Cyberspace Incident Manager

Peraton•Fort Gordon, GA
•Onsite

About The Position

Peraton seeks a Cyberspace Incident Manager to support ARCYBER G3. This role is located at Fort Gordon, GA. The primary responsibility is to manage the lifecycle of suspected and confirmed cyberspace incidents across the Army's portion of the DoD/DoW enterprise automation environments (unclassified and classified) within the Army's Incident Management program of record. This includes intake, categorization, prioritization, escalation, task order generation, and closure tracking, ensuring all incidents are properly documented and routed in accordance with CJCSM 6510.01B, AR 25-2, DA PAM 25-2, and other applicable directives. The role also involves tracking response actions to resolution and verifying timely reporting to all appropriate parties. Additionally, the Cyberspace Incident Manager will receive and process threat intelligence products and Indicators of Attack/Indicators of Compromise notifications, translating them into actionable Task Orders for mission owners and tracking remediation actions. Quality Assurance/Quality Control across all records within the Army's Incident Management program of record is crucial for ARCYBER G3 reporting standards. The position requires coordination and routing of incidents to various organizations, including the Army Criminal Investigation Division and the Army's intelligence warfighting function. Production and delivery of incident management reporting, including verbal briefings, technical write-ups, and data visualizations, are key, leveraging technologies like Microsoft Power BI, Power Automate, and Power Apps for dashboards and automation. The role also involves developing and maintaining continuity documents and CSSP accreditation artifacts, facilitating working groups, coordinating with partners, and supporting MDMP efforts.

Requirements

  • Minimum of 8 years with BS/BA; Minimum of 6 years with MS/MA; Minimum of 3 years with PhD. Will consider HS+12 or Associates +10 years of experience
  • Demonstrated expertise in cyberspace incident management at enterprise scale, including incident lifecycle governance, reporting standards enforcement, cross-organizational coordination, and process standardization across a large DoD network environment
  • Deep familiarity with CJCSM 6510.01B, AR 25-2, DA PAM 25-2, and DoD incident handling and escalation procedures.
  • Must possess DoD 8570 certification for IAT Level II (CCNA, CySA+, GICSP, GSEC, Security+, CND, or SSCP)
  • Must possess DoD 8570 certification for CSSP-Analyst (CEH, CFR, CCNA, CySA+, GCIA, GCIH, GICSP, Cloud+, SCYBER, PenTest+).
  • Able to support 8x5 operations with on-call surge support as mission requires
  • U.S. Citizenship is required
  • Active TS with the ability to obtain and maintain a Polygraph and MEAD clearance

Nice To Haves

  • Hands-on experience with the Army's Incident Management program of record (unclassified and/or classified automation environments).
  • Experience with USCYBERCOM reporting tools or DoD CSSP reporting pipelines
  • Familiarity with the Microsoft Defender suite of applications at a dashboard/reporting level for operational situational awareness.
  • Experience developing or contributing to Microsoft Power Platform dashboards or equivalent operational metrics reporting
  • Experience with ServiceNow or comparable ITSM platforms used in an incident management workflow
  • Experience with API-based data integration between enterprise security platforms
  • Experience with IT and OT cyberspace incident management or coordination within Army/DoD enterprise environments
  • Familiarity with networking protocols and experience triaging network traffic to identify anomalous or potentially malicious activity

Responsibilities

  • Manage the lifecycle of suspected and confirmed cyberspace incidents across the Army's portion of the DoD/DoW enterprise automation environments (unclassified and classified) within the Army's Incident Management program of record — including intake, categorization, prioritization, escalation, task order generation, and closure tracking — ensuring all incidents are properly documented and routed in accordance with CJCSM 6510.01B, AR 25-2, DA PAM 25-2, and other applicable directives
  • Track response actions to resolution and verify timely reporting to all appropriate and responsible parties within required timelines.
  • Receive and process threat intelligence products and Indicators of Attack/Indicators of Compromise notifications; translate them into actionable Task Orders for dissemination to appropriate mission owners; track remediation actions to completion across the enterprise.
  • Conduct Quality Assurance/Quality Control across all records within the Army's Incident Management program of record in support of ARCYBER G3 reporting standards.
  • Coordinate and route suspected and confirmed cyberspace incidents and relevant findings to superior, lateral, and subordinate organizations for incident response, to the Army Criminal Investigation Division, and to the Army's intelligence warfighting function as appropriate.
  • Produce and deliver incident management reporting — including verbal briefings, technical write-ups, and data visualizations — in accordance with Army reporting requirements; leverage appropriate technologies such as Microsoft Power BI, Power Automate, and Power Apps to develop leadership-facing dashboards and automate recurring incident management tasks and reporting workflows.
  • Develop and maintain team and directorate continuity documents and CSSP accreditation artifacts.
  • Facilitate incident management working groups and coordinate with internal and external mission partners in support of government-defined enterprise incident management outcomes.
  • Support directorate and ARCYBER-level Military Decision Making Process (MDMP) efforts for incident management-relevant functions.

Benefits

  • Overtime
  • Shift differential
  • Discretionary bonus
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service