Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Tier 2 Cyber Incident Response Team (CIRT) Shift Lead Jobs

$135k - $216k

Peraton

About Peraton

Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world's leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees solve the most daunting challenges that our customers face. Visit peraton.com to learn how we're keeping people around the world safe and secure.

Program Overview

Encompasses technical, engineering, data analytics, cyber security, management, operational, logistical, and administrative support for Bureau of Diplomatic Security, Cyber and Technology Security Directorate in three key offices/functional areas: Cyber Monitoring and Operations, Cyber Threat and Investigations, and Technology Innovation and Engineering State.

About The Role

Peraton is seeking an experienced Tier 2 Cyber Incident Response Team (CIRT) Shift Lead to join Peratons' Federal Strategic Cyber Mission program.

Location: Beltsville, MD; On-site

Work Hours: Evening Shift, 14:00- 22:00 EST (2:00 - 10:00 PM, EST), Tuesday - Saturday

In this role, you will:
  • Detect, classify, process, track, and report on cyber security events and incidents.
  • Perform advanced in-depth analysis of coordinated Tier 1 alert triage and requests in a 24x7x365 environment.
  • Analyze logs from multiple sources (e.g., host logs, EDR, firewalls, intrusion detection systems, servers) to identify, contain, and remediate suspicious activity.
  • Characterize and analyze network traffic to identify anomalous activity and potential threats.
  • Protect against and prevent potential cyber security threats and vulnerabilities.
  • Perform forensic analysis of hosts artifacts, network traffic, and email content.
  • Analyze malicious scripts and code to mitigate potential threats.
  • Conduct malware analysis to generate IOCs to identify and mitigate threats.
  • Collaborate with Department of State teams to analyze and respond to events and incidents.
  • Monitor and respond to the CIRT Security Orchestration and Automation Response (SOAR) platform, hotline, email in-boxes.
  • Create tickets and initiate workflows as instructed in technical SOPs.
  • Coordinate and report incident information to the Cybersecurity and Infrastructure Security Agency (CISA).
  • Collaborate with other local, national and international CIRTs as directed.
  • Submit alert tuning requests.
Additionally, as a Tier 2 Shift Lead you will:
  • Review all Tier 2 shift tickets for accuracy and completeness
  • Coordinate with CIRT Watch Officers and government leadership on remediation actions
  • Provide technical and procedural improvement recommendations to CIRT leadership
  • Assist with Tier 2 candidate technical interviews as required
  • Ensure coordinated remediation actions are operating properly
Qualifications

Minimum Qualifications
  • Bachelor's degree and minimum of 11 years of relevant experience; or, Master's degree with minimum of 9 years; or PhD with 6 years.
  • Must possess, or obtain prior to start date, at least one of the following certifications. Continued certification is required as a condition of employment:
    • CASP+ CE, CCISO, CCNA Cyber Ops, CCNA Security, CCNP Security, CEH, CFR, CISA, CISM, CISSP (or Associate), CISSP-ISSAP, CISSP-ISSEP, Cloud+, CySA+, GCED, GCIA, GCIH, GICSP, GSLC, SCYBER.
  • Demonstrated experience across the incident response lifecycle.
  • Experience with SOAR platforms and automated response workflows (e.g., ServiceNow, Splunk SOAR, Microsoft Sentinel).
  • Experience with Security Information and Event Management (SIEM) platforms (e.g., Splunk, Microsoft Sentinel, Elastic, QRadar).
  • Experience with Endpoint Detection and Response (EDR) solutions (e.g., Microsoft Defender for Endpoint, Elastic XDR, Carbon Black, CrowdStrike).
  • Knowledge of cloud security monitoring and incident response.
  • Knowledge of integrating indicators of compromise (IOCs) and tracking advanced persistent threat (APT) actors.
  • Ability to analyze cyber threat intelligence and understand adversary tactics, techniques, and procedures (TTPs).
  • Knowledge of malware analysis techniques.
  • Familiarity with MITRE ATT&CK and D3FEND frameworks.
  • U.S. Citizenship required.
  • Active Secret security clearance required at start.
Preferred Qualifications:
  • Proficiency with Splunk for security monitoring, alert creation, and threat hunting.
  • Experience using Microsoft Azure access and identity management.
  • Proficiency in Microsoft Defender for Endpoint and Identity for security monitoring, response, and alert generations.
  • Experience using digital forensics collection and analysis tools (e.g. Autopsy, Axiom MagnetForensics, Zimmerman-Tools, KAPE, CyLR, Volatility).
  • Experience using ServiceNow SOAR for ticketing and automated response.
  • Experience using Python, PowerShell and BASH scripting languages.
  • Proficiency in cloud security monitoring and incident response.
  • Demonstrated ability to perform static/dynamic malware analysis and reverse engineering.
  • Experience with integrating cyber threat intelligence and IOC-based hunting.
  • Technical certifications such as: Azure SC-900, CCSP, GCIH, CCSK, GSEC, CHFI, GCLD, GCIA.
  • Advanced technical certifications such as: SecurityX/CASP+, PRMP, GREM, GEIR, GNFA, or GCFA.
Details

Target Salary Range: $135,000 - $216,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual's experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.

Benefits Statement: Peraton offers eligible employees a variety of benefits including medical, dental, vision, life, health savings account, short/long term disability, EAP, parental leave, 401(k), paid time off (PTO) for vacation, and company paid holidays. A full listing of available benefits can be viewed at

Application Statements: The application period for the job is estimated to be 30 days from the job posting date. However, this timeline may be shortened or extended depending on business needs and the availability of qualified candidates. By applying to this job, you are expressing interest in the role and the Company. During the review of your application, you may be required to participate in an on-camera interview, as well as participate in a process to verify your identity.

EEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.
Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Tier 2 Cyber Incident Response Team (CIRT) Shift Lead Jobs in Beltsville, MD vacancy
  • $75k - $85k

     ...Hours: Evening Shift, 1400 – 2200...  ...encompasses cyber security, data...  ...events and incidents. Perform advanced...  ...coordinated Tier 1 alert...  ...Department of State teams to analyze...  ...respond to the CIRT Security...  ...and Automation Response (SOAR) platform...  ...and at least 2 years of... 
    Cyber
    Full time
    Interim role
    Local area
    Afternoon shift

    Twenty8tech

    Beltsville, MD
    1 day ago
  • $66k - $106k

     ...Peraton is seeking an experienced CIRT Tier 2 Analyst to support its Federal Strategic Cyber Mission program in Beltsville,...  ...and report cybersecurity incidents while performing in-depth analysis...  ...106,000, depending on qualifications and responsibilities. #J-18808-Ljbffr... 
    Cyber

    Peraton

    Beltsville, MD
    1 day ago
  • $83.5k - $87.5k

    Overview The Cyber Incident Response Analyst role is pivotal in reinforcing...  ...cases to specialized teams (e.g., Threat Hunting,...  .... Participate in shift synchronization...  ...practices. Additional (2) two years of experience...  ...Duties Please note this job description is not designed... 
    Shift work
    Cyber
    Temporary work
    Work at office
    Local area
    Flexible hours

    Cayuse Holdings

    Washington DC
    2 days ago
  • $80k - $128k

     ...Responsibilities Peraton is seeking an experienced CIRT Tier 1 Analyst to join Peratons' Federal...  ...Strategic Cyber Mission program...  ...security events and incidents. Perform triage...  ...Department teams as needed to...  ...activities. Conduct shift change briefs....  ...and at least 2 years of experience... 
    Shift work
    Cyber
    Contract work
    Local area

    Peraton

    Beltsville, MD
    1 day ago
  • $100k - $120k

     ...Bering Straits Native Corporation is seeking a Sr. Cybersecurity Incident Response Specialist in Washington, DC. This role involves monitoring cyber threats and ensuring the security of networks and systems. The ideal candidate should have a deep understanding of cybersecurity... 
    Cyber

    Bering Straits Native Corporation

    Washington DC
    1 day ago
  •  ...Job Description Job Description Who we...  ...recognized members of the Cyber Elite, we work...  ...belief that our team members do their best...  ...We are seeking a  Tier 2 Analyst for a potential...  ...to improve incident detection, analyze...  ...support detection and response. Support incident... 
    Cyber
    Contract work

    ShorePoint

    Washington DC
    7 days ago
  •  ...CircusTrix dba Sky Zone Team Lead Part-time | Onsite...  ...Facilities - gaining real responsibility, leadership experience...  ...the skills to run a shift like a pro. No need to...  ...policies and complete incident reports when necessary...  ...or older. Minimum of 2 years of progressive... 
    Shift work
    Part time
    Work at office
    All shifts
    Flexible hours
    Weekend work
    Afternoon shift

    PVH (Tommy Hilfiger/Calvin Klein)

    Columbia, MD
    2 days ago
  • $100k - $126.5k

     ...Associate/Cybersecurity & Incident Response CRA's Forensic...  ...deploying cross-trained teams of forensic professionals...  ...clients on the adequacy of cyber security controls in...  ...following - NIST CSF 2.0, HIPAA, ISO 27001 and...  ...and apply for available jobs. Career Growth and... 
    Cyber
    Work at office
    Work from home
    3 days per week

    Charles River Associates

    Washington DC
    7 hours ago
  •  ...Job Description Job Description Benefits: ~401(k) ~401...  ...seeking a mission-driven Rapid Response Team Lead to support the high-priority,...  ...Flag quarters, and immediate incident response across critical...  ...with JNOSC, engineering teams, Tier III service desk, and external... 
    Full time
    Contract work
    Immediate start
    Worldwide
    Night shift

    Geospatial And Cloud Analytics Inc

    Washington DC
    17 days ago
  • $18 per hour

     ...unforgettable birthdays, team events, and school...  ...guide how we lead, collaborate, and show...  ...- gaining real responsibility, leadership experience...  ...skills to run a shift like a pro.No need...  ...policies and complete incident reports when necessary...  ...older.Minimum of 2 years of... 
    Shift work
    Full time
    Part time
    Work at office
    All shifts
    Flexible hours
    Weekend work
    Afternoon shift

    Sky Zone

    Columbia, MD
    2 days ago
  •  ...Wilson Elser is seeking a Senior Cyber Incident Response Attorney for a fully remote role. This position allows nationwide applicants and reports...  ..., and coordinate with clients, carriers, and technical teams. The role emphasizes leadership in incident response, regulatory... 
    Cyber
    Work at office
    Remote work

    Wilson Elser

    Washington DC
    1 day ago
  • $55.7k - $82.1k

     ...The Cybersecurity Incident Response Engineer, Jr. monitors enterprise...  ...violations. Perform Tier 1 alert triage by...  ..., operations, and risk teams to align monitoring and...  ...environment, including shift work and effective handoff...  ...and promoting for all job classifications is done... 
    Shift work
    Contract work
    Work at office

    ASM Research, An Accenture Federal Services Company

    Washington DC
    4 days ago
  • $60k - $100k

     ...cybersecurity operations and a bachelor's degree in a related field. The role involves leading incident response efforts, documenting actions, and collaborating with technical teams to enhance security across multiple environments. Competitive salary range from $60,000... 
    Cyber

    MAXIMUS

    Washington DC
    1 day ago
  •  ...Cayuse is hiring a Cyber Incident Response Analyst in Washington, DC. This role is critical for reinforcing the client’s cybersecurity framework...  ...categorize incidents, and collaborate closely with various teams while maintaining high-quality customer service. Candidates... 
    Cyber

    Unavailable

    Washington DC
    4 days ago
  • $83.5k - $87.5k

    Cayuse Holdings is seeking a Cyber Incident Response Analyst in Washington, DC to enhance the cybersecurity framework. This role involves case management...  ...and CompTIA Security+ certification, with between 0-2 years of experience. The Analyst will work in a professional... 
    Cyber

    Cayuse Holdings

    Washington DC
    2 days ago
  • $30.44 - $41.18 per hour

     ...Responsibilities for this Position...  ...Full time Job Req: RQ223...  ...Description: *Shift options...  ...joining our team to bring routine...  ...routine Tier 1 technical...  ...customer incidents within a ticketing...  ...minimum of 2-3 years...  ..., offering leading...  ...ML, Cloud, Cyber and application... 
    Shift work
    Cyber
    Hourly pay
    Full time
    Temporary work
    Part time
    Immediate start
    Remote work
    Worldwide
    All shifts
    Flexible hours
    Night shift
    Weekend work

    GDIT

    Washington DC
    a month ago
  • $35.04 - $47.4 per hour

     ...Responsibilities for this Position...  ...Full time Job Req: RQ223...  ...Description: *Shift options...  ...joining our team to bring independent...  ...Tier 1 technical...  ...recurring incident trends within...  ...discipline and 2-3 years...  ..., offering leading capabilities...  ...ML, Cloud, Cyber and application... 
    Shift work
    Cyber
    Hourly pay
    Full time
    Temporary work
    Part time
    Work at office
    Immediate start
    Remote work
    Worldwide
    All shifts
    Flexible hours
    Night shift
    Weekend work

    GDIT

    Washington DC
    a month ago
  •  ...are seeking a highly skilled Lead Incident Responder to manage and maintain...  ...in risk management, incident response, and vulnerability assessment...  ...remediation efforts. Cyber Threat Monitoring: Develop and...  ...independently and work as a team. Learns and memories routine... 
    Cyber
    Contract work
    For contractors
    Work at office
    Local area

    DirectViz Solutions

    Washington DC
    3 days ago
  •  ...Federal is seeking a Lead Incident Responder to fulfill a...  ...for day-to-day incident response operations, providing leadership...  ...coordinating with SOC teams, ISSOs, and AOs,...  ...against evolving cyber threats. This position...  ...employer and welcomes all job seekers. It is the policy... 
    Cyber
    Contract work
    Flexible hours

    Evolver

    Washington DC
    1 day ago
  • $110k - $130k

     ...SkyePoint Decisions is a leading Cybersecurity Architecture and Engineering...  ...Decisions is seeking an Incident Response Analyst to support...  ...engineers, vulnerability management teams, system owners, and government...  ..., threat detection, or cyber defense. Experience supporting... 
    Cyber
    Contract work
    Remote work

    SkyePoint Decisions

    Bethesda, MD
    4 days ago
  • cFocus Software seeks a Blue Team Lead to join our program supporting...  ..., managing and performing cyber security assessments, including...  ...practices, MITRE ATT&CK, NIST CSF 2.0, and ITSO leadership...  ...Engineering, Threat Hunting, Incident Response, and Cyber Threat Intelligence... 
    Cyber
    Full time
    Work at office

    cFocus Software Incorporated

    Washington DC
    22 days ago
  •  ...Job Title: Mid-Level Cybersecurity Incident Response Analyst Location: Bethesda, Maryland...  ...Compromise (IOCs). Support Cyber Threat Intelligence (CTI)...  ...collaborate across technical teams. Commitment to...  ...state, or local law. #M-2 #LI-CK1 Ref: #856-Baltimore... 
    Cyber
    Local area

    System One

    Bethesda, MD
    12 hours ago
  •  ...Job Description Job Description Position Title Threat Emulation & Readiness Lead / Red Team Lead Position Overview The Threat Emulation &...  ...emulation, red team operations, cyber readiness exercises, and...  ...organizational detection, response, resilience, and... 
    Cyber

    cFocus Software Incorporated

    Washington DC
    22 days ago
  •  ...Job Overview A law firm seeks a Cyber Incident Response Associate Attorney in Washington, DC. This role involves managing cybersecurity incidents and advising...  ...skills. Ability to work in a fast‑paced environment. Team player. Education JD from an accredited law school.... 
    Cyber
    Flexible hours

    BCG Attorney Search

    Washington DC
    4 days ago
  •  ...A leading consulting firm is seeking a Security Operations Lead to oversee SOC functions and manage a team of Analysts and Engineers in Washington, DC. The ideal candidate will...  ...experience with specific expertise in incident response, threat hunting, and SIEM... 

    Accenture

    Washington DC
    3 days ago
  •  ...Incident Response Analyst (Task 4 – Federal Cybersecurity Contract) Location: Remote with occasional...  ...across multiple federal cybersecurity teams. The ideal candidate has hands-on...  ...playbooks. Required Qualifications ~2–5+ years of experience in cybersecurity... 
    Full time
    Contract work
    Remote work
    Monday to Friday

    Cyber Synergy

    Washington DC
    2 days ago
  • $34.74 - $47 per hour

     ...Responsibilities for this Position Location: USA...  ...Time: Full time Job Req: RQ222391...  ...EXECUTIVE SUPPORT TEAM LEAD Advance the mission...  ...during incidents and service disruptions...  ..., or similar). ~2+ years leading a...  ...modernization, AI/ML, Cloud, Cyber and application... 
    Cyber
    Hourly pay
    Full time
    Temporary work
    Part time
    Work at office
    Immediate start
    Remote work
    Worldwide
    Flexible hours

    GDIT

    Washington DC
    7 days ago
  • $65.44k

     ...protective operations. Responsibilities include:...  ..., cyber fraud, and other...  ...part of an elite team committed to excellence...  ...required to serve a 2-year trial...  ...related field, leading to such a degree...  ...performance of job duties;...  ...Chemical Biological Incident Response Force... 
    Cyber
    Permanent employment
    Full time
    Part time
    Local area
    Immediate start
    Relocation
    Overseas
    Trial period
    Flexible hours

    US Secret Service

    Washington DC
    1 day ago
  • $146k - $234k

    Responsibilities Cloud Systems Administrator - Cyber Missions Team Location: Laurel, MD | Shift: Evening or Mid Shift Peraton is seeking...  ...leverages Java and leading open‑source technologies...  ...Provide Tier 1‑3 operational support...  ...& Network Services: 2+ years managing RedHat... 
    Shift work
    Cyber
    Contract work
    Afternoon shift

    Peraton

    Laurel, MD
    1 day ago
  • $130k - $135k

     ...‑on experience performing responsibilities aligned to incident response, security operations...  ..., threat hunting, or cyber threat intelligence. Must...  ...supporting a weekend schedule. ( 2 nd Shift WEEKEND schedule,...  ...collaboration, and respect for all team members, ensuring that WWT... 
    Shift work
    Cyber
    Full time
    Remote work
    Flexible hours
    Weekend work
    Afternoon shift

    World Wide Technology

    Adelphi, MD
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Tier 2 Cyber Incident Response Team (CIRT) Shift Lead Jobs. Be the first to apply!