Peraton is currently seeking a Cyber Monitoring Signature Analyst to become part of Peraton’s Department of State (DoS) Diplomatic Security Cyber Mission (DSCM) program. This position is with the Cyber Incident Response Team. Work in a team environment with senior detection engineers, threat analysts, and incident responders to protect a global IT infrastructure against advanced threat actors. Author, tune, and maintain correlation searches, Risk Notables, and Adaptive Response actions within Splunk Cloud Enterprise Security. Evaluate new analytical detections from open-source libraries and incorporate vetted alerting into a SIEM. Author new correlational searches in SPL/SPL2 using best practice search methodologies. Maintain a living MITRE ATT&CK coverage matrix; identify gaps and prioritize with SME. Ensure proper cohesion and health of SIEM alerting. Collaborate and assist system engineers with the development, configuration and tuning of cyber security tools. Operationalize threat intelligence to ensure Indicators of Compromise are actionable in detections. Provide reporting on detection development metrics (coverage, MTTx, FP rate, notable volume by rule).
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level