Peraton-posted 1 day ago
Full-time • Mid Level
Onsite • Arlington, VA
5,001-10,000 employees

Peraton is seeking a Senior Cyber Security Deception Engineer/Threat Hunter to become part of Federal Strategic Cyber Mission programs. Location: Northern VA; On-site, 5 days a week; must be local to the work location. In this role, you will: Work closely with cross-functional teams, including Security Operations, Incident Response, Threat Intelligence, and Threat Hunting to ensure a proactive and robust security posture. Perform advanced network threat hunting to detect malicious or suspicious behavior on Department on-premise and cloud-based networks. Respond to security events received from CIRT, provide comprehensive findings and recommend remediation steps. Perform advanced traffic analysis (at the packet level) and reconstruction of network traffic to discover anomalies, trends, and patterns. Perform forensic analysis of suspected systems (e.g. on and off premise network devices, and storage media) impacted by malicious activity. Implement and use cyber security frameworks (e.g. MITRE-ATT&CK, Kill Chain, etc.). Has proven expertise in performing analyses to validate established security requirements and recommended additional security requirements and safeguards. May interface with external entities including law enforcement, intelligence and other government organizations and agencies. Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world’s leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees do the can’t be done by solving the most daunting challenges facing our customers. Visit peraton.com to learn how we’re keeping people around the world safe and secure.

  • Work closely with cross-functional teams, including Security Operations, Incident Response, Threat Intelligence, and Threat Hunting to ensure a proactive and robust security posture.
  • Perform advanced network threat hunting to detect malicious or suspicious behavior on Department on-premise and cloud-based networks.
  • Respond to security events received from CIRT, provide comprehensive findings and recommend remediation steps.
  • Perform advanced traffic analysis (at the packet level) and reconstruction of network traffic to discover anomalies, trends, and patterns.
  • Perform forensic analysis of suspected systems (e.g. on and off premise network devices, and storage media) impacted by malicious activity.
  • Implement and use cyber security frameworks (e.g. MITRE-ATT&CK, Kill Chain, etc.).
  • Has proven expertise in performing analyses to validate established security requirements and recommended additional security requirements and safeguards.
  • May interface with external entities including law enforcement, intelligence and other government organizations and agencies.
  • Bachelor’s degree and 9 years of experience, or 7 years of experience with a Master’s. An additional 4 years of experience will be considered in lieu of degree.
  • Must possess or be able to obtain at least one of the following certifications before start date. C ontinued certification required as a condition of employment: CCNA-Security, CND, CySA+, GICSP, GSEC, Security+ CE, or SSCP
  • Proven ability to develop and recommend corrective actions.
  • Expertise, knowledge, and experience integrating new architectural analysis of cyber security features.
  • Comfortable interfacing with external entities including law enforcement, intelligence and other government organizations and agencies.
  • Experience in threat hunting or network/cloud forensics.
  • U.S. citizenship is required.
  • Active Top Secret security clearance required.
  • The ability to obtain a final TS/SCI.
  • Experience using Databricks.
  • Experience using Artificial intelligence (AI) and large language models (LLMs).
  • Ability to create, troubleshoot, configure and operate complex scripting solutions with the ability to output the results in a variety of formats (e.g. HTML, XML, etc.) and to re-purpose the results for reports targeting different technical levels (e.g. other analysts, management, etc.)
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service