CronJobs

security jobs

Cyber Monitoring Signature Analyst - Active Secret

Peraton · Beltsville, MD, US

hybridunknown$80,000–$128,000Posted Oct 8, 2026Splunk Cloud Enterprise SecuritySplunk Enterprise Security (ES 8.x)Splunk SPL/SPL2MITRE ATT&CKCIMPythonZeekSuricata

Apply on the employer site

About this role

## Cyber Monitoring Signature Analyst (Active Secret) ### Overview Peraton is seeking a **Cyber Monitoring Signature Analyst** to support the **Department of State (DoS) Diplomatic Security Cyber Mission (DSCM)** program. - **Location:** Rosslyn, VA (primary) + Beltsville, MD (secondary) - **Schedule:** Mon–Fri, **08:00–16:00** (8:00 AM–4:00 PM) - **Team:** Cyber Incident Response Team ### Responsibilities - Work with senior detection engineers and Subject Matter Experts to build and enhance threat detection and response capabilities. - Author, tune, and maintain **correlation searches**, **Risk Notables**, and **Adaptive Response** actions in **Splunk Cloud Enterprise Security**. - Evaluate new analytical detections from open-source libraries and incorporate vetted alerting into a SIEM. - Write new correlational searches in **SPL/SPL2** using best-practice methodologies. - Maintain a living **MITRE ATT&CK coverage matrix**; identify gaps and prioritize with SMEs. - Ensure proper cohesion and health of SIEM alerting. - Collaborate with system engineers to develop, configure, and tune cybersecurity tools. - Operationalize threat intelligence so **Indicators of Compromise (IOCs)** are actionable in detections. - Provide reporting on detection development metrics (e.g., coverage, MTTx, FP rate, notable volume by rule). ### Qualifications **Minimum requirements** - **Bachelor’s degree + 2 years** relevant experience, **or** **0 years with a Master’s**. - **Additional 4 years** experience may substitute for the bachelor’s degree. - Must possess and maintain (or obtain before start) one of: - **CCNA-Security, CND, CySA+, GICSP, GSEC, Security+ CE, SSCP** - **3+ years** hands-on experience authoring and tuning **SPL** in a production **Splunk** environment. - Working knowledge of **Splunk Enterprise Security** (correlation searches, notable events, Incident Review, Adaptive Response) — **ES 8.x preferred**. - Experience with **Splunk CIM** and writing performant searches against accelerated data models. - Experience modifying **Splunk ES** searches, macros, and lookup tables. - Familiarity with **MITRE ATT&CK** and its use in detection engineering. - Working knowledge of **Zeek, Suricata**, and at least one **EDR**. - Knowledge of the **Incident Response Lifecycle** across cloud, legacy, and hybrid environments. - Strong organizational skills; ability to operate in a time-sensitive environment. - Effective communication (oral and written). - **U.S. Citizenship required** - **Active Secret clearance** required; ability to obtain **Top Secret**. **Preferred** - Experience operationalizing **Splunk ES Content Updates (ESCU)** analytic stories and **Risk-Based Alerting (RBA)** workflows. - Experience with **Splunk Mission Control** for triage/investigation/response. - Understanding of **CVEs** and zero-day threats and detection measures. - Working knowledge of **Python** and search syntax (e.g., **Regex**). - Knowledge of network architecture/security and where to find relevant system files (logs/registry/configs). - Understanding of policies/procedures for investigating network incidents. - Exposure to on-prem + cloud technologies; vendor cloud environments (Azure/AAD, GCP, AWS) and IaaS/PaaS/SaaS. - EDR telemetry analysis (e.g., **Microsoft Defender for Endpoint / Advanced Hunting**) and/or web proxy data (e.g., **Zscaler, Cloudflare**). - Experience with threat intelligence platforms and IOC operationalization. - Experience developing/de

Listing freshness

CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.

Browse all software engineering jobs →

Follow fresh jobs in Discord