Cyber Incident Response Analyst with OT/ICS/SCADA / Travel & Active TS
$104,000–$166,000 year
On-siteArlington, Virginia, United States
Job Summary
Respond to cybersecurity incidents across ICS, OT, and IT environments, applying functional knowledge to resolve problems of moderate scope and complexity. Conduct proactive threat hunts, collaborate with forensic analysts, and maintain accurate documentation of response activities. Prepare incident reports for stakeholders and help define response procedures for industrial control system environments while adhering to established escalation protocols. Provide sector-specific expertise for critical infrastructure areas including Water, Power, Manufacturing, and Transportation. This role requires on-site presence in Arlington, VA, with approximately 40% travel. Candidates must possess an Active Top Secret clearance and ability to obtain TS/SCI. Peraton supports federal strategic cyber programs for national-level systems across critical infrastructure sectors.
Required Qualifications
- Bachelor's degree
- 5 years of relevant experience
- Master's degree
- 3 years of experience with a Master's degree
- 4 years of relevant experience in lieu of a degree
- 1–2 years of relevant Threat Hunting or DFIR experience directly supporting Critical Infrastructure (CI) / ICS environments
- Experience conducting security site assessments, including analysis of network security architecture, baseline ports/protocols/services, and asset characterization
- Experience using SIEM tools for pattern identification, anomaly detection, and trend analysis
- Experience analyzing ICS network protocols such as ModBus, ENIP/CIP, BACnet, DNP3, etc.
- Experience with common open-source and commercial tools used in event analysis, incident response, forensics, malware analysis, or security operations
- Experience with host-based and network-based collection and detection tools (OSS/COTS)
- U.S. citizenship
- Active Top Secret security clearance
- Ability to obtain a TS/SCI for continued employment
- Ability to obtain and maintain a favorably adjudicated DHS background investigation
- Meet on-site requirements of at least one day per week (up to three days depending on mission needs)
- Travel up to 40%
Desired Qualifications
- Certifications such as GISCP, GCFA, GNFA, GRID, or OT sensor certifications
- 2+ years of Threat Hunting or DFIR experience
- Experience on DoD Cyber Protection Teams
- Experience performing digital forensics on laptops/desktops, PLCs, HMIs, Historians, and SCADA systems
- Experience with SIEM platforms (e.g., Splunk) including threat hunting, analytic development, dashboards, and reporting
- Familiarity with critical-infrastructure frameworks (NIST, IEC 62443)
- Ability to automate repeatable tasks
- Scripting experience in Python, Bash, PowerShell, and/or JavaScript
Additional Requirements
- U.S. citizenship required.
- Active Top Secret security clearance.
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.