Senior Cyber Manager

Peraton

United States

On-site

USD 146,000 - 234,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Peraton is seeking a Cyber Incident Response Analyst Manager to lead a SOC team in a government CSOC based in Washington, D.C. The role focuses on security event monitoring, advanced analytics, and incident response within a layered defense strategy.

Qualified candidates will hold a TS clearance with SCI eligibility, 12+ years of cyber experience, and a DoD 8570.1-M IAT II certification. The position requires leadership and extensive enterprise incident management expertise.

Qualifications

  • BS with 12+ years of relevant experience; in lieu of degree, 4 extra years may be considered
  • Active Top Secret clearance with SCI eligibility is required
  • Bachelor's degree in Computer Science, Information Systems, or equivalent
  • Experience managing and leading a team
  • Experience managing cyber incidents in enterprise environments
  • Current DoD 8570.1-M IAT Level II certification

Responsibilities

  • Perform technical analysis on cybersecurity issues focusing on network and host activity
  • Triage IDS/IPS alerts and correlate threat data
  • Prepare analysis reports detailing observables and conclusions
  • Analyze large volumes of network flow data to identify patterns
  • Develop automations for data parsing and simple analytics
  • Design and implement IDS/IPS signatures and tune sensors
  • Develop security metrics and trend reports
  • Prepare security documentation and test plans
  • Provide information assurance support and risk assessments
  • Conduct complex risk and vulnerability analyses

Skills

Team leadership
Incident response
Cyber security
Scripting (Python/PowerShell)
Security monitoring

Education

Bachelor's in Computer Science or Information Systems

Tools

Cisco Firepower
Cisco Sourcefire
Snort
YARA
HIPS
Splunk
ArcSight
Wireshark
Tanium

Job description

Responsibilities

Peraton is currently seeking a Cyber Incident Response Analyst Manager to support a government Cyber Security Operation Center (CSOC) onsite in Washington D.C. The program provides comprehensive Computer Network Defense and Incident Response support monitoring and analysis of potential threat activity targeting the enterprise. The Incident Response Analyst Manager will conduct security event monitoring, advanced analytics, and response activities in support of the CND operational mission, as well as manage a team of SOC analysts. We are seeking candidates with diverse backgrounds in cyber security systems operations, analysis and incident response.

  • Perform technical analysis on a wide range of cybersecurity issues, with a focus on network activity, host activity, and data. This includes, but is not limited to: network flow (i.e. netflow) or related forms of session summary data, signature-based IDS/IPS alert/event data, full packet capture (PCAP) data, proxy and application server logs (various types).
  • Triage IDS/IPS alerts, collect related data from various systems, review open and closed source information on related threats & vulnerabilities, diagnose observed activity for likelihood of system infection, compromise or unintended/high-risk exposure.
  • Prepare analysis reports detailing background, observables, analysis process & criteria, and conclusions.
  • Analyze large volumes of network flow data for specific patterns/characteristics or general anomalies, to trend network activity and to correlate flow data with other types of data or reporting regarding enterprise-wide network activity.
  • Leverage lightweight programming/scripting skills to automate data-parsing and simple analytics. Document key event details and analytic findings in analysis reports and incident management systems. Identify, extract and characterize network indicators from cyber threat intelligence sources, incident reporting and published technical advisories/bulletins.
  • Assess cyber indicators/observables for technical relevance, accuracy, and potential value/risk/reliability in monitoring systems. Recommend detection and prevention/mitigation signatures and actions as part of a layered defensive strategy leveraging multiple capabilities and data types.
  • Develop IDS/IPS signatures, test and tune signature syntax, deploy signatures to operational sensors, and monitor and tune signature and sensor performance.
  • Fuse open-source threat & vulnerability information with data collected from sensors across the enterprise into cohesive and comprehensive analysis.
  • Develop security metrics and trend analysis reports
  • Designs, develops, and implements security requirements within an organization's business processes.
  • Prepares documentation from information obtained from customer using accepted guidelines.
  • Prepares security test and evaluation plans.
  • Provides certification and accreditation support in the development of security and contingency plans and conducts complex risk and vulnerability assessments.
  • Analyzes policies and procedures against Federal laws and regulations and provides recommendations for closing gaps.
  • Recommends system enhancements to improve security deficiencies.
  • Develops, tests, and integrates computer and network security tools.
  • Secures system configurations and installs security tools, scans systems to determine compliancy and report results and evaluates products and various aspects of system administration.
  • Conducts security program audits and develops solutions to lessen identified risks.
  • Provides information assurance support for the development and implementation of security architectures to meet new and evolving security requirements.
  • Provides assistance in computer incident investigations.
  • Performs vulnerability assessments including development of risk mitigation strategies.
Qualifications

Required:

  • BS with 12+ Years of relevant experience, 4 additional years of relevant experience may be considered in lieu of a degree
  • Active Top Secret clearance with SCI eligibility is required
  • Bachelor's degree in Computer Science, Information Systems, or equivalent education or work experience (additional relevant work experience can be substituted for a degree)
  • Experience managing and leading a team
  • Experience managing cyber incidents in enterprise environments
  • Must have a current DoD 8570.1-M IAT Level II certification
Desired
  • Desired Certifications: CEH, GCIH, GCIA, GCFA
  • 3+ years in a SOC or Incident Response role
  • Experience with Cisco Firepower, Cisco Sourcefire, Cisco Advanced Malware Protection, Cisco Stealthwatch, Cisco Umbrella
  • Experience with deploying and writing signatures (Snort, YARA, HIPS)
  • Experience with network hunting utilizing Zeek/Bro
  • Experience with McAfee ePO, HBSS
  • Splunk: Create log searches, dashboards, setting up alerts, and scheduled reports to help detect and remediate security concerns.
  • Experience with ArcSight
  • Experience with Wireshark and packet analysis
  • Experience with Tanium or other endpoint solutions
  • Working knowledge of scripting languages such as Python, PowerShell, Shell
  • Knowledge of Regular Expressions
  • Knowledge of server and client operating systems
  • Participate in development and reporting of security metrics
  • Experience in a SOC or Incident Response role
  • Excellent communication, leadership, and decision-making skills
Peraton Overview

Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world's leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees do the can't be done by solving the most daunting challenges facing our customers. Visit peraton.com to learn how we're keeping people around the world safe and secure.

Target Salary Range

$146,000 - $234,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual's experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.

EEO

EEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Deputy Operations Lead / Active Top Secret
Deputy Operations Lead / Active Top Secret

Peraton • Beltsville (MD)

On-site
USD 86,000 - 138,000
NOSC Cyber Analyst Junior
NOSC Cyber Analyst Junior

Peraton • United States

On-site
USD 66,000 - 106,000
Operations Lead / Active Top Secret
Operations Lead / Active Top Secret

Peraton • Beltsville (MD)

On-site
USD 135,000 - 216,000
Cyber Monitoring Signature Analyst
Cyber Monitoring Signature Analyst

Peraton • Beltsville (MD)

On-site
USD 80,000 - 128,000
NOSC Cyber Analyst Junior
NOSC Cyber Analyst Junior

Peraton • Arlington (VA)

On-site
USD 66,000 - 106,000
SITEC - Cyber Defense Incident Responder (SR)- Fort Bragg, NC
SITEC - Cyber Defense Incident Responder (SR)- Fort Bragg, NC

Peraton • Fort Bragg (NC)

On-site
USD 80,000 - 128,000
External Job Posting Title Operations Lead / Active Top Secret
External Job Posting Title Operations Lead / Active Top Secret

Peraton • Beltsville (MD)

On-site
USD 135,000 - 216,000
External Job Posting Title Cyber Monitoring Signature Analyst
External Job Posting Title Cyber Monitoring Signature Analyst

Peraton • Beltsville (MD)

On-site
USD 80,000 - 128,000
Junior Cyber Incident Analyst - Notification Specialist
Junior Cyber Incident Analyst - Notification Specialist

Peraton • Arlington (VA)

On-site
USD 80,000 - 128,000
Cyber Monitoring Signature Analyst
Cyber Monitoring Signature Analyst

Peraton • United States

On-site
USD 80,000 - 128,000