Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Cyber Incident Response Analyst with OT/ICS/SCADA / Travel & Active TS

$104k - $166k

Peraton

Cyber Incident Response Analyst with OT/ICS/SCADA / Travel & Active TS

Job Locations


US-VA-Arlington

Requisition ID


View phone number on click.appcast.io

Position Category


Intel and Threat Analysis

Clearance


Top Secret/SCI

Responsibilities

Peraton is currently seeking to hire an experienced Incident Response Analyst (ICS/OT/SCADA) for its' Federal Strategic Cyber group.

Location: Onsite in Arlington, VA

Travel: Approximately 40%

Peraton is seeking an experienced Incident Response Analyst with strong OT/ICS/SCADA expertise to support its Federal Strategic Cyber program. This role involves responding to cyber incidents across critical infrastructure sectors and working closely with technical teams, forensic analysts, and mission partners to safeguard nationallevel systems.

In This Role, You Will:

  • Respond to cybersecurity incidents across ICS, OT, and IT environments and provide recommendations to prevent recurrence within critical infrastructure sectors.
  • Apply functional knowledge to resolve incidents, conduct proactive threat hunts, and contribute to solutions for problems of moderate scope and complexity.
  • Support highly technical operations and forensic analysis while advising client decisionmakers.
  • Provide sectorspecific expertise for one or more critical infrastructure areas, including Water, Power, Critical Manufacturing, and Transportation.
  • Follow established procedures for incident response and escalation.
  • Help define and refine response procedures for industrial control system environments.
  • Apply traditional incident response and threathunting tradecraft to ICS/criticalinfrastructure environments while accounting for operational constraints.
  • Collaborate with host, network, and cloud forensic analysts to meet mission requirements for incident response and threathunting engagements.
  • Maintain accurate documentation of incident response activities and findings.
  • Prepare and deliver incident reports to management and stakeholders.
  • Work effectively in a team environment and contribute to mission success.
  • Stay current on cybersecurity trends to enhance hunt and response operations.
  • Demonstrate strong attention to detail, critical thinking, and customerservice orientation.
  • Selfteach and test new tools, methodologies, and techniques as needed.
  • Meet onsite requirements of at least one day per week (up to three days depending on mission needs).
  • Travel up to 40%.

Qualifications

Required Qualifications:

  • Bachelor's degree and 5 years of relevant experience; Master's degree and 3 years. An additional 4 years of relevant experience will be considered in lieu of a degree.
  • Must have 1-2 years of relevant Threat Hunting or DFIR experience directly supporting Critical Infrastructure (CI) / ICS environments.
  • Experience conducting security site assessments, including analysis of network security architecture, baseline ports/protocols/services, and asset characterization.
  • Experience using SIEM tools for pattern identification, anomaly detection, and trend analysis.
  • Experience analyzing ICS network protocols such as ModBus, ENIP/CIP, BACnet, DNP3, etc.
  • Experience with common opensource and commercial tools used in event analysis, incident response, forensics, malware analysis, or security operations.
  • Experience with hostbased and networkbased collection and detection tools (OSS/COTS).
  • U.S. citizenship required.
  • Active Top Secret security clearance.
    • Ability to obtain a TS/SCI for continued employment.
    • Ability to obtain and maintain a favorably adjudicated DHS background investigation.

Desired Qualifications:

  • Certifications such as GISCP, GCFA, GNFA, GRID, or OT sensor certifications.
  • 2+ years of Threat Hunting or DFIR experience.
  • Experience on DoD Cyber Protection Teams.
  • Experience performing digital forensics on laptops/desktops, PLCs, HMIs, Historians, and SCADA systems.
  • Experience with SIEM platforms (e.g., Splunk) including threat hunting, analytic development, dashboards, and reporting.
  • Familiarity with criticalinfrastructure frameworks (NIST, IEC 62443).
  • Ability to automate repeatable tasks.
  • Scripting experience in Python, Bash, PowerShell, and/or JavaScript.
Peraton Overview

Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world's leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees do the can't be done by solving the most daunting challenges facing our customers. Visit peraton.com to learn how we're keeping people around the world safe and secure.

Target Salary Range

$104,000 - $166,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual's experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.

EEO

EEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.
Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Cyber Incident Response Analyst with OT/ICS/SCADA / Travel & Active TS in Arlington, VA vacancy
  • $110k - $135k

     ...Title Analyst Location...  ...Travel Up to...  ...clearance (active clearance...  ...sector, with particular...  ...technology (OT), implementing...  .... Key Responsibilities:...  ...vulnerabilities, and incidents impacting...  ..., and SCADA...  ...systems (ICS) or SCADA...  ...mitigate cyber threats to... 
    Travel
    Cyber
    Full time
    Currently hiring
    Local area
    Remote work

    BCS Allegient

    Washington DC
    13 hours ago
  • $60 per hour

     ...for a Part-Time Tier 2 Incident Response Analyst (IR) to support a law...  ...potential cyber threats. As a SOC team...  ...evidence of adversarial activity Perform in-depth analysis...  ...impact Collaborate with cyber threat hunting and...  ...performance Clearance: ~ TS/SCI Clearance required... 
    Cyber
    Part time
    Remote work
    Worldwide
    Shift work
    Night shift
    Weekend work
    Day shift

    Tyto Athene, LLC

    Washington DC
    3 days ago
  • $164.38k - $189.75k

     ...Job Family: Cyber and IT Risk...  ...related mission activities remain protected...  ...risks associated with critical systems...  ...Clearance: Active TS/SCI w/ polygraph...  ...support a 72-hour response timeline for...  ...Intelligence Community (IC). GDIT IS...  ...: 40 Travel Required: Less... 
    Travel
    Cyber
    Temporary work
    Immediate start
    Remote work
    Worldwide
    Flexible hours

    General Dynamics Information Technology

    Washington DC
    1 day ago
  • $147.29k - $199.28k

     ...TECH REFRESH DATA ANALYST YOUR IMPACT...  ...secure, and aligned with mission needs. KEY RESPONSIBILITIES: Collect,...  ...CLEARANCE: Active TS/SCI clearance with...  ...Familiarity with DoW/IC environments and...  ...and business travel and accident insurance...  ..., AI/ML, Cloud, Cyber and application... 
    Travel
    Cyber
    Temporary work
    Immediate start
    Worldwide
    Flexible hours

    General Dynamics Information Technology

    Washington DC
    13 hours ago
  •  ...Incident Response Expert III (Cyber Eviction Analysts) Location: Washington Dc Metro Area (On-Site...  ...: US only Clearance: Active TS/SCI (DHS EOD Suitability...  ...combine technical precision with operational agility-...  ...expertise Must be able to travel domestically on short... 
    Travel
    Cyber
    Local area
    Immediate start

    ARGO Cyber Systems

    Arlington, VA
    4 days ago
  •  ...the DHS Hunt and Incident Response Team (HIRT). We act...  ...Summary As a  Cyber Eviction Analyst (SME) , you will...  ...malicious activity. This role requires...  ...hunt activities with only broad direction...  ...Clearance: Active TS/SCI Clearance (Mandatory...  ...audiences. Travel: Ability to... 
    Travel
    Cyber

    Solutions Technology, Inc / STI Health & Wellness

    Arlington, VA
    4 days ago
  •  ...Incident Response Expert / Cyber Eviction Analyst Location: Arlington, VA Must have an active Top Secret Security Clearance Node...  ...development services with next-generation...  ...citizen with an active TS/SCI clearance and...  ...suitability ~ Ability to travel domestically on... 
    Travel
    Cyber

    Node.Digital

    Arlington, VA
    6 days ago
  •  ...full-spectrum cyber, data operations...  ...DHS's Hunt and Incident Response Team (HIRT) secures...  ...cyber activity. Nightwing provides...  ..., and research with only broad direction...  ...have an active TS/SCI clearance...  ...be able to travel domestically on...  ...IASAE II, CSSP Analyst - DoD 8... 
    Travel
    Cyber
    Immediate start

    Nightwing

    Arlington, VA
    1 day ago
  •  ...Description RiVidium is seeking an Incident Response Analyst to support our planned MODES III...  ...Responsibilities Support cyber incident response activities including analysis, documentation, and coordination. Assist with triage, investigation support,... 
    Cyber
    Full time
    Contract work
    Part time
    Shift work
    Night shift

    Rividium Inc

    Alexandria, VA
    3 days ago
  •  ...seeking Senior SOC Analysts to work with a federal agency for...  ...candidate will have an active Top Secret Clearance...  .... Position Responsibilities: The Analyst...  ...ensure that all incidents are correct in review...  ...to work with other cyber security technology... 
    Cyber
    Immediate start
    Monday to Friday
    Shift work

    Macpower Digital Assets Edge

    Washington DC
    13 hours ago
  • $104k - $166k

     ...Cyber Threat Analyst - GTA / Active TS Job Locations US-VA-Arlington...  ...Top Secret/SCI Responsibilities Peraton is...  ...technical expertise with analytical writing...  ...network defense, and incident response. Demonstrated...  ...community (IC) role. Peraton... 
    Cyber
    Full time
    Contract work
    Overseas
    Shift work

    Peraton

    Arlington, VA
    1 day ago
  • $185k

     ...Management (SCRM) Analyst/Engineer...  ...-Time TRAVEL: Some...  ...CLEARANCE: Active Top Secret/...  ...analysis, cyber threat assessment...  ...Active DoD TS/SCI...  ...Experience working with cross-...  ...technology (OT), industrial...  ...control systems (ICS), or...  ...preferred. RESPONSIBILITIES... 
    Travel
    Cyber
    Full time
    Work at office

    ASTRION, INC.

    Arlington, VA
    13 hours ago
  • $127k - $140k

     ...to challenge yourself with work that matters, then...  ...organizations from ever-increasing cyber threats 24/7/365....  ...and automated response to cyber threats together...  ...Adversary Response, the Incident Response Analyst operates on the front lines of active cyber conflict—defending... 
    Cyber
    Permanent employment
    Work experience placement
    Work at office
    Remote work
    Work from home
    Home office
    Flexible hours

    Deepwatch

    Washington DC
    3 days ago
  • $131.3k - $237.35k

     ...has a critical need for a Senior Incident Response Analyst to support the DHS CISA Program....  ...analyze, mitigate, and respond to cyber threats and adversarial activity on the DHS Enterprise. The DHS SOC...  ...scope of Incidents • Expertise with Cyber Kill Chain and have... 
    Cyber
    Local area
    Immediate start
    Remote work
    Flexible hours

    Leidos

    Arlington, VA
    13 hours ago
  •  ...Cyber Incident Responder Detect-Response performs all procedures necessary to ensure the safety...  ...anomalies in accordance with computer network...  ...Security Clearance: ~ Active TS/SCI and the willingness to...  ...polygraph, if needed IC-CAP provides equal employment... 
    Cyber
    Shift work

    IC-CAP, LLC

    Washington DC
    1 day ago
  • $227k

     ...requires an active Top Secret/SCI clearance with ability to obtain...  ...This role is responsible for securing...  ...an active TS/SCI clearance...  ...architectures in DoD or IC environments....  ...analysis, incident response, or...  ...Family IT, Cyber Security,...  ...Salary Travel Required No... 
    Travel
    Cyber
    Local area
    Remote work
    Flexible hours

    Koniag Government Services

    Washington DC
    2 days ago
  • $227k

     ...requires an active Top Secret/SCI clearance with ability to obtain...  ...will be responsible for predictive...  ...maintain an active TS/SCI clearance...  ...network incidents. Ensure wireless...  ...in DoD or IC environments....  ...Family IT, Cyber Security,...  ...Type Salary Travel Required No... 
    Travel
    Cyber
    Local area
    Flexible hours

    Koniag Government Services

    Washington DC
    3 days ago
  • $128.04k - $173.23k

     ...Operations Skills: Active Directory Domain...  .... KEY RESPONSIBILITIES: Administer and...  ...upgrades in alignment with operational and security...  ...: Active TS/SCI clearance with...  ...illness and business travel and accident...  ...modernization, AI/ML, Cloud, Cyber and application... 
    Travel
    Cyber
    Temporary work
    Immediate start
    Worldwide
    Flexible hours

    General Dynamics Information Technology

    Washington DC
    13 hours ago
  • $210k

     ...requires an active Top Secret/SCI clearance with ability to obtain...  ...an active TS/SCI clearance. Key Responsibilities: Design, implement...  ...and security incident response...  ...: 521 - Cyber Defense Infrastructure...  ...in DoD or IC environments....  ...Salary Travel Required No... 
    Travel
    Cyber
    Local area
    Flexible hours

    Koniag Government Services

    Washington DC
    2 days ago
  • A cybersecurity firm is looking for a Tier 2 Incident Response Analyst to support law enforcement in Washington, DC. You will monitor security tools, triage alerts, and investigate cyber threats. Ideal candidates have six years in cybersecurity, preferably three in SOC... 
    Cyber

    Tyto Athene, LLC

    Washington DC
    2 days ago
  • $100.2k - $164.1k

     ...Senior Incident Response Consultant 133254 This role...  ...sets, and proven cyber...  ...SpearTip partners with our clients to protect...  ...extend up to 20% travel. As a Senior Incident...  ...connecting to contain active threats, preserve...  ...junior consultants and analysts, providing technical... 
    Travel
    Cyber
    Full time
    Temporary work
    Apprenticeship
    Local area
    Remote work
    Visa sponsorship
    Flexible hours

    Zurich NA

    Washington DC
    5 days ago
  • $100k - $126.5k

     ...Associate/Cybersecurity & Incident Response CRA's Forensic...  ...motivated candidates with 3-5 years of experience...  ...efforts; Track adversary activity second-by-second on a...  ...on the adequacy of cyber security controls in...  ...international business travelers. Work Location Flexibility... 
    Travel
    Cyber
    Work at office
    Work from home
    3 days per week

    Charles River Associates

    Washington DC
    2 days ago
  • $130k - $152.5k

     .../Cybersecurity & Incident Response (Forensic Services...  ...relationships with local, state and...  ...the adequacy of cyber security controls...  ...network forensic analyst or malware analyst...  ...firm development activities. We offer a comprehensive...  ...business travelers. Work Location... 
    Travel
    Cyber
    Work at office
    Local area
    Work from home
    3 days per week

    Charles River Associates

    Washington DC
    2 days ago
  •  ...cybersecurity consulting firm is seeking an Incident Response Analyst to support incident management for...  ..., and close coordination with federal cybersecurity teams. Ideal candidates...  ...duties in the Washington, D.C. area. #J-18808-Ljbffr Cyber Synergy Consulting Group
    Cyber
    Remote job

    Cyber Synergy Consulting Group

    Washington DC
    2 days ago
  •  ...The Incident Response Coordinator supports the end-to-end response...  ...point for incident response activities, ensuring alignment with established incident...  ...incidents; engage infra/app/cyber/vendor dependencies. Communications...  ...to 50 pounds" or "some travel" required.) Reasonable... 
    Travel
    Cyber
    Contract work
    Work experience placement
    Work at office
    Shift work

    ASM Research, An Accenture Federal Services Company

    Washington DC
    2 days ago
  •  ...cybersecurity firm in Washington is seeking a SOC Analyst to support 24/7 Cyber Watch operations. The ideal candidate must possess an active Top-Secret clearance along with a bachelor's degree and DOD IAT II certification. Responsibilities include evaluating cyber events,... 
    Cyber

    ClearFocus Technologies

    Washington DC
    13 hours ago
  • $83.5k - $87.5k

     ...Overview The Cyber Incident Response Analyst role is pivotal in reinforcing the client...  .... This position aligns with Cayuse's core values of Innovation...  .... ~Maintain active oversight of shared mailboxes...  ...related experience. ~Some travel may be required to... 
    Travel
    Cyber
    Temporary work
    Work at office
    Local area
    Flexible hours
    Shift work

    Navstar

    Washington DC
    1 day ago
  •  ...The Incident Response Coordinator, Senior leads tactical coordination of...  ...Incident Manager, integrates with cyber defenders when needed, and champions...  ...business stakeholders. ~ Active SECRET clearance or ability...  ...up to 50 pounds" or "some travel" required.) Reasonable... 
    Travel
    Cyber
    Contract work
    Work experience placement
    Work at office
    Shift work

    ASM Research, An Accenture Federal Services Company

    Washington DC
    13 hours ago
  • $120k - $132k

     ...Dulles, Virginia with operations...  ...a Threat Analyst to support the...  ...Security Cyber Mission (DSCM...  ...be able to travel up to two weeks...  .... Responsibilities: Be a key...  ...threat actor activity. Perform...  ...Community (IC). Acts as...  ...during cyber incidents; this may include... 
    Travel
    Cyber
    Contract work
    Remote work

    SkyePoint Decisions

    Arlington, VA
    13 hours ago
  •  ...support Government activities in Annapolis...  ...Collaborating with the Gov Technical...  ...Recovery Some travel required. Benefits...  ...Intelligence Community (IC) providing...  ...Software Development, Cyber and Network Security...  ...committed to their responsible and ethical use.... 
    Travel
    Cyber
    Temporary work
    Relocation package

    Enssolutions

    Washington DC
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Cyber Incident Response Analyst with OT/ICS/SCADA / Travel & Active TS. Be the first to apply!