> Markdown version of [/jobs/ext/1971929-cirt-tier-1-analyst-active-secret](https://www.wearedevelopers.com/jobs/ext/1971929-cirt-tier-1-analyst-active-secret). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # CIRT Tier 1 Analyst / Active Secret - **Company:** Peraton Inc - **Location:** Arlington, VA, United States - **Experience:** Expert - **Salary:** $80,000.0 - $128,000.0 - **Contract:** Permanent contract - **Skills:** Cloud Computing Security, Cyber Security, Issue Tracking Systems, Network Protocols, Windows PowerShell, Phishing, Mitre Att&ck, Azure Security Center, Splunk, Servicenow - **Published:** August 7, 2026 - **Apply:** https://www.careerjet.com/job/usb7475ed1de106d7efdaddc2e8118883d/eaa ## About the Role * Bachelor's degree and at least 2 years of experience or a High School diploma and 6 years of experience. * Must possess or be able to obtain at least one of the following certifications before start date. Continued certification required as a condition of employment: * CCNA-Security * CND * CySA+ * GICSP * GSEC * Security+ CE * SSCP * Demonstrated knowledge of ticketing systems (i.e. ServiceNow, Remedy). * Demonstrated knowledge of computer networking protocols and principles. * Demonstrated knowledge of cybersecurity principles, practices, threats, and vulnerabilities. * Demonstrated knowledge of incident response principles and practices. * Skill in critical thinking by evaluating information and making independent decisions. * Demonstrated ability to work autonomously while taking initiative on assigned responsibilities. * Ability to follow established procedures and written guidance with precision and attention to detail. * Demonstrated skills in taking ownership of problems and seeing them through to completion. * U.S. Citizenship required. * Active Secret security clearance., * Experience with Splunk for security monitoring and alert triage. * Knowledge of Microsoft Defender for Endpoint for security monitoring and response. * Experience with ServiceNow for ticketing and workflow management. * Knowledge of cloud security monitoring fundamentals. * Experience with email security and phishing analysis. * Knowledge of the MITRE ATT&CK framework. * Familiarity with PowerShell and basic scripting concepts. ## Description * Detect, classify, process, track, and report on cyber security events and incidents. * Perform triage of incoming alerts and requests in a 24x7x365 environment. * Monitor and triage the CIRT hotline, email inboxes, and fax. * Create tickets and initiate workflows as instructed in SOPs. * Triage Splunk Enterprise Security (ES) Alerts and Microsoft Defender for Endpoint (MDE) Alerts. * Identify and triage benign, spam, exercise, and malicious phishing email. * Perform binary artifact triage to understand malware behavior. * Coordinate and collaborate with Department teams as needed to analyze and respond to events and incidents. * Report incident information to the Cybersecurity and Infrastructure Security Agency (CISA). * Collaborate with other local, national and international CIRTs as directed. * Deliver and oversee remediation activities. * Conduct shift change briefs., MANTECH seeks a motivated, career and customer-oriented Budget Analyst to join our team in Arlington, VA. This is an onsite position. Responsibilities include, but are not limite… + 4 days ago, MANTECH seeks a motivated, career and customer-oriented Senior Budget Analyst to join our team in Arlington, VA. This is an onsite position. Responsibilities include, but are not… + 4 days ago ## Related Videos - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [AI in Production: applied AI & enterprise use cases](https://www.wearedevelopers.com/videos/100130-ai-in-production-applied-ai-enterprise-use-cases) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)