Incident Handling-SME

4 weeks ago


Arlington, Virginia, United States Peraton Full time


Incident Handling-SME

Job Locations

US-VA-Arlington

Requisition ID

2025-154451

Position Category

Intel and Threat Analysis

Clearance

Top Secret

Responsibilities

We are seeking a Cyber Incident Handling SME to become part of Peraton's Department of State (DoS) Diplomatic Security Cyber Mission (DSCM) program providing leading cyber and technology security experience to enable innovative, effective and secure business processes.

Location: Beltsville, MD and Roslyn, VA.

The customer requirement requires every employee to be onsite for the first 90 days. After the 90 day period, a hybrid schedule may be offered. The selected candidate must be able to support a hybrid and flexible schedule, in the event of significant cyber incident a continuous on site presence will be required.

Peraton's DSCM program encompasses technical, engineering, data analytics, cyber security, management, operational, logistical and administrative support to aid and advise DoS Cyber & Technology Security (CTS) Directorate. This includes protecting a global cyber infrastructure comprising networks, systems, information, and mobile devices all while identifying and responding to cyber risks and threats. Those supporting Peraton's DSCM program strive to leverage their expert knowledge and propose creative solutions to real-world cybersecurity challenges.

What you'll do:

  • Support the Cyber Incident Response Team (CIRT) as a key member of Incident Response Tiger Team.
  • Provide Subject Matter Expert (SME) level incident management support in a 24x7x365 environment.
  • Share in-depth knowledge and intelligence gained from cyber security events with stakeholders.
  • Collaborate with Cyber Threat Intelligence (CTI) teams to analyze threat actor tactics, techniques, and procedures (TTPs) and integrate actionable intelligence into incident response workflows.
  • Protect against and prevent potential cyber security threats and vulnerabilities.
  • Provide SME level response, technical assistance and expertise for significant cyber incidents, investigations and related operational events.
  • Conduct advanced analysis and recommend remediation steps.
  • Plan and conduct incident response tabletop exercises (TTX), team simulations, and cyber drills to validate response plans and improve overall readiness.
  • Develop and implement training programs for incident handling analysts.
  • Conduct detailed research to increase awareness and readiness levels of the security operations center.
  • Review, draft, edit, update and publish cyber incident response plans.
  • Develop key performance indicators (KPIs) and key risk indicators (KRIs) to measure and improve incident response effectiveness.
  • Ensure incident response procedures align with industry best practices and compliance frameworks such as NIST 800-61, ISO 27035, CMMC.
  • Mentor junior analysts, conduct knowledge transfer sessions, and develop playbooks to enhance the skill set of the security operations team.

#DSCM

Qualifications

Minimum Requirements:

  • Bachelor's degree and minimum of 14 years' experience, or a Master's degree and a minimum of 12 years' experience. An additional 4 years of experience may be used in lieu of degree.
  • Must have one of the following certifications:
    • CASP+ CE, CCNP Security, CISA, CISSP (or Associate), CISSP-ISSAP, CISSP-ISSEP, GCED, GCIH.
  • Ability to manage and resolve highly complex cyber incidents.
  • Ability to recommend sound counter measures to malicious cyber activity.
  • Experience in the development of policies and procedures to investigate cyber incidents for the enterprise network.
  • Experience handling national state level cyber incidents.
  • Experience with evidence collection, custody and control procedures.
  • Experience in incident triage.
  • Perform cyber defense trend analysis and reporting.
  • Experience with the ServiceNow platform.
  • Demonstrated knowledge of the Incident Response Lifecycle.
  • Demonstrated ability to utilize and leverage forensic tools to assist in determining scope and severity of a cybersecurity incident.
  • Ability to identify remediation steps for cybersecurity events.
  • Demonstrated strong organizational skills.
  • Proven ability to operate in a time sensitive environment.
  • Proven ability to communicate orally and written.
  • Proven ability to brief (technical/informational) senior leadership.
  • U.S. citizenship required.
  • An active Secret security clearance with the ability to obtain a final Top Secret clearance.

Preferred Qualifications:

  • Experience developing processes and procedures within a help desk or security operations center environment.
  • Experience using security tools such as SIEM (Splunk or ELK), EDR/XDR (CrowdStrike, SentinelOne, Microsoft Defender), and network analysis tools (Wireshark, Zeek, Suricata).
  • Experience with cloud security incident response, including AWS, Azure, or Google Cloud, with knowledge of cloud-native security controls.
  • Knowledge of network architecture, design and security.
  • Knowledge of malware analysis, monitoring, and cloud tools and techniques.
  • Knowledge of system design and process methodologies.
  • Experience in developing and delivering comprehensive training programs.
  • Experience collaborating with cross functional teams.
  • Experience working in the inter-agency environment.
  • Experience coordinating incident response efforts across multiple teams and agencies, including legal, compliance, and law enforcement.
  • Ability to communicate technical concepts to executive level leadership.
Peraton Overview

Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world's leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees do the can't be done by solving the most daunting challenges facing our customers. Visit peraton.com to learn how we're keeping people around the world safe and secure.

Target Salary Range

$135,000 - $216,000. This represents the typical salary range for this position based on experience and other factors.

EEO

EEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.
  • Incident Handling-SME

    3 weeks ago


    Arlington, Virginia, United States Peraton Full time

    Incident Handling-SMEJob Locations US-VA-ArlingtonRequisition ID 2025-155099Position Category Intel and Threat AnalysisClearance Top SecretResponsibilitiesPeraton's DSCM program encompasses technical, engineering, data analytics, cyber security, management, operational, logistical and administrative support to aid and advise DoS Cyber & Technology...

  • Incident Handling-SME

    2 weeks ago


    Arlington, Virginia, United States Peraton Full time

    ResponsibilitiesPeraton's DSCM program encompasses technical, engineering, data analytics, cyber security, management, operational, logistical and administrative support to aid and advise DoS Cyber & Technology Security (CTS) Directorate. This includes protecting a global cyber infrastructure comprising networks, systems, information, and mobile devices all...

  • Incident Handling-SME

    4 weeks ago


    Arlington, Virginia, United States Peraton Full time

    ResponsibilitiesWe are seeking a Cyber Incident Handling SME to become part of Peraton's Department of State (DoS) Diplomatic Security Cyber Mission (DSCM) program providing leading cyber and technology security experience to enable innovative, effective and secure business processes. Location: Beltsville, MD and Roslyn, VA. The customer requirement requires...


  • Arlington, Virginia, United States Apex Systems Full time

    Incident Management SME role will be located in Beltsville, MD or Roslyn, VA. One day remote per week This role supports the Cyber Incident Response Team (CIRT) as a key member of Incident Response Tiger Team. The customer requirement requires every employee to be onsite for the first 90 days. After the 90 day period, a hybrid schedule may be offered. What...


  • Arlington, Virginia, United States Interactive Process Technology LLC Full time

    We are looking for an Incident Resolution Specialist to join our team at Interactive Process Technology LLC.In this role, you will be responsible for analyzing and resolving complex incidents that impact our customers' business operations.Key Responsibilities:Analyze and resolve complex incidents that impact our customers' business operationsDevelop and...


  • Arlington, Virginia, United States Gray Tier Technologies Full time

    Gray Tier Technologies is looking for a Network Forensics Analyst SME to support The Department of Homeland Security (DHS) Hunt and Incident Response Team (HIRT). DHS HIRT secures the Nation's cyber and communications infrastructure. HIRT provides DHS's front-line response for cyber incidents and proactively hunting for malicious cyber activity. Gray Tier...


  • Arlington, Virginia, United States ANALYGENCE, Inc. Full time

    Job Description ANALYGENCE is seeking an experienced Cyber Incident Response Manager (SME) to supportour federal customer who plays a key role in enhancing the security, resiliency, and reliability of the nation's cyber and communications infrastructure. This role directly supports the customer Mission Engineering (ME) Information Security Branch (ISB)...


  • Arlington, Virginia, United States Interactive Process Technology LLC Full time

    At Interactive Process Technology LLC, we are committed to delivering innovative business solutions using emerging technologies through proven successful methods.As a Senior Incident Analysis Manager, you will work with a team of technologists focused on delivering practical solutions that solve real problems for major government and business...


  • Arlington, Virginia, United States Nodel Full time

    About the RoleWe are looking for an experienced Incident Response Lead to join our team. In this role, you will be responsible for managing and coordinating incident response activities, ensuring that all incidents are properly documented and analyzed.Key Responsibilities:Managing and coordinating incident response activitiesEnsuring proper documentation and...


  • Arlington, Virginia, United States Nodel Full time

    IT Security Incident Manager Job DescriptionWe are looking for an experienced IT Security Incident Manager to join our team. In this role, you will be responsible for managing and coordinating IT security incident response activities, ensuring that all incidents are properly documented and analyzed.Key Responsibilities:Managing and coordinating IT security...

  • Incident Manager

    6 days ago


    Arlington, Virginia, United States Gray Tier Technologies Full time

    Gray Tier Technologies is supporting a U.S. Government customer to provide support for onsite incident response to civilian Government agencies and critical asset owners who experience cyber-attacks, providing immediate investigation and resolution. Contract personnel perform investigations to characterize the severity of breaches, develop mitigation plans,...


  • Arlington, Virginia, United States Base One Technologies Full time

    We are seeking a highly skilled Cybersecurity Incident Manager to join our team at Base One Technologies. This is a critical role that requires expertise in incident response, threat management, and security operations.Responsibilities:Correlate incident data to identify trends and patterns in reported incidents.Recommend defense-in-depth principles and...


  • Arlington, Virginia, United States Nodel Full time

    Cyber Incident Manager/ Incident Manager Location: Arlington, VA Must have Top Secret Security Clearance Node is supporting a U.S. Government customer to provide support for onsite incident response to civilian Government agencies and critical asset owners who experience cyber-attacks, providing immediate investigation and resolution. Contract personnel...


  • Arlington, Virginia, United States Nodel Full time

    Job Description Job Description Cyber Incident Manager/ Incident ManagerLocation: Arlington, VAMust have Top Secret Security ClearanceNode is supporting a U.S. Government customer to provide support for onsite incident response to civilian Government agencies and critical asset owners who experience cyber-attacks, providing immediate investigation and...

  • Incident Manager

    3 days ago


    Arlington, Virginia, United States Base One Inc Full time

    Responsibilities: - Researching and compiling known resolution steps or workarounds to enable mitigation of potential Computer Network Defense incidents within the enterprise - Applying knowledge of the tactics, techniques, and procedures of various criminal, insider, hacktivist, and nation state threat actors to identify and validate threats - Applying...

  • Incident Manager

    6 days ago


    Arlington, Virginia, United States Base One Technologies Full time

    Responsibilities:• Researching and compiling known resolution steps or workarounds to enable mitigation of potential Computer Network Defense incidents within the enterprise• Applying knowledge of the tactics, techniques, and procedures of various criminal, insider, hacktivist, and nation state threat actors to identify and validate threats• Applying...


  • Arlington, Virginia, United States Nightwing Full time

    Company OverviewNightwing is a leading provider of cybersecurity solutions, with a reputation for delivering high-quality services to our clients. Our team of experts is dedicated to staying ahead of the latest cyber threats, and we are committed to providing the best possible support to our customers.Job DescriptionWe are seeking a highly skilled Incident...


  • Arlington, Virginia, United States Solutions3 Full time

    Job Description:We are seeking an experienced Cybersecurity Incident Response Specialist to join our team. As a Cybersecurity Incident Response Specialist, you will be responsible for investigating and responding to cybersecurity incidents, developing mitigation plans, and assisting with the restoration of services.Responsibilities Include:Investigating and...

  • Incident Manager

    3 weeks ago


    Arlington, Virginia, United States BCMC, LLC Full time

    BCMC is supporting a U.S. Government customer to provide support for onsite incident response to civilian Government agencies and critical asset owners who experience cyber-attacks, providing immediate investigation and resolution. Contract personnel perform investigations to characterize the severity of breaches, develop mitigation plans, and assist with...


  • Arlington, Virginia, United States Base One Technologies Full time

    Incident Response Team LeadWe are seeking an experienced Incident Response Team Lead to join our team. The successful candidate will be responsible for coordinating the response to cybersecurity incidents, researching and compiling known resolution steps or workarounds to mitigate potential computer network defense incidents, and tracking and documenting...