Information Technology Security, SME
Peraton · Denver, CO, US
About this role
## Information Technology Security, SME ### Responsibilities - Lead and support **threat hunt operations** within **OT environments** (substations, control centers, and enterprise networks). - Perform **in-depth host and network log analysis** using tools such as **Elastic, Splunk, Malcolm, Wireshark**, and forensic toolkits. - Apply **multi-source cyber threat intelligence** to identify adversary techniques, impacted systems, and detection opportunities. - Develop **threat hunt packages**, methodologies, and documentation for systematic, intelligence-driven hunts. - Engineer, test, and deploy **sensor architectures** in **OT/ICS** environments without disrupting critical operations. - Conduct adversary behavior research using frameworks such as **MITRE ATT&CK**, **Diamond Model**, and **ICS Cyber Kill Chain**. - Produce **threat assessments**, analytic reports, and **executive-level briefings** (findings, risks, recommendations). - Collaborate with intelligence and enterprise cybersecurity teams to improve **detection, response, and situational awareness**. - Mentor junior analysts on **OT architectures**, **data collection**, and threat hunting tradecraft. - Support specialized intelligence operations using **Mandarin language capabilities**. ### Qualifications - **Minimum experience**: - **16+ years** with **BS/BA** - **14+ years** with **MS/MA** - **10+ years** with **Ph.D.** - **Active TS/SCI** with ability to obtain **Q//SCI**. - Experience in **cyber threat hunting**, **cyber intelligence**, **digital forensics**, or **OT/ICS security operations**. - Extensive experience with **OT/ICS** in **critical infrastructure** sectors. - Proficiency with SIEM/detection/forensic platforms: **Elastic, Splunk, FTK, Wireshark, IBM Analyst’s Notebook**. - Strong background in **host/network log analysis** and **adversary technique identification**. - Practical cloud experience with **AWS** and **Microsoft Azure**. - Working knowledge of **MITRE ATT&CK**, **ICS Cyber Kill Chain**, and modern **detection engineering**. - Ability to produce detailed **analytic reports** and **executive briefings**. - **US Citizenship**. ### Preferred Qualifications - Bachelor’s or Master’s in **Cybersecurity Technology** (or related field). - **GIAC** certifications (e.g., **GCFA, GCIH, GCDA**). - Experience with **detection engineering**, **incident response**, **continuous monitoring**, and **SIEM analytics**. - Experience supporting **Intelligence Community** and **DoD** cyber missions. - **Mandarin proficiency**. - Experience documenting standardized analytic procedures and knowledge management practices. ### Salary Range - **$135,000 – $216,000** (typical range; final offer depends on experience, education, location, and contract/business factors).
Listing freshness
CronJobs last confirmed this listing 3h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.