Senior Cyber Threat Analyst / Active TS/SCI

Peraton

Wiesbaden

Vor Ort

EUR 70.000 - 100.000

Vollzeit

14 Tage+

Erhalte mehr Antworten von Arbeitgebern

Versende in nur wenigen Minuten einen passgenauen Lebenslauf.

Zusammenfassung

A cybersecurity firm in Wiesbaden is seeking a Cyber Defense Analyst to analyze advanced persistent threats and produce intelligence products for the Army. This role requires a Bachelor's degree in a relevant field and at least 5 years of cyber threat analysis experience. Responsibilities include analyzing threat activity and conducting RAM memory analysis. Candidates must be U.S. citizens with a TS/SCI security clearance. The position is on-site and offers a critical role in safeguarding Army operations.

Qualifikationen

  • 5 years of cyber threat analysis and intelligence experience required.
  • Must hold active cybersecurity certifications.
  • U.S. citizenship and active DoD TS/SCI security clearance required.

Aufgaben

  • Analyze advanced persistent threat (APT) activity against DoDIN-Europe.
  • Produce cyber threat intelligence products for Army leadership.
  • Conduct RAM and system memory dump analysis.
  • Lead proactive threat hunting operations across networks.

Kenntnisse

Cyber threat analysis
Network logs analysis
Threat intelligence
Penetration techniques

Ausbildung

Bachelor’s degree in STEM/Business Admin
Associate’s degree with 7 years of experience

Tools

Zeek/Bro
Wireshark
Elastic Stack
Splunk
Memory forensics tools (Volatility, Rekall)

Jobbeschreibung

Required
  • Bachelor’s degree (STEM/Business Admin) and a minimum of 5 years of cyber threat analysis and intelligence experience; or an associate’s degree and a minimum of 7 years specialized experience; or 11 years of experience (no degree)
    • Must meet TESA Qualifications
  • DoW 8140 - Cybersecurity (Cyber Defense Analyst) - Advanced
  • Certifications — must hold active certifications (one of the following):
    • GNFA (GIAC Network Forensic Analyst)
    • GCIH (GIAC Certified Incident Handler)
    • GCTI (GIAC Cyber Threat Intelligence)
    • GDSA (GIAC Defensible Security Architecture)
    • GCDA (GIAC Certified Detection Analyst)
    • GREM (GIAC Reverse Engineering Malware)
    • Blue Team Level 2
    • Microsoft Certified: Cybersecurity Architect Expert
    • Zero Point RTO
    • OSDA (Offensive Security Operations and Defensive Analysis)
  • Demonstrated experience in threat analysis of vulnerabilities and penetration techniques; expert knowledge of network logs (firewall, PCAP, NetFlow, Zeek, DNS, web proxy); alert and activity correlation; network diagram review; RAM/system dump analysis; and cyber threat awareness product development
  • U.S. citizenship required
  • Active DoW TS/SCI security clearance
Preferred
  • Expert proficiency with Zeek/Bro for network security monitoring and custom script development for traffic analysis
  • Experience with NetFlow analysis tools (SiLK, nfdump, Elastic) for large-scale network behavior analysis and anomaly detection
  • Advanced Wireshark skills for deep packet inspection and protocol-level adversary activity reconstruction
  • Strong working knowledge of the MITRE ATT&CK framework for threat modeling, TTP mapping, and detection gap identification
  • Experience with threat intelligence platforms (MISP, OpenCTI, Anomali) for IOC management and intelligence sharing
  • Proficiency with Elastic Stack or Splunk for log aggregation, correlation, and threat hunting query development
  • Experience with memory forensics tools (Volatility, Rekall) for RAM dump analysis and malware artifact extraction
  • Familiarity with structured analytic techniques and intelligence community reporting standards for finished product development

Location: On-site, Wiesbaden, Germany

Responsibilities
  • Analyze advanced persistent threat (APT) activity targeting DoDIN-Europe by correlating indicators from multiple intelligence sources, network telemetry, and endpoint data to characterize adversary campaigns and assess risk to Army operations
  • Produce finished cyber threat intelligence products — including threat assessments, trend analyses, and adversary TTPs reports — tailored for both technical operators and senior Army leadership at RCC-E and NETCOM
  • Perform expert-level analysis of network logs including firewall events, PCAP captures, NetFlow records, Zeek/Bro connection logs, DNS query logs, and web proxy data to reconstruct adversary activity and identify lateral movement or exfiltration
  • Conduct RAM and system memory dump analysis to identify malicious processes, injected code, persistence mechanisms, and artifacts of compromise that may not be visible through traditional log-based analysis
  • Lead and support proactive threat hunting operations across RCC-E-managed networks, developing hypothesis-driven hunt packages based on current threat intelligence and MITRE ATT&CK TTPs to uncover undetected adversary activity
  • Develop cyber threat awareness products and briefings for distribution to supported Army units, providing actionable intelligence on emerging threats, vulnerabilities, and recommended defensive measures relevant to the USAREUR-AF operational environment
Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Senior Cyber Incident Handling Analyst / Active TS/SCI
Senior Cyber Incident Handling Analyst / Active TS/SCI

Peraton • Wiesbaden

Vor Ort
EUR 70.000 - 90.000
Cyber Threat Analyst – Assessment / Active TS/SCI
Cyber Threat Analyst – Assessment / Active TS/SCI

Peraton • Wiesbaden

Vor Ort
EUR 50.000 - 70.000
Senior Cyber Response Analyst / Active TS/SCI
Senior Cyber Response Analyst / Active TS/SCI

Peraton • Erbenheim

Vor Ort
EUR 88.000 - 142.000
Senior Cyber Incident Handling Analyst / Active TS/SCI
Senior Cyber Incident Handling Analyst / Active TS/SCI

Peraton • Erbenheim

Vor Ort
EUR 88.000 - 142.000
Cyber Response Analyst / Active TS/SCI
Cyber Response Analyst / Active TS/SCI

Peraton • Erbenheim

Vor Ort
EUR 88.000 - 142.000
Cyber Incident Handling Analyst / Active TS/SCI
Cyber Incident Handling Analyst / Active TS/SCI

Peraton • Erbenheim

Vor Ort
EUR 88.000 - 142.000
Cyber Systems Engineering, Lead Associate
Cyber Systems Engineering, Lead Associate

Peraton • Wiesbaden

Vor Ort
EUR 60.000 - 85.000
Cyber Software Engineering, Lead Associate
Cyber Software Engineering, Lead Associate

Peraton • Wiesbaden

Vor Ort
EUR 60.000 - 80.000
Cyber Threat Analyst - Assessment / Active TS/SCI
Cyber Threat Analyst - Assessment / Active TS/SCI

Peraton • Wiesbaden

Vor Ort
EUR 68.000 - 110.000
Medical insurance
401(k)
Paid time off (PTO)
Senior Cyber Threat Analyst - Assessment / Active TS/SCI
Senior Cyber Threat Analyst - Assessment / Active TS/SCI

Peraton • Wiesbaden

Vor Ort
EUR 88.000 - 142.000
Medical, dental, and vision insurance
401(k) plan
Paid time off