, D.C., District of Columbia, United States
    A tiempo completo
    Quick Apply
    A Senior Cyber Intrusion Detection Analyst is needed to provide advanced incident response and monitoring support.This is a hybrid position based in Washington, D. Saturday & Sunday, Friday 11pm7am,...Mostrar másÚltima actualización: hace más de 30 días
    • Oferta promocionada
    Senior Cyber Analyst

    Senior Cyber Analyst

    Leidos IncOdenton, MD, United States
    A tiempo completo
    Looking for an opportunity to make an impact?.At Leidos, we deliver innovative solutions through the efforts of our diverse and talented people who are dedicated to our customers' success.We empowe...Mostrar másÚltima actualización: hace más de 30 días
    • Oferta promocionada
    CI Cyber Threat Analyst IV

    CI Cyber Threat Analyst IV

    Obsidian Solutions Group LLCDunn Loring, VA, US
    A tiempo completo
    CI Cyber Threat Analyst Level IV.Primary Location : Springfield, VA and St.The Senior CI Cyber Threat Analyst will ensure all required reports are complete with minimal errors and that all processes...Mostrar másÚltima actualización: hace 11 días
    • Oferta promocionada
    Principal Consultant, Digital Forensic and Incident Response (DFIR) (Remote)

    Principal Consultant, Digital Forensic and Incident Response (DFIR) (Remote)

    Surefire CyberElkridge, MD, US
    Teletrabajo
    A tiempo completo
    Surefire Cyber is redefining the incident response model by delivering a swifter, stronger response to cyber incidents such as ransomware, email compromise, malware, data theft, and other threats.O...Mostrar másÚltima actualización: hace más de 30 días
    Associate Director, Cyber Incident Response

    Associate Director, Cyber Incident Response

    Control RisksWashington, DC, US
    A tiempo completo +1
    Quick Apply
    The Associate Director is responsible for managing the Cyber Response Team in the US and leading overall delivery of incident response cases in the region. This role involves leading the technical a...Mostrar másÚltima actualización: hace más de 30 días
    Technical Compliance Analyst - TS CI Poly required to apply - Wash DC

    Technical Compliance Analyst - TS CI Poly required to apply - Wash DC

    Bow Wave LLCWashington, DC, USA
    A tiempo completo
    Quick Apply
    Monitors computer networks and systems for security issues, suspicious activities, and compliance with established standards. Assists in investigating security breaches or incidents and participates...Mostrar másÚltima actualización: hace 24 días
    • Oferta promocionada
    Cyber Incident Response Analyst

    Cyber Incident Response Analyst

    Leidos IncAshburn, VA, United States
    A tiempo completo
    Leidos is seeking a highly skilled.Cyber Incident Response Analyst.Security Operations Center (SOC) support, cyber analysis, and application development. This role supports the DHS SOC, which is res...Mostrar másÚltima actualización: hace 6 días
    • Oferta promocionada
    Tier 3 Incident Response Senior Analyst

    Tier 3 Incident Response Senior Analyst

    Resource Management Concepts, Inc.Quantico, VA, US
    A tiempo completo
    Tier 3 Incident Response Senior Analyst.Quantico, Virginia, providing defensive cyberspace operations and Cyber Security Service Provider (CSSP) functions. This position will support the government&...Mostrar másÚltima actualización: hace 18 días
    • Oferta promocionada
    CI Cyber Threat Technical Analyst III

    CI Cyber Threat Technical Analyst III

    Obsidian Solutions Group LLCDunn Loring, VA, US
    A tiempo completo
    CI Cyber Threat Technical Analyst (Level III).Primary Location : Springfield, VA and St.The CI Cyber Threat Technical Analyst will ensure all required reports are complete with minimal errors and th...Mostrar másÚltima actualización: hace 11 días
    • Oferta promocionada
    Threat Assessment Team Lead

    Threat Assessment Team Lead

    Clearance JobsWashington, DC, US
    A tiempo completo
    This is a contingent opportunity.The Threat Assessment Team Lead is responsible for the pre-assessment coordination requirements and providing installation support for the development and publicati...Mostrar másÚltima actualización: hace más de 30 días
    RMF Cybersecurity Analyst - TS / SCI with CI Poly

    RMF Cybersecurity Analyst - TS / SCI with CI Poly

    ENS Solutions, LLCMcLean, VA, US
    A tiempo completo
    Quick Apply
    Our work depends on a Risk Management Framework Cybersecurity Analyst joining our team to support Government activities.As a RMF Cybersecurity Analyst supporting the Federal Government and the Inte...Mostrar másÚltima actualización: hace 17 días
    • Nueva oferta
    Senior Cyber Defense Incident Responder

    Senior Cyber Defense Incident Responder

    Network Designs Inc.Washington DC, DC, USA
    A tiempo completo
    Quick Apply
    NDi) is a leading Federal contractor that specializes in designing, developing, and delivering information technology and network solutions for government customers. Founded in 1985, NDi's firmly de...Mostrar másÚltima actualización: hace 18 horas
    • Oferta promocionada
    Cyber Technical Analyst Advisor (Technical Targeter)

    Cyber Technical Analyst Advisor (Technical Targeter)

    Leading Path ConsultingChantilly, VA, US
    A tiempo completo
    Cyber Technical Analyst Advisor (Technical Targeter).Active TS / SCI w / FS Poly REQUIRED.This project is supporting a mission critical group dealing with data vital to Homeland Security.Demonstrated ...Mostrar másÚltima actualización: hace más de 30 días
    • Oferta promocionada
    Cyber Analyst - ConMon

    Cyber Analyst - ConMon

    Leidos IncOdenton, MD, United States
    A tiempo completo
    Leidos is seeking multiple ConMon Analysts to be responsible for overseeing and monitoring authorized IT systems (re-authorization and new systems) throughout their lifecycle for security posture i...Mostrar másÚltima actualización: hace 11 días
    • Oferta promocionada
    PPSM Cyber Analyst

    PPSM Cyber Analyst

    Leidos IncOdenton, MD, United States
    A tiempo completo
    Leidos is seeking a Ports, Protocols, and Services Management (PPSM) Engineer in Ft Meade, MD.Our PPSM team provides end-to-end data protection by ensuring communication protocols in the Internet p...Mostrar másÚltima actualización: hace 12 días
    • Oferta promocionada
    Cybersecurity Service Provider / Incident Response (CSSP / IR) Analyst (3rd Shift)

    Cybersecurity Service Provider / Incident Response (CSSP / IR) Analyst (3rd Shift)

    Bespoke Corps LLCAshburn, VA, US
    A tiempo completo
    Bespoke Corps, LLC is looking for a qualified candidate to provide onsite support to one of our valued Department of Defense (DoD) customers. We are seeking a (CSSP / IR) specialist with specific skil...Mostrar másÚltima actualización: hace 19 días
    • Oferta promocionada
    Cybersecurity Service Provider / Incident Response (CSSP / IR) Analyst (Hourly 3rd Shift Weekends)

    Cybersecurity Service Provider / Incident Response (CSSP / IR) Analyst (Hourly 3rd Shift Weekends)

    Bespoke Corps LLCAshburn, VA, US
    A tiempo completo
    Bespoke Corps, LLC is looking for a qualified candidate to provide on-site support to one of our valued Department of Defense (DoD) customers. We are seeking a (CSSP / IR) specialist with specific ski...Mostrar másÚltima actualización: hace 19 días
    • Oferta promocionada
    Cyber Threat Analysis Division Task Lead

    Cyber Threat Analysis Division Task Lead

    Clearance JobsArlington, VA, US
    A tiempo completo
    Seize your opportunity to make a personal impact as a Project / Task Manager supporting our program.GDIT is your place to make meaningful contributions to challenging projects and grow a rewarding ca...Mostrar másÚltima actualización: hace más de 30 días