Cyber Incident Handling Analyst / Active TS/SCI

Peraton

Erbenheim

Vor Ort

EUR 88.616 - 141.445

Vollzeit

14 Tage+

Erhalte mehr Antworten von Arbeitgebern

Versende in nur wenigen Minuten einen passgenauen Lebenslauf.

Zusammenfassung

Peraton is looking for an experienced Incident Handling Analyst in Erbenheim, Germany. The candidate will monitor security events, triage alerts, and coordinate incident responses with various teams. A Bachelor's degree in a relevant field and 5 years of experience in cybersecurity or incident response are required, along with certifications and a DoD TS/SCI clearance. The role offers a salary range of $104,000 to $166,000 depending on experience and qualifications.

Qualifikationen

  • 5+ years of cybersecurity or incident response experience required.
  • Must hold relevant certifications like Cisco CyberOps Professional or SANS GIAC.
  • Active DoD TS/SCI clearance required.

Aufgaben

  • Monitor security event feeds and escalate incidents as necessary.
  • Coordinate incident response actions ensuring timely threat containment.
  • Document incidents with timelines, evidence, and analyst actions.

Kenntnisse

Cybersecurity incident response
Analytical judgment
Incident tracking
Network protocol analysis
Digital forensics

Ausbildung

Bachelor's degree in STEM/Business Admin
Master's degree preferred

Tools

TheHive
ServiceNow
Elastic Stack
Splunk
FTK
Autopsy
Volatility

Jobbeschreibung

Responsibilities

Peraton is seeking to hire an experienced Incident Handling Analyst for its Regional Cyber Center-Europe program

Location: On-site, Wiesbaden, Germany

  • Monitor security event feeds across IDS/SIEM platforms, reviewing alerts and identifying events requiring escalation or incident declaration in accordance with CSSP procedures
  • Triage incoming security alerts, applying analytical judgment to distinguish true positives from false positives and prioritizing response actions based on threat severity and mission impact
  • Coordinate incident response actions across internal CSSP teams, network operations, and mission owners, ensuring timely containment and eradication of identified threats
  • Document all incidents comprehensively from initial detection through resolution, capturing timelines, evidence, analyst actions, and lessons learned in the incident management system
  • Maintain and update incident tracking systems (e.g., TheHive, ServiceNow) to ensure accurate status reporting, SLA compliance, and audit-ready records for all security events
  • Support post‑incident analysis and after‑action reviews, contributing to root cause identification, process improvement recommendations, and updates to CSSP playbooks and SOPs
Qualifications

Required:

  • Bachelor's degree (STEM/Business Admin) and a minimum of 5 years of cybersecurity or incident response experience, or an associate's degree with a minimum of 7 years of relevant experience; or 11 years of relevant experience in lieu of the bachelor's degree
    • Must meet TESA Qualification
  • DoD 8140 - Cybersecurity (Cyber Defense Incident Responder) - Intermediate
  • Certifications - must hold active certifications (one of the following):
    • Cisco CyberOps Professional; OR
    • SANS (any GIAC certification); OR
    • Microsoft Certified: Security Operations Analyst Associate; OR
    • Blue Team Level 1; OR
    • OSDA (Offensive Security Defense Analyst)
  • U.S. citizenship required
  • Active DoD TS/SCI clearance or higher

Preferred:

  • Experience with TheHive or similar case management platforms for structured incident tracking
  • Familiarity with ServiceNow IT Service Management for ticketing and SLA management
  • Proficiency with Elastic Stack or Splunk for security event correlation and investigation
  • Working knowledge of NIST SP 800-61 Computer Security Incident Handling Guide
  • Experience with digital forensics tools (e.g., FTK, Autopsy, Volatility) for evidence collection
  • Familiarity with MITRE ATT&CK framework for TTP mapping during incident analysis
  • Understanding of network protocols and traffic analysis to support incident scoping
  • Experience developing or refining incident response playbooks and standard operating procedures
Target Salary Range

$104,000 - $166,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual's experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.

EEO

EEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.

Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Senior Cyber Incident Handling Analyst / Active TS/SCI
Senior Cyber Incident Handling Analyst / Active TS/SCI

Peraton • Erbenheim

Vor Ort
EUR 88.000 - 142.000
Cyber Response Analyst / Active TS/SCI
Cyber Response Analyst / Active TS/SCI

Peraton • Erbenheim

Vor Ort
EUR 88.000 - 142.000
Senior Cyber Response Analyst / Active TS/SCI
Senior Cyber Response Analyst / Active TS/SCI

Peraton • Erbenheim

Vor Ort
EUR 88.000 - 142.000
Senior Cyber Incident Handling Analyst / Active TS/SCI
Senior Cyber Incident Handling Analyst / Active TS/SCI

Peraton • Wiesbaden

Vor Ort
EUR 70.000 - 90.000
Cyber Systems Engineering, Lead Associate
Cyber Systems Engineering, Lead Associate

Peraton • Erbenheim

Vor Ort
EUR 88.000 - 142.000
Cyber Threat Analyst - Assessment / Active TS/SCI
Cyber Threat Analyst - Assessment / Active TS/SCI

Peraton • Wiesbaden

Vor Ort
EUR 68.000 - 110.000
Medical insurance
401(k)
Paid time off (PTO)
Senior Cyber Threat Analyst - Assessment / Active TS/SCI
Senior Cyber Threat Analyst - Assessment / Active TS/SCI

Peraton • Wiesbaden

Vor Ort
EUR 88.000 - 142.000
Medical, dental, and vision insurance
401(k) plan
Paid time off
Senior Systems Administration Support (UNIX/Linux OS) / Active Secret
Senior Systems Administration Support (UNIX/Linux OS) / Active Secret

Peraton • Erbenheim

Vor Ort
EUR 95.000 - 153.000
Senior Cyber Threat Analyst / Active TS/SCI
Senior Cyber Threat Analyst / Active TS/SCI

Peraton • Wiesbaden

Vor Ort
EUR 70.000 - 100.000
Senior Cyber Incident Response Investigator (all genders)
Senior Cyber Incident Response Investigator (all genders)

Accenture DACH • München

Vor Ort
EUR 55.000 - 75.000
Flexible working models
Experienced mentors
Extensive training and development offers
+2