ResponsibilitiesPeraton is seeking a SOC Analyst to join our team of qualified and diverse individuals on our Department of State (DOS) Bureau of Diplomatic Technology (DT) Consular Affairs Enterprise Infrastructure Operations (CAEIO) program. CAEIO provides IT Operations and Maintenance to modernize the legacy networks, applications, and databases supporting consular applications and services globally.
Core Work Schedule: Third shift: 11:00PM – 7:30AM EST, Thursday – Monday
Location:This position is fully remote; however, preference will be given to candidates local to the Washington, DC, metropolitan area (DMV) for occasional onsite meetings, training sessions, or customer support activities at the Washington, DC, customer location or the Peraton office in Sterling, VA.The number of days the SOC Analyst works on-site in Washington, DC, or Sterling, VA, is subject to change based on government/program requirements (for example, surge support might require the individual to be in the office five days per week).
Day-to-Day Responsibilities:
- Monitor and investigate security alerts, perform threat hunting, and notify designated managers, cyber incident responders, and cybersecurity service provider personnel of suspected incidents. Clearly articulate event history, status, and potential impact in accordance with the organization’s cyber incident response plan.
- Analyze and characterize network traffic to identify anomalous activity and potential threats to network resources.
- Create advanced ad hoc SPL queries.
- Coordinate with internal and external teams to investigate threats, assess risks, and conduct forensic analysis.
- Review and analyze log files from various sources (host logs, network traffic logs, firewall logs, IDS logs) to identify potential security threats.
- Utilize SIEM and EDR tools to monitor the operational environment.
- Develop and document configuration standards, policies, and procedures to operate, manage, and secure system infrastructure.
- Advise management and team members on technology risks and recommend mitigation strategies.
- Engage with multiple levels of management, providing technical expertise and thought leadership.
- Prepare reports detailing investigations, incidents, and other security-related activities.
- Identify and classify attack tactics and techniques.
- Recommend and implement enhancements to improve system performance, security, and reliability.
- Build and refine SOC processes and procedures, including documenting work in SOPs.
- Train and mentor junior SOC team members.
- Plan and execute SOC-related projects and initiatives.
- Communicate clearly and professionally with managers and colleagues.
- Demonstrate flexibility and an eagerness to take on additional responsibilities as needed.
Qualifications
Basic Qualifications:
Preferred Qualifications:
- Experience with Splunk data normalization (field aliases, calculated fields, field extractions)
- Splunk Power User certification or higher
- Experience tracking incidents using the MITRE ATT&CK framework
- Knowledge of cloud security
- Experience with system administration, networking, and operating system hardening techniques
- Mixed OS experience (Linux, Windows)
- Experience troubleshooting storage-related issues
- Scripting or coding experience
- Knowledge of Web Application Firewall (WAF) security features
Target Salary Range$80,000 - $128,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual’s experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.