Cyber Incident Response Analyst with OT/ICS/SCADA / Travel & Active TS

Peraton

Arlington (VA)

On-site

USD 104,000 - 166,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Peraton is seeking a Cyber Incident Response Analyst in Arlington, VA. This role involves responding to cybersecurity incidents across industrial control systems and critical infrastructure. The ideal candidate will leverage their expertise to provide actionable recommendations, ensure thorough incident documentation, and stay updated on the latest cybersecurity trends.

The successful candidate will hold a relevant degree and possess significant Threat Hunting or DFIR experience. The salary range for this position is between $104,000 and $166,000 based on various factors.

Qualifications

  • Bachelor's degree and 5 years of relevant experience; Master's degree and 3 years, or additional experience in lieu of education.
  • 1-2 years of relevant Threat Hunting or DFIR experience supporting Critical Infrastructure.
  • Experience in security site assessments and network security.

Responsibilities

  • Respond to cybersecurity incidents across ICS, OT, and IT.
  • Apply knowledge to resolve incidents and conduct threat hunts.
  • Support forensic analysis and advise decision-makers.

Skills

Threat Hunting
Incident Response
Security Assessments
SIEM Tools
Network Protocol Analysis
Digital Forensics
Scripting (Python, Bash)

Education

Bachelor's degree in relevant field
Master's degree in relevant field

Tools

SIEM tools (Splunk)
Network-based detection tools
Event analysis tools

Job description

Cyber Incident Response Analyst (ICS/OT/SCADA)

Location: Onsite in Arlington, VA

Travel: Approximately 40%

Clearance requirement: Top Secret/SCI (Active TS)

Requisition ID: 2026-163351

Position Category: Intel and Threat Analysis

Responsibilities

Respond to cybersecurity incidents across industrial control systems, operational technology, and information technology environments. Provide actionable recommendations to prevent recurrence within critical infrastructure sectors. Apply proactive threat hunting and incident resolution across moderate complexity problems. Support technical teams, forensic analysts, and mission partners.

  • Respond to cybersecurity incidents across ICS, OT, and IT environments and provide recommendations to prevent recurrence within critical infrastructure sectors.
  • Apply functional knowledge to resolve incidents, conduct proactive threat hunts, and contribute to solutions for problems of moderate scope and complexity.
  • Support highly technical operations and forensic analysis while advising client decision‑makers.
  • Provide sector‑specific expertise for one or more critical infrastructure areas, including Water, Power, Critical Manufacturing, and Transportation.
  • Follow established procedures for incident response and escalation.
  • Help define and refine response procedures for industrial control system environments.
  • Apply traditional incident response and threat‑troaching trade‑craft to industrial control system and critical infrastructure environments while accounting for operational constraints.
  • Collaborate with host, network, and cloud forensic analysts to meet mission requirements for incident response and threat‑touging engagements.
  • Maintain accurate documentation of incident response activities and findings.
  • Prepare and deliver incident reports to management and stakeholders.
  • Work effectively in a team environment and contribute to mission success.
  • Stay current on cybersecurity trends to enhance hunt and response operations.
  • Demonstrate strong attention to detail, critical thinking, and customer‑service orientation.
  • Self‑teach and test new tools, methodologies, and techniques as needed.
  • Meet onsite requirements of at least one day per week (up to three days depending on mission needs).
  • Travel up to 40%.
Qualifications

Required Qualifications:

  • Bachelor's degree and 5 years of relevant experience; Master's degree and 3 years. An additional 4 years of relevant experience will be considered in lieu of a degree.
  • Must have 1‑2 years of relevant Threat Hunting or DFIR experience directly supporting Critical Infrastructure (CI) / IC environments.
  • Experience conducting security site assessments, including analysis of network security architecture, baseline ports/protocols/services, and asset characterization.
  • Experience using SIEM tools for pattern identification, anomaly detection, and trend analysis.
  • Experience analyzing IC network protocols such as ModBus, ENIP/CIP, BACnet, DNP3, etc.
  • Experience with common open‑source and commercial tools used in event analysis, incident response, forensics, malware analysis, or security operations.
  • Experience with host‑based and network‑based collection and detection tools (OSS/COTS).
  • U.S. citizenship required.
  • Active Top Secret security clearance.
  • Ability to obtain a TS/SCI for continued employment.
  • Ability to obtain and maintain a favorably adjudicated DHS background investigation.

Desired Qualifications:

  • Certifications such as GISCP, GCFA, GNFA, GRID, or OT sensor certifications.
  • 2+ years of Threat Hunting or DFIR experience.
  • Experience on DoD Cyber Protection Teams.
  • Experience performing digital forensics on laptops/desktops, PLCs, HMIs, Historians, and SCADA systems.
  • Experience with SIEM platforms (e.g., Splunk) including threat hunting, analytic development, dashboards, and reporting.
  • Familiarity with critical infrastructure frameworks (NIST, IEC 62443).
  • Ability to automate repeatable tasks.
  • Scripting experience in Python, Bash, PowerShell, and/or JavaScript.
Target Salary Range

$104,000 - $166,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual's experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.

EEO

EEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

External Job Posting Title ICS Threat Hunt Analyst / Active Top Secret
External Job Posting Title ICS Threat Hunt Analyst / Active Top Secret

Peraton • Arlington (VA), Northern (KY)

Hybrid
USD 86,000 - 138,000
ICS Threat Hunt Analyst / Active Top Secret
ICS Threat Hunt Analyst / Active Top Secret

Peraton • Arlington (VA)

On-site
USD 86,000 - 138,000
Sr Industrial Control System Cyber Threat Intelligence Analyst with OT/CTI/Threat Hunt experience
Sr Industrial Control System Cyber Threat Intelligence Analyst with OT/CTI/Threat Hunt experience

Peraton • Arlington (VA)

On-site
USD 100,000 - 130,000
ICS Threat Intelligence Strategist (OT/SCADA)
ICS Threat Intelligence Strategist (OT/SCADA)

Peraton • Arlington (VA)

On-site
USD 100,000 - 130,000
Jr Industrial Control System Cyber Threat Intelligence Analyst / Active Top Secret, SCI eligibility
Jr Industrial Control System Cyber Threat Intelligence Analyst / Active Top Secret, SCI eligibility

Peraton • Arlington (VA)

On-site
USD 86,000 - 138,000
Cyber Incident Response Analyst
Cyber Incident Response Analyst

CACI International Inc • Hampton (VA)

On-site
USD 75,000 - 158,000
ICS/OT Cyber Incident Responder for Critical Infrastructure
ICS/OT Cyber Incident Responder for Critical Infrastructure

Peraton • Arlington (VA)

On-site
USD 104,000 - 166,000
OpenSource Cyber Threat Intelligence Analyst
OpenSource Cyber Threat Intelligence Analyst

Peraton • Arlington (VA)

On-site
USD 104,000 - 166,000
Cyber Defense Analyst
Cyber Defense Analyst

Saic • Fort Meade (MD)

On-site
USD 120,000 - 160,000
CTI Analyst - Mid / Public Trust
CTI Analyst - Mid / Public Trust

Peraton • Warrenton (VA)

On-site
USD 66,000 - 106,000