Middle SOC Analyst
Peraton is seeking a SOC Analyst to join our team of qualified and diverse individuals on our Department of State (DOS) Bureau of Diplomatic Technology (DT) Consular Affairs Enterprise Infrastructure Operations (CAEIO) program. CAEIO provides IT Operations and Maintenance to modernize the legacy networks, applications, and databases supporting consular applications and services globally.
Core Work Schedule: Third shift: 11:00PM – 7:30AM EST, Thursday – Monday
Location:This position is fully remote; however, preference will be given to candidates local to the Washington, DC, metropolitan area (DMV) for occasional onsite meetings, training sessions, or customer support activities at the Washington, DC, customer location or the Peraton office in Sterling, VA.The number of days the SOC Analyst works on-site in Washington, DC, or Sterling, VA, is subject to change based on government/program requirements (for example, surge support might require the individual to be in the office five days per week).
Day-to-Day Responsibilities:
- Monitor and investigate security alerts, perform threat hunting, and notify designated managers, cyber incident responders, and cybersecurity service provider personnel of suspected incidents. Clearly articulate event history, status, and potential impact in accordance with the organization’s cyber incident response plan.
- Analyze and characterize network traffic to identify anomalous activity and potential threats to network resources.
- Create advanced ad hoc SPL queries.
- Coordinate with internal and external teams to investigate threats, assess risks, and conduct forensic analysis.
- Review and analyze log files from various sources (host logs, network traffic logs, firewall logs, IDS logs) to identify potential security threats.
- Utilize SIEM and EDR tools to monitor the operational environment.
- Develop and document configuration standards, policies, and procedures to operate, manage, and secure system infrastructure.
- Advise management and team members on technology risks and recommend mitigation strategies.
- Engage with multiple levels of management, providing technical expertise and thought leadership.
- Prepare reports detailing investigations, incidents, and other security-related activities.
- Identify and classify attack tactics and techniques.
- Recommend and implement enhancements to improve system performance, security, and reliability.
- Build and refine SOC processes and procedures, including documenting work in SOPs.
- Train and mentor junior SOC team members.
- Plan and execute SOC-related projects and initiatives.
- Communicate clearly and professionally with managers and colleagues.
- Demonstrate flexibility and an eagerness to take on additional responsibilities as needed.
Basic Qualifications:
- Bachelors degree and 2 years of experience or an Associates degree and 4 years of experience or a High School diploma/equivalent and 6 years of experience.
- U.S. citizenship and an active SECRET security clearance
- 2+ years of cybersecurity, SOC, or systems security experience in a federal government environment supporting business critical, high availability systems.
- 2+ years of SOC or cybersecurity related experience.
- Experience working with a SIEM platform, preferably Splunk.
- Experience using Splunk dashboards and Microsoft Sentinel for security monitoring and analysis.
- Experience querying and analyzing security data, including SPL, with a working understanding of data types, conditions, and regular expressions.
- Working knowledge of system, network, and application security threats and vulnerabilities, with the ability to support the development and improvement of monitoring solutions.
- Understanding of Boolean logic and event correlation.
- Experience identifying logging and monitoring gaps and supporting efforts to improve security monitoring.
- Working knowledge of cybersecurity incidents, anomaly analysis, log analysis, digital forensics, and common threat vectors.
- Understanding of TCP/IP, UDP, network ports, protocols, and traffic flow.
- Security+ CE or other DoD 8570 IAT Level II certification.
- Familiarity with cybersecurity frameworks and specifications, including RMF and NIST standards, such as NIST SP 800-53.
Familiarity frameworks and specifications, including RMF and NIST standards (e.g., NIST SP 800-53)
Preferred Qualifications:
- Experience with Splunk data normalization (field aliases, calculated fields, field extractions)
- Splunk Power User certification or higher
- Experience tracking incidents using the MITRE ATT&CK framework
- Knowledge of cloud security
- Experience with system administration, networking, and operating system hardening techniques
- Mixed OS experience (Linux, Windows)
- Experience troubleshooting storage-related issues
- Scripting or coding experience
- Knowledge of Web Application Firewall (WAF) security features
Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world’s leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees do the can’t be done by solving the most daunting challenges facing our customers. Visit peraton.com to learn how we’re keeping people around the world safe and secure.
Required Skills
Required Languages
🇬🇧 English