Senior Forensic and Malware Analyst Top Secret/SCI w/Poly

Peraton

• $135K — $216K *
Aerospace & Defense
11 - 15 years of experience
Job Overview by Ladders

Qualifications

  • 12+ years of experience with a BS/BA; 10+ years with an MS/MA; 7+ years with a PhD; or equivalent experience with HS/Associates degree
  • IA certification required upon start (e.g., CCNA-Security, CySA+, Security+)
  • Proficient in scripting languages (PowerShell, BASH, Python) for automation
  • Experience in static and dynamic analysis of malicious software
  • Skilled in reverse-engineering executable code and analyzing non-compiled content
  • Familiar with DOD standards of reporting
  • US Citizenship and active TS clearance required

Responsibilities

  • Update SOPs, TTPs, and website information related to malware analysis
  • Coordinate with mission partners to contextualize malware findings
  • Conduct malware analysis and reverse engineering of malicious content
  • Develop and maintain malware detection signatures and analysis artifacts
  • Perform digital media forensics, including static and dynamic analysis
  • Conduct mobile device forensic examinations using specialized lab tools
  • Analyze network traffic for malicious indicators and intrusion artifacts

Benefits

  • Comprehensive health and wellness programs
  • Retirement savings plans with company matching
  • Professional development and training opportunities
  • Flexible work arrangements
  • Paid time off and holidays
Full Job Description
Responsibilities

Peraton seeks a Senior Forensic and Malware Analyst to support ARCYBER G3.

Location: Fort Gordon, GA.

Tasks include:
  • Update FMA portions of SOPs, TTPs, CSSP, and website information
  • Coordinate with internal and external mission partners and intelligence professionals to contextualize malware findings within broader adversary TTPs and campaign activity
  • Conduct malware analysis/reverse engineering of compiled executable code and non-compiled malicious content in order to characterize and understand its functions and capabilities
    • Perform reverse-engineering on executable code
    • Analyze and deobfuscate scripts, encoded commands, macros, and other non-compiled malicious content (e.g., PowerShell, VBScript, batch files, Office macros) to determine intent and functionality
    • Develop and maintain malware detection signatures (e.g., YARA rules) based on analytic findings to support detection engineering and threat hunting activities
    • Develop and maintain malware analysis artifacts, case notes, and all case-related data; produce written reports of findings and deliver regular operational briefings (daily/weekly/monthly) to leadership and mission partners
  • Conduct and assist in executing digital media forensics
    • Perform dead-box (static) forensic analysis and live (dynamic) forensic/incident handling analysis
    • Use static, dynamic, and hybrid analysis techniques to detect and identify anomalous and/or malicious activity/software
    • Collect, preserve, and transfer forensic evidence of intrusions to on-premises Information System(s) (IS)
    • Analyze images, suspicious/malicious files, intrusion-related artifacts, entry points/vectors
    • Perform network forensic analysis including inspection of packet captures (PCAPs) for malicious indicators, protocol anomalies, C2 communications, and other intrusion artifacts
  • Conduct mobile device forensic examinations utilizing the Mobile device forensics lab
    • Leverage mobile forensics lab tools and capabilities to acquire, examine, and analyze data from mobile devices in support of forensic investigations


Qualifications

Required Qualifications:
  • Minimum of 12 years with BS/BA; Minimum of 10 years with MS/MA; Minimum of 7 years with a PhD. Will consider HS with 16 years of relevant experience or Associates degree with 14 years of experience
  • Must have an IA certification upon start: CCNA-Security, CCNA-Cybersecurity, CySA+, GICSP, GSEC, Security+, CND, or SSCP
  • Able to support surge operations if mission requires
  • Experience with scripting languages (e.g., PowerShell, BASH, Python, etc.) for automating analysis tasks, parsing artifacts, or developing tooling in support of malware or forensic workflows
  • Able to examine suspicious or malicious software-using static, dynamic, and hybrid techniques
  • Experienced in conducting analysis of malicious software to determine what it does, how it works, and how to detect, contain, and remove it
  • Experience with dead-box (static) forensic analysis and live (dynamic) forensic/incident handling analysis
  • Able to perform reverse-engineering on executable code and analysis of non-compiled malicious content such as scripts, encoded commands, macros, and obfuscated files
  • Experience with DOD standards of reporting
  • Skilled in inspecting packet captures (PCAPs) for domains, URI paths, protocols, User Agent strings, TLS metadata, and other artifacts that may indicate compromise
  • US Citizenship is required
  • Active TS with ability to obtain/maintain SCI and Polygraph

Preferred Qualifications:
  • Active, or previously held, GIAC Certified Forensic Analyst (GCFA) certification


Target Salary Range

$135,000 - $216,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual's experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.

Similar Jobs

More Jobs at Peraton

More Aerospace & Defense Jobs

Find similar Senior Forensic and Malware Analyst Top Secret/SCI w/Poly jobs: