×
Register Here to Apply for Jobs or Post Jobs. X

Cyber Monitoring Signature Analyst with Security Clearance

Job in Beltsville, Prince George's County, Maryland, 20704, USA
Listing for: Peraton
Full Time position
Listed on 2026-08-07
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, Security Management & Operations
Job Description & How to Apply Below
About Peraton Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world's leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace.

The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees solve the most daunting challenges that our customers face. Visit  to learn how we're keeping people around the world safe and secure. Program Overview Encompasses technical, engineering, data analytics, cyber security, management, operational, logistical, and administrative support for Bureau of Diplomatic Security, Cyber and Technology Security Directorate in three key offices/functional areas:
Cyber Monitoring and Operations, Cyber Threat and Investigations, and Technology Innovation and Engineering State. About

The Role Peraton is currently seeking a Cyber Monitoring Signature Analyst to become part of Peraton's Department of State (DoS) Diplomatic Security Cyber Mission (DSCM) program.

Location:

Rosslyn, VA and a secondary at Beltsville, MD

Schedule:

Mon-Friday, 08:00-16:00 (8:00 AM - 4:00PM) In this role, you will:
* Work under senior detection engineers and Subject Matter Experts with cutting edge cyber monitoring tools to build and enhance the organization's threat detection and response capabilities. This position is with the Cyber Incident Response Team.

* Work in a team environment with senior detection engineers, threat analysts, and incident responders to protect a global IT infrastructure against advanced threat actors.

* Author, tune, and maintain correlation searches, Risk Notables, and Adaptive Response actions within Splunk Cloud Enterprise Security.
* Evaluate new analytical detections from open-source libraries and incorporate vetted alerting into a SIEM.

* Author new correlational searches in SPL/SPL2 using best practice search methodologies.

* Maintain a living MITRE ATT&CK coverage matrix; identify gaps and prioritize with SME.

* Ensure proper cohesion and health of SIEM alerting.

* Collaborate and assist system engineers with the development, configuration and tuning of cyber security tools.

* Operationalize threat intelligence to ensure Indicators of Compromise are actionable in detections.

* Provide reporting on detection development metrics (coverage, MTTx, FP rate, notable volume by rule).#DSCM Qualifications Minimum requirements are:
* Bachelor's degree and 5 years of relevant experience; or, 3 years with a Masters degree. An additional 4 years of experience in lieu of the bachelors degree will be considered.
* Must possess and maintain one of the following certifications or the ability to obtain before start date: CASP+ CE, CCNA Cyber Ops, CCNA-Security, CCNP Security, CEH, CFR, CHFI, CISA, CISSP (or Associate), CySA+, GCED, GCFA, GCIH, SCYBER, or Security+

* Hands-on experience authoring and tuning SPL in a production Splunk environment (minimum 3 years).

* Working knowledge of Splunk Enterprise Security (correlation searches, notable events, Incident Review, Adaptive Response) - ES 8.x experience strongly preferred.

* Demonstrated experience with the Splunk Common Information Model (CIM) and writing performant searches against accelerated data models.

* Experience modifying Splunk ES searches, macros, and lookup tables.

* Familiarity with the MITRE ATT&CK framework and its application to detection engineering.

* Working knowledge of Zeek, Suricata, and at least one EDR.

* Demonstrated knowledge of the Incident Response Lifecycle and how it applies to cloud, legacy, and hybrid environments.

* Strong organizational skills.

* Proven ability to operate in a time-sensitive environment.

* Proven ability to effectively communicate orally and in writing.

* U.S. Citizenship is required

* Ability to obtain an interim Secret clearance…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary