Company

PeratonSee more

addressAddressUnited States
CategoryInformation Technology

Job description

Responsibilities

We are seekingCyber Incident Responder to join our team in support of the U.S. Army Europe Regional CyberCenter (RCC-E) in Wiesbaden, Germany.

 

In this role, you will:

  • Be working as an expert to perform analysis of cyber relate events to detect and deter malicious actors using SIEM technologies focused on the threat to networked weapons platforms and US DoD information networks.
  • Need to be able to support this position having the potential to work multiple shifts in a rotational schedule.
  • Analyze host and network events to determine the impact on current operations, conduct research to determine advisory capability, and develop analytics based on indicators of compromise to leverage the SIEM. 
  • Produce high-quality papers, presentations, recommendations, and findings for senior US government intelligence and network operations officials.

You will have the opportunity to:

  • Perform documentation and vetting of identified vulnerabilities for operational use.
  • Monitor and action SIEM platforms for alerts, events, and rules providing insight into malicious activities and/or security posture violations.
  • Review intrusion detection system alerts for anomalies that may pose a threat to the customer’s network.
  • Identify and investigate vulnerabilities, asses exploit potential, and suggest analytics for automation in the SIEM engines.
  • Report events through the incident handling process of creating incident tickets for deeper analysis and triage activities.
  • Issue triage steps to local touch labor organizations and Army units to mitigate or collect on-site data.
  • Develop unique queries and rules in the SIEM platforms to further detection for first line cyber defenders.
  • Provide daily updates to Cyber Security Service Provider Division higher staff on intrusion detection operation and trends of events causing incidents.
  • Draft reports of remotely exploitable vulnerabilities to increase customer situational awareness and improve the customer’s cyber security posture.
  • Assist all sections of the Cyber Security Service Provider Division as required in performing Analysis and other duties as assigned.

Qualifications

Required:

 

  • BA/BS in Engineering, Computer Science, Science, Business Administration or Mathematics and 5 years of specialized experience, or an Associate’s degree and 7 years of specialized experience. An additional 4 years of experience may be considered in lieu of education/degree. 
  • Experience in packet captures and analyzing a network packet.
  • Experience with intrusion detection systems such as Snort, Suricata, and Zeek.
  • Experience with the Elastic SIEM.
  • Ability to work independently as well as part of a team.
  • Ability to work on shift rotation to assist the team.
  • DoD 8140 DCWF 531 & 511 certified in the following: 
    • DCWF 531 - B.S.+ or GCFA, GCIA, CCSP, CEH, CFR, Cloud+, CYSA+, GCED, GICSP, PenTest+
    • DCWF 511 - B.S.+ or GCFA, GCIA, CFR, Cloud+, CYSA+, GCED, PenTest
    • A minimum of ONE of the following upon start: Cisco CyberOps Professional, GCED, GCFA, GCFE, GCIH, GNFA, DCITA CIRC, Blue Team level 1, FIWE or Offensive Security OSDA
  • Must have a full, complete, and in-depth understanding of all aspects of Defensive Cyber Operations.
  • Must be fluent in all aspects of government and corporate communications media to include all MS Office products and common task ticketing systems.
  • Must have a good breadth of knowledge of common ports and protocols of system and network services.
  • Must have the demonstrated ability to communicate with a variety of stakeholders in a variety of formats.
  • U.S. citizenship and an active TS with SCI Clearance (ICD 706 Eligibility).

 

Preferred Qualifications:

  • Experience with writing Snort or Suricata IDS rules.
  • Experience in developing complex dashboards, report, and automated searches in Elastic/Kibana.
  • Experience with analyzing packets using Arkime.
  • Experience with Microsoft Windows event IDs.
  • Experience with Linux audit log analysis.
  • Familiarity with Git and VScode.
  • Experience with one or more scripting languages such as PowerShell, Bash, Python.

Peraton Overview

Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world’s leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees do the can’t be done by solving the most daunting challenges facing our customers. Visit peraton.com to learn how we’re keeping people around the world safe and secure.

Target Salary Range

$66,000 - $106,000. This represents the typical salary range for this position based on experience and other factors.

Benefits

Team events
Refer code: 9306151. Peraton - The previous day - 2024-05-24 07:50

Peraton

United States
Jobs feed

Front Desk Agent PM

Aloft Newport On The Levee

Newport, KY

$15 - $16 an hour

Store Associate

Cvs Health

Erlanger, KY

$15 an hour

Warehouse Associate - Entry Level

Ferguson Enterprises, Llc

Halethorpe, MD

$16.39 - $24.58 an hour

SALES ASSOCIATE

Dollar General

Erlanger, KY

$20.4K - $25.9K a year

Machine Operator (Packer) - Overnight Weekend Shift

Berry Global, Inc

Baltimore, MD

$26.5K - $31.8K a year

4am Inbound (Stocking) (T1200)

Target

Florence, KY

$15 an hour

SALES FLOOR ASSOCIATE

Dollar Tree

Kentucky, United States

$19.8K - $25.1K a year

Sales Associate Retail

Paradies Lagardere

Erlanger, KY

$11.50 - $13.00 an hour

Pet Care Store Associate

Feeders Pet Supply

Kentucky, United States

$10.00 - $11.75 an hour

Store Associate, PT - Monroe

Nike

Cincinnati, OH

$15.50 an hour

Share jobs with friends

Related jobs

Cyber Incident Responder

Critical Incident Responder - LPC, LMFT, LICSW or Psychologist

R3 Continuum

$70 - $80 an hour

Leesburg, VA

2 weeks ago - seen

Cybersecurity Incident Responder/Cyber Engineer Senior II

Node.digital

Lorida, FL

3 weeks ago - seen

Associate Cyber Incident Responder

Highmark Health

Sylvania, PA

4 weeks ago - seen

Cyber Incident Responder

Highmark Health

Sylvania, PA

2 months ago - seen

Cyber Incident Responder

Highmark Health

Remote - Pennsylvania, United States

2 months ago - seen

Critical Incident Responder - LCPC, LCMFT, LSCSW or Licensed Clinical Psychotherapist

R3 Continuum

$70 - $80 an hour

Overland Park, KS

2 months ago - seen

Lead Cyber Defense Incident Responder

Nike

Beaverton, OR

3 months ago - seen

Lead Incident Responder

Rapid7

Arlington, VA

4 months ago - seen

SOC Incident Responder (Intermediate)

Edgewater Federal Solutions, Inc.

$95.6K - $121K a year

Bethesda, MD

4 months ago - seen

Lead Incident Responder - CSIRT

U.s. Bank National Association

$123,165 - $159,390 a year

Charlotte, NC

4 months ago - seen

Senior Cybersecurity Incident Responder

Maveris

Austin, TX

4 months ago - seen

Incident Responder

JetBlue

Orlando, FL

5 months ago - seen

Incident Responder

Chainlink Labs

Remote - United States

5 months ago - seen

Senior Incident Responder

JetBlue

Washington, DC

5 months ago - seen