Cyber Monitoring Signature Analyst

Peraton

$80K — $128K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree and 5 years of relevant experience, or 3 years with a Master's degree; equivalent experience may apply.
  • Possess a relevant certification (e.g., CASP+ CE, CISSP, or equivalent) or ability to obtain before starting.
  • Hands-on experience with SPL authoring and tuning in a production Splunk environment (minimum 3 years).
  • Familiarity with the MITRE ATT&CK framework for detection engineering.
  • Experience with Splunk Enterprise Security and the Common Information Model (CIM).
  • Knowledge of incident response lifecycle in various environments.

Responsibilities

  • Collaborate with senior engineers to strengthen organization’s threat detection capabilities.
  • Utilize advanced cyber monitoring tools for threat detection.
  • Author and maintain correlation searches and adaptive response actions in Splunk Cloud ES.
  • Evaluate and incorporate new analytical detections into the SIEM.
  • Maintain a MITRE ATT&CK coverage matrix and prioritize gaps with SMEs.
  • Assist in developing and tuning cyber security tools with system engineers.
  • Operationalize threat intelligence for actionable detections.

Benefits

  • Healthcare, dental, and vision insurance.
  • Retirement plans with company matching.
  • Paid time off and holidays.
  • Professional development opportunities.
  • Flexible work hours and a supportive team environment.
Full Job Description
Responsibilities

Peraton is currently seeking a Cyber Monitoring Signature Analyst to become part of Peraton’s Department of State (DoS) Diplomatic Security Cyber Mission (DSCM) program.

Location: Rosslyn, VA and a secondary at Beltsville, MD

Schedule: Mon-Friday, 08:00-16:00 (8:00 AM - 4:00PM)

In this role, you will:

  • Work under senior detection engineers and Subject Matter Experts with cutting edge cyber monitoring tools to build and enhance the organization's threat detection and response capabilities.This position is with the Cyber Incident Response Team.
  • Work in a team environment with senior detection engineers, threat analysts, and incident responders to protect a global IT infrastructure against advanced threat actors.
  • Author, tune, and maintain correlation searches, Risk Notables, and Adaptive Response actions within Splunk Cloud Enterprise Security.
  • Evaluate new analytical detections from open-source libraries and incorporate vetted alerting into a SIEM.
  • Author new correlational searches in SPL/SPL2 using best practice search methodologies.
  • Maintain a living MITRE ATT&CK coverage matrix; identify gaps and prioritize with SME.
  • Ensure proper cohesion and health of SIEM alerting.
  • Collaborate and assist system engineers with the development, configuration and tuning of cyber security tools.
  • Operationalize threat intelligence to ensure Indicators of Compromise are actionable in detections.
  • Provide reporting on detection development metrics (coverage, MTTx, FP rate, notable volume by rule).

#DSCM

Qualifications

Minimum requirements are:

  • Bachelor's degree and 5 years of relevant experience; or, 3 years with a Masters degree. An additional 4 years of experience in lieu of the bachelors degree will be considered.
  • Must possess and maintain one of the following certifications or the ability to obtain before start date: CASP+ CE, CCNA Cyber Ops, CCNA-Security, CCNP Security, CEH, CFR, CHFI, CISA, CISSP (or Associate), CySA+, GCED, GCFA, GCIH, SCYBER, or Security+
  • Hands-on experience authoring and tuning SPL in a production Splunk environment (minimum 3 years).
  • Working knowledge of Splunk Enterprise Security (correlation searches, notable events, Incident Review, Adaptive Response) - ES 8.x experience strongly preferred.
  • Demonstrated experience with the Splunk Common Information Model (CIM) and writing performant searches against accelerated data models.
  • Experience modifying Splunk ES searches, macros, and lookup tables.
  • Familiarity with the MITRE ATT&CK framework and its application to detection engineering.
  • Working knowledge of Zeek, Suricata, and at least one EDR.
  • Demonstrated knowledge of the Incident Response Lifecycle and how it applies to cloud, legacy, and hybrid environments.
  • Strong organizational skills.
  • Proven ability to operate in a time-sensitive environment.
  • Proven ability to effectively communicate orally and in writing.
  • U.S. Citizenship is required
  • Ability to obtain an interim Secret clearance before start date.
    • Able to obtain a Top Secret security clearance.

Preferred:

  • Prior experience operationalizing Splunk ES Content Updates (ESCU) analytic stories and Risk-Based Alerting (RBA) workflows.
  • Experience with Splunk Mission Control for triage, investigation, and response workflows.
  • Understanding of CVEs, zero-day threats, their modes of operation, and threat detection measures.
  • Working knowledge of Python and search syntax like Regex.
  • Knowledge of network architecture, design, and security.
  • Knowledge of which system files (e.g., log files, registry files, configuration files) contain relevant information and where to find those system files.
  • Understanding of policies and procedures to investigate incidents in a computer network.
  • Knowledge of intersection of on-prem and cloud-based technologies.
  • Exposure to leading vendor cloud environments (Microsoft Azure/AAD, Google GCP, Amazon AWS), Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS).
  • Experience with EDR telemetry analysis (Microsoft Defender for Endpoint / Advanced Hunting) and/or web proxy data (Zscaler, Cloudflare).
  • Experience with threat intelligence platforms and IOC operationalization.
  • Experience in developing and delivering comprehensive training programs.
  • Previous Incident Response experience at the analyst level.
  • Knowledge and familiarity with Detection as Code.
  • Knowledge and familiarity with implementation of AI-driven workflows.
Target Salary Range$80,000 - $128,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual’s experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.

Similar Jobs

More Jobs at Peraton

More Information Technology Jobs

Find similar Cyber Monitoring Signature Analyst jobs: