Talent.com
Monitoring Cyber Incident Response Team (CIRT) Analyst

Monitoring Cyber Incident Response Team (CIRT) Analyst

PeratonBeltsville, MD, US
job_description.job_card.1_day_ago
serp_jobs.job_preview.job_type
  • serp_jobs.job_card.temporary
job_description.job_card.job_description

Join to apply for the Monitoring Cyber Incident Response Team (CIRT) Analyst role at Peraton

About Peraton

Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world's leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains : land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees do the can't be done by solving the most daunting challenges facing our customers.

Program Overview

Encompasses technical, engineering, data analytics, cyber security, management, operational, logistical, and administrative support for Bureau of Diplomatic Security, Cyber and Technology Security Directorate in three key offices / functional areas : Cyber Monitoring and Operations, Cyber Threat and Investigations, and Technology Innovation and Engineering State.

About The Role

Peraton is seeking an experienced Monitoring Cyber Incident Response Team (CIRT) Analyst to join Peratons' Federal Strategic Cyber Mission program.

Location : Beltsville, MD; On-site

Work Hours : Days Shift, 0600 - 1400 EST, SUN-THU.

In this role, you will :

  • Detect, classify, process, track, and report on cyber security events and incidents.
  • Perform advanced in-depth analysis of coordinated Tier 1 alert triage and requests in a 24x7x365 environment.
  • Analyze logs from multiple sources (e.g., host logs, EDR, firewalls, intrusion detection systems, servers) to identify, contain, and remediate suspicious activity.
  • Characterize and analyze network traffic to identify anomalous activity and potential threats.
  • Protect against and prevent potential cyber security threats and vulnerabilities.
  • Perform forensic analysis of hosts artifacts, network traffic, and email content.
  • Analyze malicious scripts and code to mitigate potential threats.
  • Conduct malware analysis to generate IOCs to identify and mitigate threats.
  • Collaborate with Department of State teams to analyze and respond to events and incidents.
  • Monitor and respond to the CIRT Security Orchestration and Automation Response (SOAR) platform, hotline, email in-boxes.
  • Create tickets and initiate workflows as instructed in technical SOPs.
  • Coordinate and report incident information to the Cybersecurity and Infrastructure Security Agency (CISA).
  • Collaborate with other local, national and international CIRTs as directed.
  • Submit alert tuning requests.

Qualifications

Required :

  • Bachelor's degree and at least 2 years of experience or a High School diploma and 6 years of experience.
  • One of the professional certifications listed below, or have the ability to obtain one prior to start date :
  • A+ CE, CCNA-Security, CND, Network+ CE, SSCP
  • Continued certification is required as a condition of employment.
  • Demonstrated experience in the Incident Response lifecycle.
  • Knowledge of SOAR ticketing and automated response systems (e.g. ServiceNow, Splunk SOAR, Microsoft Sentinel).
  • Demonstrated experience with using Security Information and Event Management (SIEM) platforms (e.g. Splunk, Microsoft Sentinel, Elastic, Q-Radar).
  • Demonstrated experience in using Endpoint Detection and Response systems (e.g. MDE, ElasticXDR, CarbonBlack, Crowdstrike).
  • Knowledge of cloud security monitoring and incident response.
  • Knowledge of integrating IOCs and Advanced Persistent Threat actors.
  • Ability to analyze cyber threat intelligence reporting and understanding adversary methodologies and techniques.
  • Knowledge of malware analysis techniques.
  • Knowledge of the MITRE ATT&CK and D3FEND frameworks.
  • U.S. Citizenship required.
  • Active Interim Secret clearance in order to start.
  • Preferred :

  • Active Secret clearance.
  • Proficiency with Splunk for security monitoring, alert creation, and threat hunting.
  • Knowledge of Microsoft Azure access and identity management.
  • Proficiency with Microsoft Defender for Endpoint and Identity for security monitoring, response, and alert generations.
  • Experience in using digital forensics collection and analysis tools (e.g. Autopsy, MagnetForensics, Zimmerman-Tools, KAPE, CyLR, Volatility).
  • Experience with using ServiceNow SOAR for ticketing and automated response.
  • Knowledge of Python, PowerShell and BASH scripting languages.
  • Experience with cloud security monitoring and incident response.
  • Demonstrated ability to perform static / dynamic malware analysis and reverse engineering.
  • Experience with integrating cyber threat intelligence and IOC-based hunting.
  • Technical certifications such as : Security+, CySA+, Cloud+, Try Hack Me SAL1, Hack the Box CDSA, CyberDefenders, CCD, Azure SC-900, CCSP, GCIH, CCSK, GSEC, CHFI, GCLD, GCIA.
  • Advanced technical certifications such as : SecurityX / CASP+, PRMP, GREM, GEIR, GNFA, or GCFA.
  • SCA / Union / Intern Rate or Range

    Target Salary Range : $66,000 - $106,000.

    EEO : Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.

    J-18808-Ljbffr

    serp_jobs.job_alerts.create_a_job

    Incident Response • Beltsville, MD, US

    Job_description.internal_linking.related_jobs
    Tier 3 Incident Response Senior Analyst

    Tier 3 Incident Response Senior Analyst

    Resource Management Concepts, Inc.Quantico, VA, US
    serp_jobs.job_card.full_time
    serp_jobs.filters_job_card.quick_apply
    Tier 3 Incident Response Senior Analyst.Quantico, Virginia, providing defensive cyberspace operations and Cyber Security Service Provider (CSSP) functions. This position will support the government'...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    Senior Consultant, Cyber Incident Response

    Senior Consultant, Cyber Incident Response

    Control RisksWashington, DC, US
    serp_jobs.job_card.full_time +1
    serp_jobs.filters_job_card.quick_apply
    The Senior Consultant is responsible for delivering Incident Response support to our clients by helping them investigate and remediate the impacts of cyber attacks quickly and comprehensively.This ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    Senior Cyber Intrusion Detection Analyst

    Senior Cyber Intrusion Detection Analyst

    Vets HiredWashington, D.C., District of Columbia, United States
    serp_jobs.job_card.full_time
    serp_jobs.filters_job_card.quick_apply
    A Senior Cyber Intrusion Detection Analyst is needed to provide advanced incident response and monitoring support.This is a hybrid position based in Washington, D. Saturday & Sunday, Friday 11pm7am,...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Mission Assurance Cyber Analyst

    Mission Assurance Cyber Analyst

    Leidos IncOdenton, MD, United States
    serp_jobs.job_card.full_time
    The Senior Analyst will support the DISA Joint Operations Center (DJOC) on Ft Meade, MD, and participate in all facets of DISA Mission Relevant Terrain - Cyber (MRT-C) mapping.Their responsibilitie...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Senior Cyber Analyst

    Senior Cyber Analyst

    Leidos IncOdenton, MD, United States
    serp_jobs.job_card.full_time
    Looking for an opportunity to make an impact?.At Leidos, we deliver innovative solutions through the efforts of our diverse and talented people who are dedicated to our customers' success.We empowe...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    Associate Director, Cyber Incident Response

    Associate Director, Cyber Incident Response

    Control RisksWashington, DC, US
    serp_jobs.job_card.full_time +1
    serp_jobs.filters_job_card.quick_apply
    The Associate Director is responsible for managing the Cyber Response Team in the US and leading overall delivery of incident response cases in the region. This role involves leading the technical a...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Cyber Analyst, Journeyman

    Cyber Analyst, Journeyman

    Leidos IncOdenton, MD, United States
    serp_jobs.job_card.full_time
    Looking for an opportunity to make an impact?.At Leidos, we deliver innovative solutions through the efforts of our diverse and talented people who are dedicated to our customers' success.We empowe...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Senior Cyber Intelligence Analyst

    Senior Cyber Intelligence Analyst

    Leidos IncOdenton, MD, United States
    serp_jobs.job_card.full_time
    Looking for an opportunity to make an impact?.At Leidos, we deliver innovative solutions through the efforts of our diverse and talented people who are dedicated to our customers' success.We empowe...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Cyber Incident Response Analyst

    Cyber Incident Response Analyst

    Leidos IncAshburn, VA, United States
    serp_jobs.job_card.full_time
    Leidos is seeking a highly skilled.Cyber Incident Response Analyst.Security Operations Center (SOC) support, cyber analysis, and application development. This role supports the DHS SOC, which is res...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    Cybersecurity Vulnerability Analyst (Incident Manager III)

    Cybersecurity Vulnerability Analyst (Incident Manager III)

    Solutions³ LLCArlington, VA, US
    serp_jobs.job_card.full_time
    serp_jobs.filters_job_card.quick_apply
    Cybersecurity Vulnerability Analyst (Incident Manager III ) Description : Solutions³ LLC is supporting our prime contractor and their U. Government customer to provide cybersecurity vulne...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    Cyber Incident Manager / Incident Manager

    Cyber Incident Manager / Incident Manager

    Node.DigitalArlington, VA, US
    serp_jobs.job_card.full_time
    serp_jobs.filters_job_card.quick_apply
    Cyber Incident Manager / Incident Manager.Must have an active Top Secret Security Clearance.Government customer to provide support for onsite incident response to civilian Government agencies and cr...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Strategic Cyber Risk Management Analyst

    Strategic Cyber Risk Management Analyst

    Leidos IncAshburn, VA, United States
    serp_jobs.job_card.full_time
    Department of Homeland Security (DHS), Customs and Border Protection (CBP) Security Operations Center (SOC) is a US Government program responsible to prevent, identify, contain and eradicate cyber ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    RMF Cybersecurity Analyst - TS / SCI with CI Poly

    RMF Cybersecurity Analyst - TS / SCI with CI Poly

    ENS Solutions, LLCReston, VA, US
    serp_jobs.job_card.full_time
    serp_jobs.filters_job_card.quick_apply
    Our work depends on a Risk Management Framework Cybersecurity Analyst joining our team to support Government activities.As a RMF Cybersecurity Analyst supporting the Federal Government and the Inte...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Cyber Analyst - ConMon

    Cyber Analyst - ConMon

    Leidos IncOdenton, MD, United States
    serp_jobs.job_card.full_time
    Leidos is seeking multiple ConMon Analysts to be responsible for overseeing and monitoring authorized IT systems (re-authorization and new systems) throughout their lifecycle for security posture i...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    PPSM Cyber Analyst

    PPSM Cyber Analyst

    Leidos IncOdenton, MD, United States
    serp_jobs.job_card.full_time
    Leidos is seeking a Ports, Protocols, and Services Management (PPSM) Engineer in Ft Meade, MD.Our PPSM team provides end-to-end data protection by ensuring communication protocols in the Internet p...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Insider Threat Program Investigative Team Analyst

    Insider Threat Program Investigative Team Analyst

    Leidos IncWashington, DC, United States
    serp_jobs.job_card.full_time
    The Digital Modernization Sector at Leidos currently has an opening for a UAM Investigative Team Analyst supporting the HEITS Contract as part of the Department of Homeland Security (DHS) Insider T...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Cyberspace Intelligence Threat Analyst, Journeyman

    Cyberspace Intelligence Threat Analyst, Journeyman

    Leidos IncOdenton, MD, United States
    serp_jobs.job_card.full_time
    Looking for an opportunity to make an impact?.At Leidos, we deliver innovative solutions through the efforts of our diverse and talented people who are dedicated to our customers' success.We empowe...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Cyber Analyst, Journeyman - Evening Shift

    Cyber Analyst, Journeyman - Evening Shift

    Leidos IncOdenton, MD, United States
    serp_jobs.job_card.full_time
    Looking for an opportunity to make an impact?.At Leidos, we deliver innovative solutions through the efforts of our diverse and talented people who are dedicated to our customers' success.We empowe...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Cyber Threat Analysis Division Task Lead

    Cyber Threat Analysis Division Task Lead

    Clearance JobsArlington, VA, US
    serp_jobs.job_card.full_time
    Seize your opportunity to make a personal impact as a Project / Task Manager supporting our program.GDIT is your place to make meaningful contributions to challenging projects and grow a rewarding ca...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Principal Auditor - Cyber, Risk and Analysis Technology Audit

    Principal Auditor - Cyber, Risk and Analysis Technology Audit

    Capital OneFalls Church, VA, US
    serp_jobs.job_card.full_time +1
    Principal Auditor - Cyber, Risk and Analysis Technology Audit.Capital One's Audit function is a dedicated group of professionals focused on delivering top-quality assurance services to the organiza...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days