Incident Handling-SME
4 weeks ago
Incident Handling-SME
Job Locations
US-VA-Arlington
Requisition ID
2025-154451
Position Category
Intel and Threat Analysis
Clearance
Top Secret
Responsibilities
We are seeking a Cyber Incident Handling SME to become part of Peraton's Department of State (DoS) Diplomatic Security Cyber Mission (DSCM) program providing leading cyber and technology security experience to enable innovative, effective and secure business processes.
Location: Beltsville, MD and Roslyn, VA.
The customer requirement requires every employee to be onsite for the first 90 days. After the 90 day period, a hybrid schedule may be offered. The selected candidate must be able to support a hybrid and flexible schedule, in the event of significant cyber incident a continuous on site presence will be required.
Peraton's DSCM program encompasses technical, engineering, data analytics, cyber security, management, operational, logistical and administrative support to aid and advise DoS Cyber & Technology Security (CTS) Directorate. This includes protecting a global cyber infrastructure comprising networks, systems, information, and mobile devices all while identifying and responding to cyber risks and threats. Those supporting Peraton's DSCM program strive to leverage their expert knowledge and propose creative solutions to real-world cybersecurity challenges.
What you'll do:
- Support the Cyber Incident Response Team (CIRT) as a key member of Incident Response Tiger Team.
- Provide Subject Matter Expert (SME) level incident management support in a 24x7x365 environment.
- Share in-depth knowledge and intelligence gained from cyber security events with stakeholders.
- Collaborate with Cyber Threat Intelligence (CTI) teams to analyze threat actor tactics, techniques, and procedures (TTPs) and integrate actionable intelligence into incident response workflows.
- Protect against and prevent potential cyber security threats and vulnerabilities.
- Provide SME level response, technical assistance and expertise for significant cyber incidents, investigations and related operational events.
- Conduct advanced analysis and recommend remediation steps.
- Plan and conduct incident response tabletop exercises (TTX), team simulations, and cyber drills to validate response plans and improve overall readiness.
- Develop and implement training programs for incident handling analysts.
- Conduct detailed research to increase awareness and readiness levels of the security operations center.
- Review, draft, edit, update and publish cyber incident response plans.
- Develop key performance indicators (KPIs) and key risk indicators (KRIs) to measure and improve incident response effectiveness.
- Ensure incident response procedures align with industry best practices and compliance frameworks such as NIST 800-61, ISO 27035, CMMC.
- Mentor junior analysts, conduct knowledge transfer sessions, and develop playbooks to enhance the skill set of the security operations team.
#DSCM
QualificationsMinimum Requirements:
- Bachelor's degree and minimum of 14 years' experience, or a Master's degree and a minimum of 12 years' experience. An additional 4 years of experience may be used in lieu of degree.
- Must have one of the following certifications:
- CASP+ CE, CCNP Security, CISA, CISSP (or Associate), CISSP-ISSAP, CISSP-ISSEP, GCED, GCIH.
- Ability to manage and resolve highly complex cyber incidents.
- Ability to recommend sound counter measures to malicious cyber activity.
- Experience in the development of policies and procedures to investigate cyber incidents for the enterprise network.
- Experience handling national state level cyber incidents.
- Experience with evidence collection, custody and control procedures.
- Experience in incident triage.
- Perform cyber defense trend analysis and reporting.
- Experience with the ServiceNow platform.
- Demonstrated knowledge of the Incident Response Lifecycle.
- Demonstrated ability to utilize and leverage forensic tools to assist in determining scope and severity of a cybersecurity incident.
- Ability to identify remediation steps for cybersecurity events.
- Demonstrated strong organizational skills.
- Proven ability to operate in a time sensitive environment.
- Proven ability to communicate orally and written.
- Proven ability to brief (technical/informational) senior leadership.
- U.S. citizenship required.
- An active Secret security clearance with the ability to obtain a final Top Secret clearance.
Preferred Qualifications:
- Experience developing processes and procedures within a help desk or security operations center environment.
- Experience using security tools such as SIEM (Splunk or ELK), EDR/XDR (CrowdStrike, SentinelOne, Microsoft Defender), and network analysis tools (Wireshark, Zeek, Suricata).
- Experience with cloud security incident response, including AWS, Azure, or Google Cloud, with knowledge of cloud-native security controls.
- Knowledge of network architecture, design and security.
- Knowledge of malware analysis, monitoring, and cloud tools and techniques.
- Knowledge of system design and process methodologies.
- Experience in developing and delivering comprehensive training programs.
- Experience collaborating with cross functional teams.
- Experience working in the inter-agency environment.
- Experience coordinating incident response efforts across multiple teams and agencies, including legal, compliance, and law enforcement.
- Ability to communicate technical concepts to executive level leadership.
Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world's leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees do the can't be done by solving the most daunting challenges facing our customers. Visit peraton.com to learn how we're keeping people around the world safe and secure.
Target Salary Range$135,000 - $216,000. This represents the typical salary range for this position based on experience and other factors.
EEO
EEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.
-
Incident Handling-SME
3 weeks ago
Arlington, Virginia, United States Peraton Full timeIncident Handling-SMEJob Locations US-VA-ArlingtonRequisition ID 2025-155099Position Category Intel and Threat AnalysisClearance Top SecretResponsibilitiesPeraton's DSCM program encompasses technical, engineering, data analytics, cyber security, management, operational, logistical and administrative support to aid and advise DoS Cyber & Technology...
-
Incident Handling-SME
2 weeks ago
Arlington, Virginia, United States Peraton Full timeResponsibilitiesPeraton's DSCM program encompasses technical, engineering, data analytics, cyber security, management, operational, logistical and administrative support to aid and advise DoS Cyber & Technology Security (CTS) Directorate. This includes protecting a global cyber infrastructure comprising networks, systems, information, and mobile devices all...
-
Incident Handling-SME
4 weeks ago
Arlington, Virginia, United States Peraton Full timeResponsibilitiesWe are seeking a Cyber Incident Handling SME to become part of Peraton's Department of State (DoS) Diplomatic Security Cyber Mission (DSCM) program providing leading cyber and technology security experience to enable innovative, effective and secure business processes. Location: Beltsville, MD and Roslyn, VA. The customer requirement requires...
-
Arlington, Virginia, United States Apex Systems Full timeIncident Management SME role will be located in Beltsville, MD or Roslyn, VA. One day remote per week This role supports the Cyber Incident Response Team (CIRT) as a key member of Incident Response Tiger Team. The customer requirement requires every employee to be onsite for the first 90 days. After the 90 day period, a hybrid schedule may be offered. What...
-
Incident Resolution Specialist
7 days ago
Arlington, Virginia, United States Interactive Process Technology LLC Full timeWe are looking for an Incident Resolution Specialist to join our team at Interactive Process Technology LLC.In this role, you will be responsible for analyzing and resolving complex incidents that impact our customers' business operations.Key Responsibilities:Analyze and resolve complex incidents that impact our customers' business operationsDevelop and...
-
Network Forensics SME
2 days ago
Arlington, Virginia, United States Gray Tier Technologies Full timeGray Tier Technologies is looking for a Network Forensics Analyst SME to support The Department of Homeland Security (DHS) Hunt and Incident Response Team (HIRT). DHS HIRT secures the Nation's cyber and communications infrastructure. HIRT provides DHS's front-line response for cyber incidents and proactively hunting for malicious cyber activity. Gray Tier...
-
Cyber Incident Response Manager
6 days ago
Arlington, Virginia, United States ANALYGENCE, Inc. Full timeJob Description ANALYGENCE is seeking an experienced Cyber Incident Response Manager (SME) to supportour federal customer who plays a key role in enhancing the security, resiliency, and reliability of the nation's cyber and communications infrastructure. This role directly supports the customer Mission Engineering (ME) Information Security Branch (ISB)...
-
Senior Incident Analysis Manager
1 week ago
Arlington, Virginia, United States Interactive Process Technology LLC Full timeAt Interactive Process Technology LLC, we are committed to delivering innovative business solutions using emerging technologies through proven successful methods.As a Senior Incident Analysis Manager, you will work with a team of technologists focused on delivering practical solutions that solve real problems for major government and business...
-
Incident Response Lead
6 days ago
Arlington, Virginia, United States Nodel Full timeAbout the RoleWe are looking for an experienced Incident Response Lead to join our team. In this role, you will be responsible for managing and coordinating incident response activities, ensuring that all incidents are properly documented and analyzed.Key Responsibilities:Managing and coordinating incident response activitiesEnsuring proper documentation and...
-
IT Security Incident Manager
6 days ago
Arlington, Virginia, United States Nodel Full timeIT Security Incident Manager Job DescriptionWe are looking for an experienced IT Security Incident Manager to join our team. In this role, you will be responsible for managing and coordinating IT security incident response activities, ensuring that all incidents are properly documented and analyzed.Key Responsibilities:Managing and coordinating IT security...
-
Incident Manager
6 days ago
Arlington, Virginia, United States Gray Tier Technologies Full timeGray Tier Technologies is supporting a U.S. Government customer to provide support for onsite incident response to civilian Government agencies and critical asset owners who experience cyber-attacks, providing immediate investigation and resolution. Contract personnel perform investigations to characterize the severity of breaches, develop mitigation plans,...
-
Incident Response Specialist
6 days ago
Arlington, Virginia, United States Base One Technologies Full timeWe are seeking a highly skilled Cybersecurity Incident Manager to join our team at Base One Technologies. This is a critical role that requires expertise in incident response, threat management, and security operations.Responsibilities:Correlate incident data to identify trends and patterns in reported incidents.Recommend defense-in-depth principles and...
-
Cyber Incident Manager/ Incident Manager
3 weeks ago
Arlington, Virginia, United States Nodel Full timeCyber Incident Manager/ Incident Manager Location: Arlington, VA Must have Top Secret Security Clearance Node is supporting a U.S. Government customer to provide support for onsite incident response to civilian Government agencies and critical asset owners who experience cyber-attacks, providing immediate investigation and resolution. Contract personnel...
-
Cyber Incident Manager/ Incident Manager
7 days ago
Arlington, Virginia, United States Nodel Full timeJob Description Job Description Cyber Incident Manager/ Incident ManagerLocation: Arlington, VAMust have Top Secret Security ClearanceNode is supporting a U.S. Government customer to provide support for onsite incident response to civilian Government agencies and critical asset owners who experience cyber-attacks, providing immediate investigation and...
-
Incident Manager
3 days ago
Arlington, Virginia, United States Base One Inc Full timeResponsibilities: - Researching and compiling known resolution steps or workarounds to enable mitigation of potential Computer Network Defense incidents within the enterprise - Applying knowledge of the tactics, techniques, and procedures of various criminal, insider, hacktivist, and nation state threat actors to identify and validate threats - Applying...
-
Incident Manager
6 days ago
Arlington, Virginia, United States Base One Technologies Full timeResponsibilities:• Researching and compiling known resolution steps or workarounds to enable mitigation of potential Computer Network Defense incidents within the enterprise• Applying knowledge of the tactics, techniques, and procedures of various criminal, insider, hacktivist, and nation state threat actors to identify and validate threats• Applying...
-
Incident Response Specialist
6 days ago
Arlington, Virginia, United States Nightwing Full timeCompany OverviewNightwing is a leading provider of cybersecurity solutions, with a reputation for delivering high-quality services to our clients. Our team of experts is dedicated to staying ahead of the latest cyber threats, and we are committed to providing the best possible support to our customers.Job DescriptionWe are seeking a highly skilled Incident...
-
Incident Management Lead
6 days ago
Arlington, Virginia, United States Solutions3 Full timeJob Description:We are seeking an experienced Cybersecurity Incident Response Specialist to join our team. As a Cybersecurity Incident Response Specialist, you will be responsible for investigating and responding to cybersecurity incidents, developing mitigation plans, and assisting with the restoration of services.Responsibilities Include:Investigating and...
-
Incident Manager
3 weeks ago
Arlington, Virginia, United States BCMC, LLC Full timeBCMC is supporting a U.S. Government customer to provide support for onsite incident response to civilian Government agencies and critical asset owners who experience cyber-attacks, providing immediate investigation and resolution. Contract personnel perform investigations to characterize the severity of breaches, develop mitigation plans, and assist with...
-
Incident Response Team Lead
5 days ago
Arlington, Virginia, United States Base One Technologies Full timeIncident Response Team LeadWe are seeking an experienced Incident Response Team Lead to join our team. The successful candidate will be responsible for coordinating the response to cybersecurity incidents, researching and compiling known resolution steps or workarounds to mitigate potential computer network defense incidents, and tracking and documenting...