Required Qualifications:
- Minimum of 12 years with BS/BA; Minimum of 10 years with MS/MA; Minimum of 7 years with a PhD. Will consider HS with 16 years of relevant experience or Associates degree with 14 years of experience
- Must have an IA certification upon start: CCNA-Security, CCNA-Cybersecurity, CySA+, GICSP, GSEC, Security+, CND, or SSCP
- Able to support surge operations if mission requires
- Experience with scripting languages (e.g., PowerShell, BASH, Python, etc.) for automating analysis tasks, parsing artifacts, or developing tooling in support of malware or forensic workflows
- Able to examine suspicious or malicious software—using static, dynamic, and hybrid techniques
- Experienced in conducting analysis of malicious software to determine what it does, how it works, and how to detect, contain, and remove it
- Experience with dead-box (static) forensic analysis and live (dynamic) forensic/incident handling analysis
- Able to perform reverse-engineering on executable code and analysis of non-compiled malicious content such as scripts, encoded commands, macros, and obfuscated files
- Experience with DOD standards of reporting
- Skilled in inspecting packet captures (PCAPs) for domains, URI paths, protocols, User Agent strings, TLS metadata, and other artifacts that may indicate compromise
- US Citizenship is required
- Active TS with ability to obtain/maintain SCI and Polygraph
Preferred Qualifications:
- Active, or previously held, GIAC Certified Forensic Analyst (GCFA) certification
Peraton seeks a Senior Forensic and Malware Analyst to support ARCYBER G3.
Location: Fort Gordon, GA.
Tasks include:
- Update FMA portions of SOPs, TTPs, CSSP, and website information
- Coordinate with internal and external mission partners and intelligence professionals to contextualize malware findings within broader adversary TTPs and campaign activity
- Conduct malware analysis/reverse engineering of compiled executable code and non-compiled malicious content in order to characterize and understand its functions and capabilities
- Perform reverse-engineering on executable code
- Analyze and deobfuscate scripts, encoded commands, macros, and other non-compiled malicious content (e.g., PowerShell, VBScript, batch files, Office macros) to determine intent and functionality
- Develop and maintain malware detection signatures (e.g., YARA rules) based on analytic findings to support detection engineering and threat hunting activities
- Develop and maintain malware analysis artifacts, case notes, and all case-related data; produce written reports of findings and deliver regular operational briefings (daily/weekly/monthly) to leadership and mission partners
- Conduct and assist in executing digital media forensics
- Perform dead-box (static) forensic analysis and live (dynamic) forensic/incident handling analysis
- Use static, dynamic, and hybrid analysis techniques to detect and identify anomalous and/or malicious activity/software
- Collect, preserve, and transfer forensic evidence of intrusions to on-premises Information System(s) (IS)
- Analyze images, suspicious/malicious files, intrusion-related artifacts, entry points/vectors
- Perform network forensic analysis including inspection of packet captures (PCAPs) for malicious indicators, protocol anomalies, C2 communications, and other intrusion artifacts
- Conduct mobile device forensic examinations utilizing the Mobile device forensics lab
- Leverage mobile forensics lab tools and capabilities to acquire, examine, and analyze data from mobile devices in support of forensic investigations