Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy, and consent to receive emails from Rise
Jobs / Job page
Tier 2 Cyber Incident Response Team (CIRT) Analyst image - Rise Careers
Job details

Tier 2 Cyber Incident Response Team (CIRT) Analyst - job 1 of 2

Responsibilities

Peraton is seeking an experienced Tier 2 Cyber Incident Response Team (CIRT) Analyst to join Peraton's Department of State (DOS) Diplomatic Security Cyber Mission (DSCM) program, which provides leading cyber and technology security expertise to enable innovative, effective, and secure business processes that protect our nation's diplomatic missions worldwide.

 

Location: Beltsville, MD

 

Work Hours: Mids Shift, 2200 - 0600 EST, TUE-SAT.

 

In this role, you will:

 

  • Detect, classify, process, track, and report on cyber security events and incidents.
  • Perform advanced in-depth analysis of coordinated Tier 1 alert triage and requests in a 24x7x365 environment.
  • Analyze logs from multiple sources (e.g., host logs, EDR, firewalls, intrusion detection systems, servers) to identify, contain, and remediate suspicious activity.
  • Characterize and analyze network traffic to identify anomalous activity and potential threats.
  • Protect against and prevent potential cyber security threats and vulnerabilities.
  • Perform forensic analysis of hosts artifacts, network traffic, and email content.
  • Analyze malicious scripts and code to mitigate potential threats.
  • Conduct malware analysis to generate IOCs to identify and mitigate threats.
  • Collaborate with Department of State teams to analyze and respond to events and incidents.
  • Monitor and respond to the CIRT Security Orchestration and Automation Response (SOAR) platform, hotline, email inboxes.
  • Create tickets and initiate workflows as instructed in technical SOPs.
  • Coordinate and report incident information to the Cybersecurity and Infrastructure Security Agency (CISA).
  • Collaborate with other local, national and international CIRTs as directed.
  • Submit alert tuning requests.

#DSCM

Qualifications

Required Qualifications:

  • Bachelor's degree and at least 2 years of experience or a High School diploma and 6 years of experience.
  • Must possess one of the following certifications prior to start date:
    • A+ CE, CCNA-Security, CND, Network+ CE, SSCP, Security+.
  • Demonstrated experience in the Incident Response lifecycle.
  • Knowledge of SOAR ticketing and automated response systems (e.g. ServiceNow, Splunk SOAR, Microsoft Sentinel).
  • Demonstrated experience with using Security Information and Event Management (SIEM) platforms (e.g. Splunk, Microsoft Sentinel, Elastic, Q-Radar).
  • Demonstrated experience in using Endpoint Detection and Response systems (e.g. MDE, ElasticXDR, CarbonBlack, Crowdstrike).
  • Knowledge of cloud security monitoring and incident response.
  • Knowledge of integrating IOCs and Advanced Persistent Threat actors.
  • Ability to analyze cyber threat intelligence reporting and understanding adversary methodologies and techniques.
  • Knowledge of malware analysis techniques.
  • Knowledge of the MITRE ATT&CK and D3FEND frameworks.
  • U.S. Citizenship required.
  • Active Interim Secret clearance in order to start.

 

Preferred Qualifications:

 

  • Proficiency with Splunk for security monitoring, alert creation, and threat hunting.
  • Knowledge of Microsoft Azure access and identity management.
  • Proficiency with Microsoft Defender for Endpoint and Identity for security monitoring, response, and alert generations.
  • Experience in using digital forensics collection and analysis tools (e.g. Autopsy, MagnetForensics, Zimmerman-Tools, KAPE, CyLR, Volatility).
  • Experience with using ServiceNow SOAR for ticketing and automated response.
  • Knowledge of Python, PowerShell and BASH scripting languages.
  • Experience with cloud security monitoring and incident response.
  • Demonstrated ability to perform static/dynamic malware analysis and reverse engineering.
  • Experience with integrating cyber threat intelligence and IOC-based hunting.
  • Technical certifications such as: Security+, CySA+, Cloud+, Try Hack Me SAL1, Hack the Box CDSA, CyberDefenders, CCD, Azure SC-900, CCSP, GCIH, CCSK, GSEC, CHFI, GCLD, GCIA.
  • Advanced technical certifications such as: SecurityX/CASP+, PRMP, GREM, GEIR, GNFA, or GCFA.

 

Peraton Overview

Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world’s leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees do the can’t be done by solving the most daunting challenges facing our customers. Visit peraton.com to learn how we’re keeping people around the world safe and secure.

Target Salary Range

$80,000 - $128,000. This represents the typical salary range for this position based on experience and other factors.

EEO

EEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.

Average salary estimate

$104000 / YEARLY (est.)
min
max
$80000K
$128000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

Similar Jobs
Photo of the Rise User

Senior Network Engineer needed to deliver enterprise-level network design, integration, and Tier 3 support for SITEC EOM at Fort Bragg, requiring TS/SCI clearance and deep experience with DoD network architectures.

Photo of the Rise User
Posted 13 hours ago

Peraton is hiring a seasoned Network Engineer to lead design, security, and operations for DoD networks with COMSEC responsibilities and an active TS clearance.

Photo of the Rise User
Posted 15 hours ago

BETA Technologies is hiring an expert Network Engineer to lead the design, deployment, and operational support of our enterprise LAN/WAN and wireless infrastructure in South Burlington, VT.

Saint Mary of Nazareth Hospital seeks an onsite IT Technician to deliver desktop support, troubleshoot end-user systems, and help ensure uninterrupted clinical operations.

PSI is hiring a Junior Linux System Administrator to support SUSE Linux servers and Unisys Forward/ES3000 environments for NYS ITS, focusing on backups, scripting, performance monitoring, and system maintenance.

Photo of the Rise User

WinnCompanies is hiring an IT Transitions Lead to oversee property technology onboarding/offboarding and lead cross-functional transition projects from its Boston headquarters.

Photo of the Rise User
Posted 17 hours ago

TherapyNotes is hiring a Senior Cloud Security Engineer to lead cloud and hybrid environment security, incident response, and secure engineering practices for its behavioral health SaaS platform.

Photo of the Rise User

Presbyterian Healthcare Services seeks an experienced Workday Supply Chain Analyst to lead SCM configuration, reporting and business consulting for Procurement, AP, Expenses and Inventory in a remote capacity.

Photo of the Rise User

Les Schwab is hiring a Network Operations Engineer II in Bend, OR to lead monitoring, incident response, and optimization for a large multi-site retail network.

Photo of the Rise User
Groundswell Hybrid Remote - Washington D.C.
Posted 15 hours ago

Groundswell is hiring a Lead Technical Architect to lead secure Workday deployments and integrations for IC/DoD missions while bridging technical teams and stakeholders.

Lead the delivery and support of Financial and Purchasing application solutions as the Application Development Manager, driving system enhancements, integrations, and vendor coordination to meet business and regulatory needs.

Photo of the Rise User
Posted 18 hours ago

Sigma Defense seeks Network Engineers (I–III) to design, implement, and sustain secure Navy enterprise networks, supporting programs such as SD-WAN, IPv6 migration, and Zero Trust.

Photo of the Rise User
Posted 16 hours ago

Mid-level Cybersecurity Engineer needed to support DevSecOps and client cybersecurity teams by implementing RMF-aligned controls, STIG compliance, and container security governance for DoD environments.

Photo of the Rise User
CyberArk Hybrid Newton, Massachusetts, United States
Posted 13 hours ago

Join CyberArk's Global SOC as a SOC Engineer driving Splunk projects, automated detection engineering, cloud investigations, and EDR operations to improve global threat visibility and response.

Photo of the Rise User
Posted 4 hours ago
Inclusive & Diverse
Feedback Forward
Collaboration over Competition
Growth & Learning

OpenAI is hiring a Director of Supply Chain Systems to lead and scale Oracle Fusion-based supply chain platforms and integrations that support global procure-to-pay, inventory, planning, and order management.

Our mission is to protect and promote freedom around the world by Securing our future, Connecting our world, Safeguarding our enterprise, Protecting our borders, Enabling commerce, Enhancing human knowledge, and Protecting our citizens.

104 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, onsite
DATE POSTED
September 4, 2025
Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!