Overview
Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world’s leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees do the can’t be done by solving the most daunting challenges facing our customers. Visitperaton.comto learn how we’re keeping people around the world safe and secure.
Responsibilities
Peraton is hiring aContent Developer (Data Scientist)for its' Regional Cyber Center-Europe program.Location: On-site, Wiesbaden, GermanyPotentially 2nd/3rd Shift workResponsibilities:Develop, tune, and maintain SIEM detection content including correlation rules, alerts, and watch-lists in Elastic and/or Splunk to improve threat detection fidelity across CSSP monitoring systemsDesign and build automated data analytics pipelines that ingest, normalize, and process large volumes of security telemetry to support real-time and historical threat analysisCreate custom algorithms and machine learning models for anomaly detection, behavioral base-lining, and advanced threat identification within DoD network environmentsDevelop interactive dashboards and data visualizations in Kibana, Splunk, or similar platforms that provide actionable situational awareness for analysts and leadershipConduct metrics analysis to measure CSSP operational performance, detection coverage, and response effectiveness, producing regular reports for program management and government stakeholdersSupport threat intelligence content development by translating finished intelligence products into actionable SIEM queries, detection signatures, and automated response playbooks
Qualifications
Required:5 years of data science, analytics, or SIEM content development experience with a Bachelor’s degree in a STEM field or Business Administration; 11 years of relevant experience may substitute for degree.Must meet TESA Qualifications.DoD 8140 - Cybersecurity (Cyber Defense Analyst) - IntermediateCertifications - must hold active certifications (one of the following):GDAT (GIAC Defending Advanced Threats); ORGDSA (GIAC Defensible Security Architecture); ORElastic Certified Analyst or Engineer; ORArcSight Enterprise Security Manager Advanced Analyst Certified Expert; ORMicrosoft Certified: Cybersecurity Architect Expert; ORAzure DevOps Engineer Expert; ORTCM Security PNPTU.S. citizenship requiredActive DoD TS/SCI clearancePreferred:Deep expertise with Elastic Stack (Elasticsearch, Logstash, Kibana, Beats) for SIEM content development and data pipeline managementProficiency with Splunk SPL for advanced search, correlation rule development, and dashboard creationStrong Python skills for data processing, algorithm development, and automation scriptingFamiliarity with machine learning frameworks (e.g., scikit-learn, TensorFlow) for anomaly detection use casesExperience with Kibana or Grafana for building operational security dashboards and visualizationsKnowledge of KQL (Kusto Query Language) for Microsoft Sentinel or Azure Log Analytics environmentsFamiliarity with ArcSight ESM for content development and event correlation in enterprise environmentsExperience with threat intelligence platforms (e.g., MISP, OpenCTI) for converting intelligence into detection content