Cyber Incident Handling Analyst / Active TS/SCI

Peraton

Deutschland

Vor Ort

EUR 90.000 - 143.000

Vollzeit

14 Tage+
Bewerbungsgenerator

Eine komplette Bewerbung in einer Minute — maßgeschneiderter Lebenslauf und Anschreiben, versandbereit.

Schaffe es an den ATS-Filtern vorbei

Zusammenfassung

Peraton is seeking an experienced Incident Handling Analyst for its Regional Cyber Center-Europe program, based on-site in Wiesbaden, Germany.

The role emphasizes monitoring security feeds, triaging alerts, coordinating responses, and maintaining comprehensive incident records in TheHive and ServiceNow, aligned with CSSP playbooks and DoD standards.

Qualifikationen

  • Bachelor's degree or 11 years of relevant experience considered in lieu of degree.
  • DoD 8140 Cybersecurity – Intermediate level.
  • Active DoD TS/SCI clearance or higher required.
  • Must hold one of the listed certifications (Cisco CyberOps / GIAC / Microsoft SOC Analyst / Blue Team / OSDA).

Aufgaben

  • Monitor security event feeds across IDS/SIEM platforms and escalate incidents per CSSP procedures.
  • Triage alerts, distinguish true positives from false positives, and prioritize response actions.
  • Coordinate incident response across CSSP teams, network operations, and mission owners.
  • Document incidents from detection to resolution with timelines and evidence.
  • Maintain incident tracking systems (TheHive, ServiceNow) for status and audits.
  • Assist post-incident analyses and update CSSP playbooks/SOPs.

Kenntnisse

Incident handling
Cybersecurity
Security incident coordination
Thorough documentation
US citizenship
TS/SCI clearance

Ausbildung

Bachelor's degree in STEM/Business Admin
DoD 8140 - Cybersecurity (Intermediate)
Active DoD TS/SCI clearance
Certifications - Cisco CyberOps / GIAC / MS SOC / Blue Team / OSDA

Tools

TheHive
ServiceNow
Elastic Stack
Splunk
MITRE ATT&CK

Jobbeschreibung

Responsibilities

Peraton is seeking to hire an experienced Incident Handling Analyst for its Regional Cyber Center-Europe program

Location: On-site, Wiesbaden, Germany

Responsibilities:

  • Monitor security event feeds across IDS/SIEM platforms, reviewing alerts and identifying events requiring escalation or incident declaration in accordance with CSSP procedures
  • Triage incoming security alerts, applying analytical judgment to distinguish true positives from false positives and prioritizing response actions based on threat severity and mission impact
  • Coordinate incident response actions across internal CSSP teams, network operations, and mission owners, ensuring timely containment and eradication of identified threats
  • Document all incidents comprehensively from initial detection through resolution, capturing timelines, evidence, analyst actions, and lessons learned in the incident management system
  • Maintain and update incident tracking systems (e.g., TheHive, ServiceNow) to ensure accurate status reporting, SLA compliance, and audit-ready records for all security events
  • Support post-incident analysis and after-action reviews, contributing to root cause identification, process improvement recommendations, and updates to CSSP playbooks and SOPs
Qualifications

Required:

  • Bachelor's degree (STEM/Business Admin)and a minimum of 5 years of cybersecurity or incident response experience, or an associate's degree with a minimum of 7 years of relevant experience; or 11 years of relevant experience in lieu of the bachelors degree
    • Must meet TESA Qualification
  • DoD 8140 - Cybersecurity (Cyber Defense Incident Responder) - Intermediate
  • Certifications - must hold active certifications (one of the following):
    • Cisco CyberOps Professional; OR
    • SANS (any GIAC certification); OR
    • Microsoft Certified: Security Operations Analyst Associate; OR
    • Blue Team Level 1; OR
    • OSDA (Offensive Security Defense Analyst)
  • U.S. citizenship required
  • Active DoD TS/SCI clearance or higher

Preferred:

  • Experience with TheHive or similar case management platforms for structured incident tracking
  • Familiarity with ServiceNow IT Service Management for ticketing and SLA management
  • Proficiency with Elastic Stack or Splunk for security event correlation and investigation
  • Working knowledge of NIST SP 800-61 Computer Security Incident Handling Guide
  • Experience with digital forensics tools (e.g., FTK, Autopsy, Volatility) for evidence collection
  • Familiarity with MITRE ATT&CK framework for TTP mapping during incident analysis
  • Understanding of network protocols and traffic analysis to support incident scoping
  • Experience developing or refining incident response playbooks and standard operating procedures
Peraton Overview

Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world's leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees do the can't be done by solving the most daunting challenges facing our customers. Visit peraton.com to learn how we're keeping people around the world safe and secure.

Target Salary Range

$104,000 - $166,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual's experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.

EEO

EEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.

Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Cyber Response Analyst / Active TS/SCI
Cyber Response Analyst / Active TS/SCI

Peraton • Deutschland

Vor Ort
EUR 90.000 - 143.000
Senior Cyber Incident Handling Analyst / Active TS/SCI
Senior Cyber Incident Handling Analyst / Active TS/SCI

Peraton • Deutschland

Vor Ort
EUR 90.000 - 143.000
Senior Cyber Response Analyst / Active TS/SCI
Senior Cyber Response Analyst / Active TS/SCI

Peraton • Deutschland

Vor Ort
EUR 90.000 - 143.000
External Job Posting Title Senior Cyber Response Analyst / Active TS/SCI
External Job Posting Title Senior Cyber Response Analyst / Active TS/SCI

Peraton • Wiesbaden

Vor Ort
EUR 90.000 - 143.000
External Job Posting Title Senior Cyber Incident Handling Analyst / Active TS/SCI
External Job Posting Title Senior Cyber Incident Handling Analyst / Active TS/SCI

Peraton • Wiesbaden

Vor Ort
EUR 90.000 - 143.000
Cyber Threat Analyst / Active TS/SCI
Cyber Threat Analyst / Active TS/SCI

Peraton • Deutschland

Vor Ort
EUR 90.000 - 143.000
Senior Cyber Threat Analyst / Active TS/SCI
Senior Cyber Threat Analyst / Active TS/SCI

Peraton • Deutschland

Vor Ort
EUR 90.000 - 143.000
Senior Cyber Threat Analyst - Assessment / Active TS/SCI
Senior Cyber Threat Analyst - Assessment / Active TS/SCI

Peraton • Deutschland

Vor Ort
EUR 90.000 - 143.000
Cyber Threat Analyst - Assessment / Active TS/SCI
Cyber Threat Analyst - Assessment / Active TS/SCI

Peraton • Deutschland

Vor Ort
EUR 69.000 - 110.000
Deputy Program Manager / active Top Secret
Deputy Program Manager / active Top Secret

Peraton • Erbenheim

Vor Ort
EUR 96.000 - 153.000