Overview
Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world’s leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees do the can’t be done by solving the most daunting challenges facing our customers. Visitperaton.comto learn how we’re keeping people around the world safe and secure.
Responsibilities
Peraton is seeking to hire an experiencedCyber Response Analystfor its’ Regional Cyber Center-EuropeLocation: On-site, Wiesbaden, GermanyResponsibilities:Monitor IDS/SIEM platforms (Elastic, Splunk, ArcSight) for security events, anomalies, and indicators of compromise across DoD networks in the USAREUR-AF AORTriage, analyze, and escalate security alerts in accordance with CSSP standard operating procedures, ensuring timely notification to senior analysts and mission partnersConduct initial malware analysis and static/dynamic examination of suspicious files, URLs, and artifacts to determine threat scope and impactDocument security incidents from initial detection through containment, recording all actions, findings, and evidence in the incident tracking systemSupport incident response actions including host isolation, evidence collection, and coordination with network operations and mission ownersProduce accurate and timely shift reports, end-of-day summaries, and incident tickets that capture event timelines, analyst actions, and recommended follow-on steps#RCC-E
Qualifications
Required:Bachelor’s degree (STEM/Business Admin) and a minimum of 5 years of cybersecurity experience, or an associates degree and minimum of 7 years of relevant experience, or 11 total years of relevant experience in lieu of the bachelors degree requirementMust meet TESA QualificationDoD 8140 - Cybersecurity (Cyber Defense Incident Responder) - AdvancedCertifications - must hold active certifications (one of the following):Cisco CyberOps Professional; ORSANS (any GIAC certification); ORBlue Team Level 1; ORMicrosoft Certified: Security Operations Analyst AssociateU.S. citizenship requiredActive DoD TS/SCI clearance or higherPreferred:Hands-on experience with Elastic Stack (Elasticsearch, Kibana, Logstash) or Splunk for security event monitoringProficiency with Wireshark or similar packet analysis tools for network traffic inspectionFamiliarity with MITRE ATT&CK framework for mapping adversary TTPs to observed activityExperience with malware analysis tools (e.g., Cuckoo Sandbox, Any.Run, VirusTotal)Working knowledge of TheHive or similar incident case management platformsExperience with network forensics and log analysis across firewall, DNS, and proxy sourcesFamiliarity with NIST SP 800-61 incident response lifecycleExposure to scripting (Python or Bash) for alert triage automation