Cyber Monitoring Signature Analyst - Active Secret
Peraton · Beltsville, MD, US
About this role
## Cyber Monitoring Signature Analyst (Active Secret) ### Overview Peraton is seeking a **Cyber Monitoring Signature Analyst** to support the **Department of State (DoS) Diplomatic Security Cyber Mission (DSCM)** program. - **Location:** Rosslyn, VA (primary) + Beltsville, MD (secondary) - **Schedule:** Mon–Fri, **08:00–16:00** (8:00 AM–4:00 PM) - **Team:** Cyber Incident Response Team ### Responsibilities - Work with senior detection engineers and Subject Matter Experts to build and enhance threat detection and response capabilities. - Author, tune, and maintain **correlation searches**, **Risk Notables**, and **Adaptive Response** actions in **Splunk Cloud Enterprise Security**. - Evaluate new analytical detections from open-source libraries and incorporate vetted alerting into a SIEM. - Write new correlational searches in **SPL/SPL2** using best-practice methodologies. - Maintain a living **MITRE ATT&CK coverage matrix**; identify gaps and prioritize with SMEs. - Ensure proper cohesion and health of SIEM alerting. - Collaborate with system engineers to develop, configure, and tune cybersecurity tools. - Operationalize threat intelligence so **Indicators of Compromise (IOCs)** are actionable in detections. - Provide reporting on detection development metrics (e.g., coverage, MTTx, FP rate, notable volume by rule). ### Qualifications **Minimum requirements** - **Bachelor’s degree + 2 years** relevant experience, **or** **0 years with a Master’s**. - **Additional 4 years** experience may substitute for the bachelor’s degree. - Must possess and maintain (or obtain before start) one of: - **CCNA-Security, CND, CySA+, GICSP, GSEC, Security+ CE, SSCP** - **3+ years** hands-on experience authoring and tuning **SPL** in a production **Splunk** environment. - Working knowledge of **Splunk Enterprise Security** (correlation searches, notable events, Incident Review, Adaptive Response) — **ES 8.x preferred**. - Experience with **Splunk CIM** and writing performant searches against accelerated data models. - Experience modifying **Splunk ES** searches, macros, and lookup tables. - Familiarity with **MITRE ATT&CK** and its use in detection engineering. - Working knowledge of **Zeek, Suricata**, and at least one **EDR**. - Knowledge of the **Incident Response Lifecycle** across cloud, legacy, and hybrid environments. - Strong organizational skills; ability to operate in a time-sensitive environment. - Effective communication (oral and written). - **U.S. Citizenship required** - **Active Secret clearance** required; ability to obtain **Top Secret**. **Preferred** - Experience operationalizing **Splunk ES Content Updates (ESCU)** analytic stories and **Risk-Based Alerting (RBA)** workflows. - Experience with **Splunk Mission Control** for triage/investigation/response. - Understanding of **CVEs** and zero-day threats and detection measures. - Working knowledge of **Python** and search syntax (e.g., **Regex**). - Knowledge of network architecture/security and where to find relevant system files (logs/registry/configs). - Understanding of policies/procedures for investigating network incidents. - Exposure to on-prem + cloud technologies; vendor cloud environments (Azure/AAD, GCP, AWS) and IaaS/PaaS/SaaS. - EDR telemetry analysis (e.g., **Microsoft Defender for Endpoint / Advanced Hunting**) and/or web proxy data (e.g., **Zscaler, Cloudflare**). - Experience with threat intelligence platforms and IOC operationalization. - Experience developing/de
Listing freshness
CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.