Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Tier 2 Cyber Incident Response Team (CIRT) Shift Lead Jobs

$135k - $216k

Navstar

About Peraton

Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world's leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees solve the most daunting challenges that our customers face. Visit peraton.com to learn how we're keeping people around the world safe and secure.

Program Overview

Encompasses technical, engineering, data analytics, cyber security, management, operational, logistical, and administrative support for Bureau of Diplomatic Security, Cyber and Technology Security Directorate in three key offices/functional areas: Cyber Monitoring and Operations, Cyber Threat and Investigations, and Technology Innovation and Engineering State.

About The Role

Peraton is seeking an experienced Tier 2 Cyber Incident Response Team (CIRT) Shift Lead to join Peratons' Federal Strategic Cyber Mission program.

Location: Beltsville, MD; On-site

Work Hours: Evening Shift, 14:00- 22:00 EST (2:00 - 10:00 PM, EST), Tuesday - Saturday

In this role, you will:
  • Detect, classify, process, track, and report on cyber security events and incidents.
  • Perform advanced in-depth analysis of coordinated Tier 1 alert triage and requests in a 24x7x365 environment.
  • Analyze logs from multiple sources (e.g., host logs, EDR, firewalls, intrusion detection systems, servers) to identify, contain, and remediate suspicious activity.
  • Characterize and analyze network traffic to identify anomalous activity and potential threats.
  • Protect against and prevent potential cyber security threats and vulnerabilities.
  • Perform forensic analysis of hosts artifacts, network traffic, and email content.
  • Analyze malicious scripts and code to mitigate potential threats.
  • Conduct malware analysis to generate IOCs to identify and mitigate threats.
  • Collaborate with Department of State teams to analyze and respond to events and incidents.
  • Monitor and respond to the CIRT Security Orchestration and Automation Response (SOAR) platform, hotline, email in-boxes.
  • Create tickets and initiate workflows as instructed in technical SOPs.
  • Coordinate and report incident information to the Cybersecurity and Infrastructure Security Agency (CISA).
  • Collaborate with other local, national and international CIRTs as directed.
  • Submit alert tuning requests.
Additionally, as a Tier 2 Shift Lead you will:
  • Review all Tier 2 shift tickets for accuracy and completeness
  • Coordinate with CIRT Watch Officers and government leadership on remediation actions
  • Provide technical and procedural improvement recommendations to CIRT leadership
  • Assist with Tier 2 candidate technical interviews as required
  • Ensure coordinated remediation actions are operating properly
Qualifications

Minimum Qualifications
  • Bachelor's degree and minimum of 11 years of relevant experience; or, Master's degree with minimum of 9 years; or PhD with 6 years.
  • Must possess, or obtain prior to start date, at least one of the following certifications. Continued certification is required as a condition of employment:
    • CASP+ CE, CCISO, CCNA Cyber Ops, CCNA Security, CCNP Security, CEH, CFR, CISA, CISM, CISSP (or Associate), CISSP-ISSAP, CISSP-ISSEP, Cloud+, CySA+, GCED, GCIA, GCIH, GICSP, GSLC, SCYBER.
  • Demonstrated experience across the incident response lifecycle.
  • Experience with SOAR platforms and automated response workflows (e.g., ServiceNow, Splunk SOAR, Microsoft Sentinel).
  • Experience with Security Information and Event Management (SIEM) platforms (e.g., Splunk, Microsoft Sentinel, Elastic, QRadar).
  • Experience with Endpoint Detection and Response (EDR) solutions (e.g., Microsoft Defender for Endpoint, Elastic XDR, Carbon Black, CrowdStrike).
  • Knowledge of cloud security monitoring and incident response.
  • Knowledge of integrating indicators of compromise (IOCs) and tracking advanced persistent threat (APT) actors.
  • Ability to analyze cyber threat intelligence and understand adversary tactics, techniques, and procedures (TTPs).
  • Knowledge of malware analysis techniques.
  • Familiarity with MITRE ATT&CK and D3FEND frameworks.
  • U.S. Citizenship required.
  • Active Secret security clearance required at start.
Preferred Qualifications:
  • Proficiency with Splunk for security monitoring, alert creation, and threat hunting.
  • Experience using Microsoft Azure access and identity management.
  • Proficiency in Microsoft Defender for Endpoint and Identity for security monitoring, response, and alert generations.
  • Experience using digital forensics collection and analysis tools (e.g. Autopsy, Axiom MagnetForensics, Zimmerman-Tools, KAPE, CyLR, Volatility).
  • Experience using ServiceNow SOAR for ticketing and automated response.
  • Experience using Python, PowerShell and BASH scripting languages.
  • Proficiency in cloud security monitoring and incident response.
  • Demonstrated ability to perform static/dynamic malware analysis and reverse engineering.
  • Experience with integrating cyber threat intelligence and IOC-based hunting.
  • Technical certifications such as: Azure SC-900, CCSP, GCIH, CCSK, GSEC, CHFI, GCLD, GCIA.
  • Advanced technical certifications such as: SecurityX/CASP+, PRMP, GREM, GEIR, GNFA, or GCFA.
Details

Target Salary Range: $135,000 - $216,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual's experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.

Benefits Statement: Peraton offers eligible employees a variety of benefits including medical, dental, vision, life, health savings account, short/long term disability, EAP, parental leave, 401(k), paid time off (PTO) for vacation, and company paid holidays. A full listing of available benefits can be viewed at

Application Statements: The application period for the job is estimated to be 30 days from the job posting date. However, this timeline may be shortened or extended depending on business needs and the availability of qualified candidates. By applying to this job, you are expressing interest in the role and the Company. During the review of your application, you may be required to participate in an on-camera interview, as well as participate in a process to verify your identity.

EEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.
Vacancy posted 9 hours ago
Similar jobs that could be interesting for youBased on the Tier 2 Cyber Incident Response Team (CIRT) Shift Lead Jobs in Beltsville, MD vacancy
  • $135k - $216k

     ...Tier 2 Cyber Incident Response Team (CIRT) Shift Lead Peraton is seeking an experienced Tier 2 Cyber Incident Response Team (CIRT) Shift Lead to join Peratons' Federal Strategic Cyber Mission program. Location: Beltsville, MD; On-site Work Hours: Evening Shift... 
    Shift work
    Cyber
    Contract work
    Local area
    All shifts
    Afternoon shift

    Peraton

    Beltsville, MD
    2 days ago
  • $80k - $92k

     ...Job Description Job Description SkyePoint Decisions is a leading Cybersecurity Architecture and Engineering, Critical...  ...seeking an experienced Tier 2 Analyst for the Cyber Incident Response Team to support our customer...  ...and respond to the CIRT Security Orchestration... 
    Cyber
    Contract work
    Local area

    SkyePoint Decisions

    Beltsville, MD
    a month ago
  • $60 per hour

     ...Athene is searching for a Part-Time Tier 2 Incident Response Analyst (IR) to support a law...  ...alerts, and investigating potential cyber threats. As a SOC team member, you will also serve as the...  ...on the client site as needed Shift: ~ Fri Night - Sat Morning 10pm... 
    Shift work
    Cyber
    Part time
    Worldwide
    Night shift
    Weekend work
    Day shift

    Tyto Athene, LLC

    Washington DC
    4 days ago
  • $66k - $106k

     ...Responsibilities Peraton is seeking an experienced CIRT Tier 2 Analyst to join Peratons'...  ...Federal Strategic Cyber Mission...  ...Hours: Evening Shift, 14:00- 22:00...  ...security events and incidents. * Perform...  ...Department of State teams to analyze and...  ...the world's leading mission... 
    Shift work
    Cyber
    Contract work
    Local area
    Afternoon shift

    Peraton

    Beltsville, MD
    3 days ago
  • A cybersecurity firm is looking for a Tier 2 Incident Response Analyst to support law enforcement in Washington, DC. You will monitor security tools, triage alerts, and investigate cyber threats. Ideal candidates have six years in cybersecurity, preferably three in SOC... 
    Cyber

    Tyto Athene, LLC

    Washington DC
    3 days ago
  • $80k - $128k

     ...Responsibilities Position: Tier 2/3 Cyber Security Analyst - Microsoft Sentinel...  ...for complex security incidents, lead advanced threat-...  ...Collaborate with customer teams to investigate and...  ...and international CIRTs as directed. •...  ...eligible for overtime, shift differential, and a... 
    Shift work
    Cyber
    Contract work
    Work at office
    Local area

    Peraton

    Washington DC
    5 days ago
  • Tyto-Athene is seeking a Part-Time Tier 2 Incident Response Analyst to support law enforcement in Washington, DC. You will monitor cybersecurity tools, triage alerts, and respond to incidents. Ideal candidates have significant cybersecurity experience and a Bachelor's... 
    Part time

    Tyto-Athene

    Washington DC
    4 days ago
  • $83.5k - $87.5k

     ...Overview The Cyber Incident Response Analyst role is pivotal in...  ...cases to specialized teams (e.g., Threat Hunting,...  ...~Participate in shift synchronization meetings...  ...practices. ~Additional (2) two years of experience...  ...: Please note this job description is not designed... 
    Shift work
    Cyber
    Temporary work
    Work at office
    Local area
    Flexible hours

    Navstar

    Washington DC
    1 day ago
  •  ...The Perks: As recognized members of the Cyber Elite, we work together in partnership...  ...We are committed to the belief that our team members do their best work when they...  ...Who we’re looking for: We are seeking an Incident Response Lead to serve as the Subject Matter Expert (... 
    Cyber
    Contract work

    ShorePoint

    Washington DC
    3 days ago
  •  ...have a new and exciting role available within our Cyber Security division for an Incident Response Engagement Lead in the United States. S-RM is a global intelligence...  ...are in more demand than ever. We’re building a team to meet this challenge. We’re quick to respond, innovate... 
    Cyber
    Immediate start
    Flexible hours

    S-RM Intelligence and Risk Consulting

    Washington DC
    3 days ago
  • $160k - $190k

     ...Incident Response (IR) Tech Lead Job Locations US-MD-Bethesda ID 2026-4536...  ...maturation of an Incident Response team comprised of IR Tier-1, IR Tier-2, and Forensics specialists on...  ...techniques to defend against complex cyber threats. This role requires... 
    Cyber
    Full time
    Contract work

    Edgewater Federal Solutions

    Bethesda, MD
    1 day ago
  •  ...Job Description Job Description Salary...  ...recognized members of the Cyber Elite, we work...  ...belief that our team members do their best...  ...We are seeking a Tier 2 Analyst (Secret Clearance...  ...to improve incident detection, analyze...  ...support detection and response. Support incident... 
    Cyber

    ShorePoint

    Washington DC
    13 days ago
  •  ...cloud services; cyber; software; advanced...  ...seeking Watch Team Systems...  ...alerts, coordinate incident management, and...  ...the first line of response for outages affecting...  ...within two (2) hours to prevent...  ...Perform first-tier triage on Windows...  ...comfort with rotating shifts, on-call... 
    Shift work
    Cyber
    Local area
    Night shift
    Rotating shift

    Navstar

    Washington DC
    1 day ago
  •  ...Cyber Incident Responder Detect-Response performs all procedures necessary to ensure the safety of information...  ..., and Web-based security. Shift work may be required . Level...  .... May serve as a team or task lead. Job Description : Monitors and... 
    Shift work
    Cyber

    IC-CAP, LLC

    Washington DC
    2 days ago
  •  ...The Incident Response Coordinator supports the end-to...  ...communication among technical teams, vendors, and...  ...engage infra/app/cyber/vendor...  ...status pages); manage shift handoffs and continuity...  ...Improvement: Help lead PIRs; identify...  ...promoting for all job classifications is... 
    Shift work
    Cyber
    Contract work
    Work experience placement
    Work at office

    ASM Research, An Accenture Federal Services Company

    Washington DC
    3 days ago
  •  ...seeking an  to serve as Tier 2 - Senior Desk...  ...in a senior or lead role. This position...  ...collaboration across IT teams to ensure reliable...  ...:  76,000-85,000 Responsibilities: ~Serve as the...  ...tools to document incidents, resolutions, and...  ...Cloud Solutions, Cyber Security, and IT... 
    Cyber
    Full time
    Remote work

    ActioNet

    Washington DC
    1 day ago
  •  ...The Incident Response Coordinator, Senior leads tactical coordination of complex IT...  ...runbooks, drives cross-team collaboration, and...  ...Manager, integrates with cyber defenders when...  ...consistent execution across shifts/teams. Mentoring:...  ...promoting for all job classifications is... 
    Shift work
    Cyber
    Contract work
    Work experience placement
    Work at office

    ASM Research, An Accenture Federal Services Company

    Washington DC
    1 day ago
  • $26.44 per hour

     ...Government Services company, is seeking a Tier 2 Help Desk Engineer to support KITS...  ...(3) days per week. Be a part of a shift team schedule with shifts falling between...  ...accordance with Public Law 88-352 Job Details Job Family IT, Cyber Security, Network Systems Job... 
    Shift work
    Cyber
    Hourly pay
    Work at office
    Local area
    Relocation
    Flexible hours
    3 days per week

    Koniag Government Services

    Washington DC
    5 days ago
  • $10k

     ...Administrator Level 2 to support...  ...operational teams. You will...  ...operates in a shift-based...  ...support. Key Responsibilities: Install,...  ...resolution of incidents Coordinate...  ...Global Industrial Cyber Security Professional...  ...factors: Job Role and...  ...: Our tiered program provides... 
    Shift work
    Cyber
    Temporary work
    For contractors
    Local area
    Monday to Friday

    Columbia Technology Partners

    Annapolis Junction, MD
    4 days ago
  • $180k - $210k

     ...Penetration Tester, Lead Job ID...  ...Full-Time Shift: Day Telework...  ...cybersecurity team focused on securing...  ...collaborate closely with cyber SMEs, engineers...  .... Responsibilities Conduct internal...  ...Support cyber incident response activities...  ...a team of top-tier professionals... 
    Shift work
    Cyber
    Full time
    Remote work
    Flexible hours

    Wood Consulting

    Annapolis Junction, MD
    1 day ago
  • $135k - $216k

     ...Responsibilities Peraton is seeking a Team Lead / Information Systems Security Engineer  to support...  ...our Federal Strategic Cyber programs. Location:...  ...expertise to risk analysis, incident response, system...  ...eligible for overtime, shift differential, and a discretionary... 
    Shift work
    Cyber
    Contract work
    For contractors
    Work at office

    Peraton

    Washington DC
    5 days ago
  • $100k - $126.5k

     ...Associate/Cybersecurity & Incident Response CRA's Forensic...  ...deploying cross-trained teams of forensic professionals...  ...clients on the adequacy of cyber security controls in...  ...following - NIST CSF 2.0, HIPAA, ISO 27001 and...  ...and apply for available jobs. Career Growth and... 
    Cyber
    Work at office
    Work from home
    3 days per week

    Charles River Associates

    Washington DC
    3 days ago
  • $130k - $152.5k

     ...Associate/Cybersecurity & Incident Response (Forensic Services...  ...CRA is a leading global consulting...  ...deploying cross-trained teams of forensic...  ...on the adequacy of cyber security controls...  ...following - NIST CSF 2.0, HIPAA, ISO 270...  ...apply for available jobs. Career Growth... 
    Cyber
    Work at office
    Local area
    Work from home
    3 days per week

    Charles River Associates

    Washington DC
    2 days ago
  • $104k - $166k

     ...Administrator Job Locations...  ...w/Poly Responsibilities Peraton...  ...infrastructure team for a...  ...Provide Tier 1 and Tier 2 support for...  ...operational incidents Diagnose...  ...developers, or cyber/network experimentation...  ...the world's leading mission...  ...for overtime, shift differential... 
    Shift work
    Cyber
    Full time
    Contract work
    For subcontractor
    Relocation package

    Peraton

    College Park, MD
    1 day ago
  •  ...Cyber Incident Response Analyst Location: Houston, Texas (Preferred)/Washington, DC/San Ramon, CA (Hybrid – 1-2 Day/week Onsite) Job Type: Long Term Contract This is a 24/7 team and they are on call once every 9 weeks. This usually consists of about 25 extra... 
    Cyber
    Long term contract
    Local area
    2 days per week
    1 day per week

    Samprasoft

    Washington DC
    4 days ago
  •  ...Trust ActioNet is seeking a Tier 2 - Desk Side Support - IT...  ...Salary Range: 65,000-75,000 Responsibilities: Provide Tier 2 desk...  ...with Tier 3 and Infrastructure teams for escalation and advanced...  ...Engineering, Cloud Solutions, Cyber Security, and IT Managed Services... 
    Cyber
    Full time
    Work at office
    Remote work

    ActioNet

    Washington DC
    4 days ago
  • $55.7k - $82.1k

     ...The Cybersecurity Incident Response Engineer, Jr. monitors enterprise...  ...violations. Perform Tier 1 alert triage by...  ..., operations, and risk teams to align monitoring and...  ...environment, including shift work and effective handoff...  ...and promoting for all job classifications is done... 
    Shift work
    Contract work
    Work at office

    ASM Research, An Accenture Federal Services Company

    Washington DC
    1 day ago
  •  ...Job Description Job Description Cyber Incident Manager Location: Washington...  ...nationwide. Our teams deliver rapid incident response, advanced forensics...  ...Manager to lead onsite incident...  ...NIST SP 800-61 Rev.2 and FISMA reporting...  ...or managing shift-based or 24×7 cyber... 
    Shift work
    Cyber
    Immediate start

    Argo Cyber Systems

    Washington DC
    25 days ago
  •  ...cybersecurity consulting firm is seeking an Incident Response Analyst to support incident management...  ...coordination with federal cybersecurity teams. Ideal candidates will have experience...  ...site duties in the Washington, D.C. area. #J-18808-Ljbffr Cyber Synergy Consulting Group
    Cyber
    Remote job

    Cyber Synergy Consulting Group

    Washington DC
    3 days ago
  •  ...Cyber Incident Detector Level 3 will have the opportunity to build strong...  .... May serve as a team or task lead. How a Cyber Incident Detector...  .... Day, Swing, or Mid Shift position available- willing...  ...Certifications : ~ IAT Level 2 Security Clearance:... 
    Shift work
    Cyber
    Weekend work
    Day shift
    Afternoon shift

    IC-CAP, LLC

    Washington DC
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Tier 2 Cyber Incident Response Team (CIRT) Shift Lead Jobs. Be the first to apply!