
Job Overview
Employment Type
Full-time
Compensation
Salary
Range $104,000.00 - $166,000.00
Work Schedule
Day Shifts
Benefits
Medical insurance
Dental Insurance
Vision Insurance
Life insurance
Health savings account
short term disability
long term disability
Employee assistance program
Parental leave
401(k)
Paid Time Off
Company paid holidays
Job Description
Peraton is a leading next-generation national security company dedicated to advancing missions of critical importance across the globe and even extending into outer space. As the world's foremost mission capability integrator and an innovative enterprise IT provider, Peraton delivers highly trusted and distinctive solutions and technologies designed to safeguard the nation and its allies. Operating at the pivotal intersection of both traditional and emerging threats across diverse domains—including land, sea, space, air, and cyberspace—Peraton plays a vital role in national defense. The company is a respected partner to key government agencies and supports every branch of the U.S. armed forces. Every day, Peraton’s workforce addresses some of the most challenging problems faced by its customers, working tirelessly to keep people safe and secure worldwide. For more information about their mission and impact, you can visit peraton.com.
This role is set within Peraton’s Federal Strategic Cyber Mission program, specifically supporting the Bureau of Diplomatic Security’s Cyber and Technology Security Directorate. This program integrates technical, engineering, data analytics, cyber security, management, operations, and logistical support to protect critical government functions. The position is based on-site in Beltsville, MD, operating during the day shift from 6:00 AM to 2:00 PM EST, Tuesday through Saturday. The Tier 2 Cyber Incident Response Team (CIRT) Shift Lead will be integral in overseeing and managing cyber security incident responses, coordinating with various stakeholders to ensure swift detection, analysis, and remediation of security threats.
The Tier 2 CIRT Shift Lead will use deep technical expertise to analyze cyber security events and incidents, including the examination of logs from various sources such as host logs, firewalls, intrusion detection systems, and endpoint detection and response (EDR) solutions. The role demands proficiency in forensic analysis, malware investigation, and the ability to characterize network traffic to detect anomalous behavior and potential cyber threats. The incumbent will actively partner with Department of State teams and coordinate security incident workflows using platforms like SOAR (Security Orchestration, Automation, and Response).
Additionally, the Shift Lead will be responsible for reviewing ticket accuracy, communicating with CIRT Watch Officers and government leaders, driving procedural improvements, and supporting candidate technical interviews. The position requires a proactive approach to ensure coordinated remediation actions are effective and that the cyber security posture remains robust against evolving threats.
Peraton values a strong combination of experience and credentials. Candidates are expected to possess extensive experience in incident response lifecycle management and proficiency with SOAR and Security Information and Event Management (SIEM) platforms like Splunk and Microsoft Sentinel. Knowledge of cloud security monitoring, malware analysis, cyber threat intelligence, and familiarity with frameworks such as MITRE ATT&CK and D3FEND is essential. Applicants must be U.S. citizens with an active Secret security clearance at the outset of employment.
The company offers a competitive salary range from $104,000 to $166,000, reflecting various factors including experience, education, and location. In addition to base pay, employees may be eligible for overtime, shift differentials, and discretionary bonuses. Peraton also provides a comprehensive benefits package, including medical, dental, vision coverage, life insurance, health savings accounts, disability insurance, employee assistance programs, parental leave, 401(k) plans, paid time off for vacation, and company paid holidays.
Peraton fosters an inclusive and equal opportunity working environment, welcoming applicants from diverse backgrounds including those with disabilities and protected veterans. The application period typically lasts around 30 days but may change based on business needs and candidate availability. Applicants may be required to undergo identity verification and interviews as part of the hiring process.
This role is set within Peraton’s Federal Strategic Cyber Mission program, specifically supporting the Bureau of Diplomatic Security’s Cyber and Technology Security Directorate. This program integrates technical, engineering, data analytics, cyber security, management, operations, and logistical support to protect critical government functions. The position is based on-site in Beltsville, MD, operating during the day shift from 6:00 AM to 2:00 PM EST, Tuesday through Saturday. The Tier 2 Cyber Incident Response Team (CIRT) Shift Lead will be integral in overseeing and managing cyber security incident responses, coordinating with various stakeholders to ensure swift detection, analysis, and remediation of security threats.
The Tier 2 CIRT Shift Lead will use deep technical expertise to analyze cyber security events and incidents, including the examination of logs from various sources such as host logs, firewalls, intrusion detection systems, and endpoint detection and response (EDR) solutions. The role demands proficiency in forensic analysis, malware investigation, and the ability to characterize network traffic to detect anomalous behavior and potential cyber threats. The incumbent will actively partner with Department of State teams and coordinate security incident workflows using platforms like SOAR (Security Orchestration, Automation, and Response).
Additionally, the Shift Lead will be responsible for reviewing ticket accuracy, communicating with CIRT Watch Officers and government leaders, driving procedural improvements, and supporting candidate technical interviews. The position requires a proactive approach to ensure coordinated remediation actions are effective and that the cyber security posture remains robust against evolving threats.
Peraton values a strong combination of experience and credentials. Candidates are expected to possess extensive experience in incident response lifecycle management and proficiency with SOAR and Security Information and Event Management (SIEM) platforms like Splunk and Microsoft Sentinel. Knowledge of cloud security monitoring, malware analysis, cyber threat intelligence, and familiarity with frameworks such as MITRE ATT&CK and D3FEND is essential. Applicants must be U.S. citizens with an active Secret security clearance at the outset of employment.
The company offers a competitive salary range from $104,000 to $166,000, reflecting various factors including experience, education, and location. In addition to base pay, employees may be eligible for overtime, shift differentials, and discretionary bonuses. Peraton also provides a comprehensive benefits package, including medical, dental, vision coverage, life insurance, health savings accounts, disability insurance, employee assistance programs, parental leave, 401(k) plans, paid time off for vacation, and company paid holidays.
Peraton fosters an inclusive and equal opportunity working environment, welcoming applicants from diverse backgrounds including those with disabilities and protected veterans. The application period typically lasts around 30 days but may change based on business needs and candidate availability. Applicants may be required to undergo identity verification and interviews as part of the hiring process.
Job Requirements
- Bachelor’s degree or higher
- Minimum 9 years of relevant experience
- Ability to obtain and maintain an active Secret clearance
- U.S. citizenship
- Ability to work on-site in Beltsville, MD
- Available to work day shift, 6:00 AM to 2:00 PM EST, Tuesday through Saturday
- Proficiency with incident response and cyber security tools
- Strong communication skills
- Ability to collaborate with government and cross-functional teams
Job Qualifications
- Bachelor’s degree and minimum of 9 years of relevant experience
- or Master’s degree with minimum of 7 years
- or PhD with 4 years
- in lieu of a degree, 4 years of additional experience may be considered
- Must possess, or obtain prior to start date, at least one certification such as CASP+ CE, CCNA Cyber Ops, CCNA-Security, CCNP Security, CEH, CFR, CHFI, CISA, CISSP (or Associate), CISSP-ISSAP, CISSP-ISSEP, CySA+, GCED, GCFA, GCIH, SCYBER
- Demonstrated experience across the incident response lifecycle
- Experience with SOAR platforms and automated response workflows such as ServiceNow, Splunk SOAR, Microsoft Sentinel
- Experience with Security Information and Event Management (SIEM) platforms such as Splunk, Microsoft Sentinel, Elastic, QRadar
- Experience with Endpoint Detection and Response (EDR) solutions such as Microsoft Defender for Endpoint, Elastic XDR, Carbon Black, CrowdStrike
- Knowledge of cloud security monitoring and incident response
- Knowledge of integrating indicators of compromise (IOCs) and tracking advanced persistent threat (APT) actors
- Ability to analyze cyber threat intelligence and understand adversary tactics, techniques, and procedures (TTPs)
- Knowledge of malware analysis techniques
- Familiarity with MITRE ATT&CK and D3FEND frameworks
- U.S. citizenship required
- Active Secret security clearance required at start
Job Duties
- Detect, classify, process, track, and report on cyber security events and incidents
- Perform advanced in-depth analysis of coordinated Tier 1 alert triage and requests in a 24x7x365 environment
- Analyze logs from multiple sources such as host logs, EDR, firewalls, intrusion detection systems, and servers to identify, contain, and remediate suspicious activity
- Characterize and analyze network traffic to identify anomalous activity and potential threats
- Protect against and prevent potential cyber security threats and vulnerabilities
- Perform forensic analysis of hosts artifacts, network traffic, and email content
- Analyze malicious scripts and code to mitigate potential threats
- Conduct malware analysis to generate IOCs to identify and mitigate threats
- Collaborate with Department of State teams to analyze and respond to events and incidents
- Monitor and respond to the CIRT Security Orchestration and Automation Response (SOAR) platform, hotline, email in-boxes
- Create tickets and initiate workflows as instructed in technical SOPs
- Coordinate and report incident information to the Cybersecurity and Infrastructure Security Agency (CISA)
- Collaborate with other local, national and international CIRTs as directed
- Submit alert tuning requests
- Review all Tier 2 shift tickets for accuracy and completeness
- Coordinate with CIRT Watch Officers and government leadership on remediation actions
- Provide technical and procedural improvement recommendations to CIRT leadership
- Assist with Tier 2 candidate technical interviews as required
- Ensure coordinated remediation actions are operating properly
Job Criteria
Experience
Mid Level (3-7 years)
Job Location
Your Profile Is Visible To Hiring Managers Across OysterLink.
We'll match you with best jobs
Get job offers faster


Search For More Opportunities:
How Candidates Get Hired Faster
Apply to 2–3 similar roles
Complete profile & get best matches
Check new opportunities daily

