707,525open jobs
41,962companies
101,146added this week
Browse all
Salary
$80k – $128k per year
Location
In office
Seniority
Middle · 3+ years exp
Overview
Company
Impact
Profile match
Peraton.com is the corporate site for Peraton which is a national security and technology company serving government and critical infrastructure customers. It provides mission support systems engineering cyber space and communications solutions along with specialized services for defense intelligence civil and commercial sectors.

Responsibilities

Peraton is currently seeking a Cyber Monitoring Signature Analyst to become part of Peraton’s Department of State (DoS) Diplomatic Security Cyber Mission (DSCM) program.

Location: Rosslyn, VA and a secondary at Beltsville, MD

Schedule: Mon-Friday, 08:00-16:00 (8:00 AM - 4:00PM)

In this role, you will:

  • Work under senior detection engineers and Subject Matter Experts with cutting edge cyber monitoring tools to build and enhance the organization's threat detection and response capabilities. This position is with the Cyber Incident Response Team.
  • Work in a team environment with senior detection engineers, threat analysts, and incident responders to protect a global IT infrastructure against advanced threat actors.
  • Author, tune, and maintain correlation searches, Risk Notables, and Adaptive Response actions within Splunk Cloud Enterprise Security.
  • Evaluate new analytical detections from open-source libraries and incorporate vetted alerting into a SIEM.
  • Author new correlational searches in SPL/SPL2 using best practice search methodologies.
  • Maintain a living MITRE ATT&CK coverage matrix; identify gaps and prioritize with SME.
  • Ensure proper cohesion and health of SIEM alerting.
  • Collaborate and assist system engineers with the development, configuration and tuning of cyber security tools.
  • Operationalize threat intelligence to ensure Indicators of Compromise are actionable in detections.
  • Provide reporting on detection development metrics (coverage, MTTx, FP rate, notable volume by rule).

Qualifications

Minimum requirements are:

  • Bachelor's degree and 5 years of relevant experience; or, 3 years with a Masters degree. An additional 4 years of experience in lieu of the bachelors degree will be considered.
  • Must possess and maintain one of the following certifications or the ability to obtain before start date: CASP+ CE, CCNA Cyber Ops, CCNA-Security, CCNP Security, CEH, CFR, CHFI, CISA, CISSP (or Associate), CySA+, GCED, GCFA, GCIH, SCYBER, or Security+
  • Hands-on experience authoring and tuning SPL in a production Splunk environment (minimum 3 years).
  • Working knowledge of Splunk Enterprise Security (correlation searches, notable events, Incident Review, Adaptive Response) - ES 8.x experience strongly preferred.
  • Demonstrated experience with the Splunk Common Information Model (CIM) and writing performant searches against accelerated data models.
  • Experience modifying Splunk ES searches, macros, and lookup tables.
  • Familiarity with the MITRE ATT&CK framework and its application to detection engineering.
  • Working knowledge of Zeek, Suricata, and at least one EDR.
  • Demonstrated knowledge of the Incident Response Lifecycle and how it applies to cloud, legacy, and hybrid environments.
  • Strong organizational skills.
  • Proven ability to operate in a time-sensitive environment.
  • Proven ability to effectively communicate orally and in writing.
  • U.S. Citizenship is required
  • Ability to obtain an interim Secret clearance before start date.
    • Able to obtain a Top Secret security clearance.

Preferred:

  • Prior experience operationalizing Splunk ES Content Updates (ESCU) analytic stories and Risk-Based Alerting (RBA) workflows.
  • Experience with Splunk Mission Control for triage, investigation, and response workflows.
  • Understanding of CVEs, zero-day threats, their modes of operation, and threat detection measures.
  • Working knowledge of Python and search syntax like Regex.
  • Knowledge of network architecture, design, and security.
  • Knowledge of which system files (e.g., log files, registry files, configuration files) contain relevant information and where to find those system files.
  • Understanding of policies and procedures to investigate incidents in a computer network.
  • Knowledge of intersection of on-prem and cloud-based technologies.
  • Exposure to leading vendor cloud environments (Microsoft Azure/AAD, Google GCP, Amazon AWS), Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS).
  • Experience with EDR telemetry analysis (Microsoft Defender for Endpoint / Advanced Hunting) and/or web proxy data (Zscaler, Cloudflare).
  • Experience with threat intelligence platforms and IOC operationalization.
  • Experience in developing and delivering comprehensive training programs.
  • Previous Incident Response experience at the analyst level.
  • Knowledge and familiarity with Detection as Code.
  • Knowledge and familiarity with implementation of AI-driven workflows.

Peraton Overview

Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world’s leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees do the can’t be done by solving the most daunting challenges facing our customers. Visit peraton.com to learn how we’re keeping people around the world safe and secure.

Target Salary Range

$80,000 - $128,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual’s experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.

EEO

EEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
707,525 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
Senior Cloud Engineer 4 hours ago
$112k – $179k per year • In office • TS/SCI • 9+ years exp • High School Diploma
Python
PowerShell
Bash
DevOps
Splunk
Terraform
GCP
Azure DevOps
GitHub Actions
VMWare
CloudFormation
Prometheus
GitLab CI
Azure
CI/CD
Windows Server
Jenkins
AWS
Docker
Kubernetes
Grafana
Configuration Management
Bicep
IAM
Windows
DNS
Cybersecurity
NIST 800-53
Zero Trust
Apply
Senior Cloud Engineer 4 hours ago
$135k – $216k per year • In office • TS/SCI • 3+ years exp • Bachelor's Degree
Python
PowerShell
Bash
DevOps
Splunk
Terraform
GCP
Azure DevOps
GitHub Actions
VMWare
CloudFormation
Prometheus
GitLab CI
Azure
CI/CD
Windows Server
Jenkins
AWS
Docker
Kubernetes
Grafana
Configuration Management
Bicep
IAM
Windows
DNS
Cybersecurity
NIST 800-53
Zero Trust
Apply
Software Developer 4 hours ago
In office • Secret • 8+ years exp • Bachelor's Degree
Python
JavaScript
Java
PHP
TypeScript
SQL
C#
C#
ASP.NET Core
Databases
PostgreSQL
Frontend
Angular
DevOps
Helm
GitLab CI
Azure
CI/CD
AWS
Docker
Kubernetes
GitLab
Apache HTTP Server
Management
Confluence
Jira
Apply
$86k – $138k per year • In office • 9+ years exp • High School Diploma
Python
COBOL
COBOL
IBM MQ
Databases
DynamoDB
DevOps
Terraform
Ansible
AWS CDK
CloudFormation
CI/CD
AWS
Docker
Kubernetes
Amazon EKS
AWS Lambda
Amazon EC2
Amazon S3
Amazon ECS
Amazon CloudWatch
AWS Step Functions
Management
Agile
Scrum
Apply
$112k – $179k per year • In office • TS/SCI • 16+ years exp • PhD
DevOps
Azure
Windows Server
AWS
VLAN
BGP
OSPF
MPLS
Apply
Technical Trainer 4 hours ago
$104k – $166k per year • In office • TS/SCI • 8+ years exp • Bachelor's Degree
AI/ML
Post-training
Management
Microsoft Office
Apply
$176k – $282k per year • In office • TS/SCI • 4+ years exp • Bachelor's Degree
DevOps
Splunk
Management
ITIL
Apply
Propulsion Engineer 4 hours ago
$104k – $166k per year • In office • TS/SCI • 5+ years exp • Bachelor's Degree
Apply
Enterprise Architect 4 hours ago
$112k – $179k per year • In office • 12+ years exp • Bachelor's Degree
DevOps
BGP
OSPF
MPLS
Cybersecurity
Zero Trust
Apply
$135k – $216k per year • In office • TS/SCI • 12+ years exp • Bachelor's Degree
Management
SharePoint
Microsoft Office
Apply
See all jobs
This is one of many
707,525 more open roles from verified company boards, updated every day.