Talent.com
Tier 2 Cyber Incident Response Team (CIRT) Analyst at Peraton Beltsville, MD
Tier 2 Cyber Incident Response Team (CIRT) Analyst at Peraton Beltsville, MDItlearn360 • Beltsville, MD, US
Tier 2 Cyber Incident Response Team (CIRT) Analyst at Peraton Beltsville, MD

Tier 2 Cyber Incident Response Team (CIRT) Analyst at Peraton Beltsville, MD

Itlearn360 • Beltsville, MD, US
13 days ago
Job type
  • Temporary
Job description

Tier 2 Cyber Incident Response Team (CIRT) Analyst job at Peraton. Beltsville, MD.

Program Overview

Encompasses technical, engineering, data analytics, cyber security, management, operational, logistical, and administrative support for Bureau of Diplomatic Security, Cyber and Technology Security Directorate in three key offices / functional areas : Cyber Monitoring and Operations, Cyber Threat and Investigations, and Technology Innovation and Engineering State.

About The Role

Peraton is seeking an experienced Tier 2 Cyber Incident Response Team (CIRT) Analyst to join Peraton's Department of State (DOS) Diplomatic Security Cyber Mission (DSCM) program, which provides leading cyber and technology security expertise to enable innovative, effective, and secure business processes that protect our nation's diplomatic missions worldwide.

Location : Beltsville, MD

Work Hours : Evening Shift, 1400 – 2200 EST, TUE-SAT

In this role, you will :

  • Detect, classify, process, track, and report on cyber security events and incidents.
  • Perform advanced in-depth analysis of coordinated Tier 1 alert triage and requests in a 24x7x365 environment.
  • Analyze logs from multiple sources (e.g., host logs, EDR, firewalls, intrusion detection systems, servers) to identify, contain, and remediate suspicious activity.
  • Characterize and analyze network traffic to identify anomalous activity and potential threats.
  • Protect against and prevent potential cyber security threats and vulnerabilities.
  • Perform forensic analysis of hosts artifacts, network traffic, and email content.
  • Analyze malicious scripts and code to mitigate potential threats.
  • Conduct malware analysis to generate IOCs to identify and mitigate threats.
  • Collaborate with Department of State teams to analyze and respond to events and incidents.
  • Monitor and respond to the CIRT Security Orchestration and Automation Response (SOAR) platform, hotline, email inboxes.
  • Create tickets and initiate workflows as instructed in technical SOPs.
  • Coordinate and report incident information to the Cybersecurity and Infrastructure Security Agency (CISA).
  • Collaborate with other local, national and international CIRTs as directed.
  • Submit alert tuning requests.

DSCM

Qualifications

Required Qualifications :

  • Bachelor's degree and at least 2 years of experience or a High School diploma and 6 years of experience.
  • Must possess one of the following certifications prior to start date :
  • A+ CE, CCNA-Security, CND, Network+ CE, SSCP, Security+.

  • Demonstrated experience in the Incident Response lifecycle.
  • Knowledge of SOAR ticketing and automated response systems (e.g. ServiceNow, Splunk SOAR, Microsoft Sentinel).
  • Demonstrated experience with using Security Information and Event Management (SIEM) platforms (e.g. Splunk, Microsoft Sentinel, Elastic, Q-Radar).
  • Demonstrated experience in using Endpoint Detection and Response systems (e.g. MDE, ElasticXDR, CarbonBlack, Crowdstrike).
  • Knowledge of cloud security monitoring and incident response.
  • Knowledge of integrating IOCs and Advanced Persistent Threat actors.
  • Ability to analyze cyber threat intelligence reporting and understanding adversary methodologies and techniques.
  • Knowledge of malware analysis techniques.
  • Knowledge of the MITRE ATT&CK and D3FEND frameworks.
  • U.S. Citizenship required.
  • Active Interim Secret clearance in order to start.
  • Preferred Qualifications :

  • Proficiency with Splunk for security monitoring, alert creation, and threat hunting.
  • Knowledge of Microsoft Azure access and identity management.
  • Proficiency with Microsoft Defender for Endpoint and Identity for security monitoring, response, and alert generations.
  • Experience in using digital forensics collection and analysis tools (e.g. Autopsy, MagnetForensics, Zimmerman-Tools, KAPE, CyLR, Volatility).
  • Experience with using ServiceNow SOAR for ticketing and automated response.
  • Knowledge of Python, PowerShell and BASH scripting languages.
  • Experience with cloud security monitoring and incident response.
  • Demonstrated ability to perform static / dynamic malware analysis and reverse engineering.
  • Experience with integrating cyber threat intelligence and IOC-based hunting.
  • Technical certifications such as : Security+, CySA+, Cloud+, Try Hack Me SAL1, Hack the Box CDSA, CyberDefenders, CCD, Azure SC-900, CCSP, GCIH, CCSK, GSEC, CHFI, GCLD, GCIA.
  • Advanced technical certifications such as : SecurityX / CASP+, PRMP, GREM, GEIR, GNFA, or GCFA.
  • SCA / Union / Intern Rate or Range

    Details

    Target Salary Range : $80,000 - $128,000. This represents the typical salary range for this position based on experience and other factors.

    EEO : Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.

    J-18808-Ljbffr

    Create a job alert for this search

    Incident Response • Beltsville, MD, US

    Related jobs
    Mid Cyber Incident Analyst

    Mid Cyber Incident Analyst

    ECS • Arlington, VA, US
    Full-time
    ECS is seeking talented professionals to join our successful and growing team supporting the Cybersecurity and Infrastructure Security Agency's (CISA) Joint Cyber Defense Collaborative (JCDC).The J...Show more
    Last updated: 13 days ago • Promoted
    ICS Incident Response Analyst

    ICS Incident Response Analyst

    GrammaTech • Arlington, VA, US
    Full-time
    Hybrid role, on-site as needed.Candidates must be a US citizen with ability to obtain a TS / SCI and must be willing to work onsite as required. Respond to cybersecurity incidents for ICS / OT / IT enviro...Show more
    Last updated: 13 days ago • Promoted
    Senior Cyber Intrusion Detection Analyst

    Senior Cyber Intrusion Detection Analyst

    Vets Hired • Washington, D.C., District of Columbia, United States
    Full-time
    Quick Apply
    A Senior Cyber Intrusion Detection Analyst is needed to provide advanced incident response and monitoring support.This is a hybrid position based in Washington, D. Saturday & Sunday, Friday 11pm7am,...Show more
    Last updated: 30+ days ago
    Cyber Incident Response Analyst

    Cyber Incident Response Analyst

    Leidos Inc • Ashburn, VA, United States
    Full-time
    Leidos is seeking a highly skilled.Cyber Incident Response Analyst.Security Operations Center (SOC) support, cyber analysis, and application development. This role supports the DHS SOC, which is res...Show more
    Last updated: 17 days ago • Promoted
    Tier 3 Incident Response Senior Analyst

    Tier 3 Incident Response Senior Analyst

    Resource Management Concepts, Inc. • Quantico, VA, US
    Full-time
    Tier 3 Incident Response Senior Analyst.Quantico, Virginia, providing defensive cyberspace operations and Cyber Security Service Provider (CSSP) functions. This position will support the government&...Show more
    Last updated: 29 days ago • Promoted
    Mid Cyber Analyst (Technical Response Team)

    Mid Cyber Analyst (Technical Response Team)

    Prescient Edge • Quantico, VA, US
    Full-time
    Mid Cyber Analyst (Technical Response Team).At Prescient Edge, we believe that acting with integrity and serving our employees is the key to everyone's success. To that end, we provide employees wit...Show more
    Last updated: 13 days ago • Promoted
    Cybersecurity Vulnerability Analyst (Incident Manager III)

    Cybersecurity Vulnerability Analyst (Incident Manager III)

    Solutions³ LLC • Arlington, VA, US
    Full-time
    Quick Apply
    Cybersecurity Vulnerability Analyst (Incident Manager III ) Description : Solutions³ LLC is supporting our prime contractor and their U. Government customer to provide cybersecurity vulne...Show more
    Last updated: 30+ days ago
    Cybersecurity Vulnerability Analyst (Incident Manager III)

    Cybersecurity Vulnerability Analyst (Incident Manager III)

    Vervic • Arlington, VA, USA
    Full-time
    Quick Apply
    Cybersecurity Vulnerability Analyst (Incident Manager III.Supporting our prime contractor and their U.Government customer to provide cybersecurity vulnerability analysis support to reduce the preva...Show more
    Last updated: 9 days ago
    Senior Cyber Analyst (Technical Response Team)

    Senior Cyber Analyst (Technical Response Team)

    Prescient Edge • Quantico, VA, US
    Full-time
    Senior Cyber Analyst (Technical Response Team).At Prescient Edge, we believe that acting with integrity and serving our employees is the key to everyone's success. To that end, we provide employees ...Show more
    Last updated: 13 days ago • Promoted
    Cybersecurity Service Provider / Incident Response (CSSP / IR) Analyst

    Cybersecurity Service Provider / Incident Response (CSSP / IR) Analyst

    Bespoke Corps LLC • Arlington, VA, US
    Full-time
    Bespoke Corps, LLC is looking for a qualified candidate to provide on-site support to one of our valued Department of Defense (DoD) customers. We are seeking a (CSSP / IR) specialist with specific ski...Show more
    Last updated: 13 days ago • Promoted
    Cybersecurity Assessment & Authorization (A&A) SME

    Cybersecurity Assessment & Authorization (A&A) SME

    Nationwide IT Services • Fort Belvoir, VA, United States
    Full-time
    Cybersecurity Assessment & Authorization (A&A) SME.IT-II Non-Critical Sensitive or Tier 3 (T3) Secret.Remote or DLA HQ, Fort Belvoir, VA. Certified Cloud Security Professional (CCSP) and DoD 8570 / 81...Show more
    Last updated: 14 days ago • Promoted
    Jr. Cyber Incident Analyst

    Jr. Cyber Incident Analyst

    ECS • Arlington, VA, US
    Full-time
    ECS is seeking talented professionals to join our successful and growing team supporting the Cybersecurity and Infrastructure Security Agency's (CISA) Joint Cyber Defense Collaborative (JCDC).The J...Show more
    Last updated: 13 days ago • Promoted
    Target Digital Network Analyst, Senior

    Target Digital Network Analyst, Senior

    Booz Allen Hamilton • Fort Meade, MD, US
    Full-time +1
    Your growth matters to us - explore our career development opportunities.Connect with others in our people-first culture and enhance our collective ingenuity. Learn how we'll support you as you purs...Show more
    Last updated: 13 days ago • Promoted
    Tier 2 Cyber Incident Response Team (CIRT) Analyst

    Tier 2 Cyber Incident Response Team (CIRT) Analyst

    Peraton • Beltsville, MD, US
    Temporary
    Bachelor's degree and at least 2 years of experience or a High School diploma and 6 years of experience.Must possess one of the following certifications prior to start date : .A+ CE, CCNA-Security, C...Show more
    Last updated: 13 days ago • Promoted
    Monitoring Cyber Incident Response Team (CIRT) Analyst

    Monitoring Cyber Incident Response Team (CIRT) Analyst

    Peraton • Beltsville, MD, US
    Temporary
    Bachelor's degree and at least 2 years of experience or a High School diploma and 6 years of experience.One of the professional certifications listed below, or have the ability to obtain one prior ...Show more
    Last updated: 13 days ago • Promoted
    Cybersecurity Service Provider / Incident Response (CSSP / IR) Analyst (Hourly 3rd Shift Weekends)

    Cybersecurity Service Provider / Incident Response (CSSP / IR) Analyst (Hourly 3rd Shift Weekends)

    Bespoke Corps LLC • Ashburn, VA, US
    Full-time
    Bespoke Corps, LLC is looking for a qualified candidate to provide on-site support to one of our valued Department of Defense (DoD) customers. We are seeking a (CSSP / IR) specialist with specific ski...Show more
    Last updated: 30+ days ago • Promoted
    Faculty Member, Cybersecurity / Information Technology

    Faculty Member, Cybersecurity / Information Technology

    InsideHigherEd • Frederick, Maryland, United States
    Full-time +1
    Faculty Member, Cybersecurity / Information Technology.The ­­­­­Cybersecurity / Information Technology faculty position supports the Cybersecurity and Information Technology programs and strategic oper...Show more
    Last updated: 30+ days ago • Promoted
    Tier 2 Cyber Incident Response Team (CIRT) Analyst with Security

    Tier 2 Cyber Incident Response Team (CIRT) Analyst with Security

    Peraton • Arlington, VA, US
    Temporary
    About Peraton Peraton is a next–generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy.As the world's leadin...Show more
    Last updated: 1 day ago • Promoted