CYSOC Analyst

Peraton Inc
Washington, DC, United States
14 days ago
Apply on diversityjobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
$112,000.0 - $179,000.0
Working hours
Regular working hours

Tech stack

CompTIA Security+ Cyber Security Domain Name System (DNS) Intelligence Analysis Network Security Pcap NetFlow Routing Packet Analyzer Remote Access Technology Security Information and Event Management TCP/IP
+9 more
Workflow Management Systems Mitre Att&ck Malware Cyber Threat Analysis Tanium Platform Expertise Cybercrime Real Time Data Cyber Warfare Splunk

Job description

Develops detailed plans for the support of a range of cyber operations through collaboration with planners, operators, analysts, and military leadership. Participates in targeting selection, validation, synchronization, integration, and execution of cyber activities. Analyzes, reviews, and monitors strategies, doctrine, policies, and other directives to ensure compliance with mandated regulations from both the government at large and the military customer. Assists and advises inter-agency partners in identifying and developing standard operation procedures (SOPs) for operational support in achievement of organizational objectives. Employees have knowledge of cyber security principles, operations security, cyber threats and vulnerabilities, and knowledge of national regulations, policies, and ethics as they relate to cyber security. Develops, reviews, and applies specific cyber operations guidance for integration into broader planning activities. Responsible for providing input to stakeholders for the development and refinement of cyber operations objectives, priorities, strategies, plans and programs. Provides input into the administrative and logistical elements of an operational support plan. Employees review, approve, prioritize, and submit operational requirements for research, development, and/or acquisition of cyber capabilities. Collaborates with internal and external stakeholders to leverage analytical and technical expertise to ensure mission goals are met. Typically has prior military experience and a deep understanding of military hierarchy and leadership. May work in the financial sphere to assist with planning goals, programming objectives, and may be responsible for preparing real time data for leadership. Assists in developing new approaches to improve organizational framework through the coordination and integration of staff processes. Drafts and provides briefings, information/decision papers, policy documents, staffing packages, letters, memorandums, and official multimedia correspondence.

Requirements

Active TS/SCI or Q/SCI clearance required.

  • Minimum of 12 years with BS/BA; Minimum of 10 years with MS/MA; Minimum of 7 years with Ph.D., 16 years with a HS Diploma
  • Experience supporting Security Operations Center (SOC), Computer Network Defense (CND), or cyber operations environments.
  • Hands-on experience with:

  • Splunk Enterprise Security (ES)
  • CrowdStrike Falcon
  • Tanium
  • SIEM and log aggregation platforms
  • Endpoint Detection and Response (EDR) tools
  • Security ticketing and workflow management systems

Experience performing:

  • Incident response
  • Threat hunting
  • Malware analysis
  • Alert triage and escalation
  • Log correlation and forensic analysis

Strong understanding of:

  • TCP/IP protocol suite
  • DNS
  • Routing and switching concepts
  • Network security architecture
  • Remote access security technologies
  • Enterprise security monitoring

Experience analyzing:

  • NetFlow data
  • Packet captures (PCAP)
  • Security event logs
  • Indicators of compromise (IOCs)

Knowledge of:

  • MITRE ATT&CK framework
  • Threat actors and adversary campaigns
  • Cyber kill chain methodologies
  • Intelligence Community cybersecurity operations

Ability to communicate technical findings clearly through written reports and verbal briefings., * Prior experience supporting Intelligence Community (IC), Department of Defense (DoD), or other Federal Government cybersecurity programs.

  • Familiarity with CDOC/SOC operational environments and federal cybersecurity compliance frameworks.
  • Experience with classified network environments and cross-domain security operations.
  • Industry certifications such as:

  • CompTIA Security+
  • CySA+
  • CEH
  • GCIH
  • GCIA
  • CISSP

Knowledge of:

  • NIST 800-series publications
  • RMF (Risk Management Framework)
  • Continuous Diagnostics and Mitigation (CDM)
  • Cyber threat intelligence analysis

About the company

Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world’s leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees do the can’t be done by solving the most daunting challenges facing our customers. Visit peraton.com to learn how we’re keeping people around the world safe and secure. Target Salary Range

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on diversityjobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:23 min

Understanding the complexity of cybersecurity domains

Jennifer Reif · LIVE

5:02 min

Mapping distributed compute paradigms to modern vehicles

Joachim Werner · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

3:50 min

Queues in TCP stacks and continuous network connections

Clemens Vasters Clemens Vasters · World Congress 2022

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

Videos

See all

Related articles

See all