Peraton logo
PeratonPosted 1 week ago

Senior Incident Response Analyst

$104,000–$166,000 year

RemoteUnited States

Full TimeSenior LevelBachelors DegreeEnterprise

Job Summary

Lead end-to-end incident response for Covered California and CalHEERS, managing triage, containment, eradication, recovery, and post-incident reviews while serving as backup incident manager. Own detection engineering, SIEM and SOAR content development, log onboarding, and MITRE ATT&CK-based threat hunting to ensure early detection and containment of PII, PHI, and federal tax data. Build and exercise response playbooks through tabletop drills, coordinate evidence handling and chain of custody, and meet strict contractual notification timelines. Report incident status to security leadership and support vulnerability management coordination.

Required Qualifications

  • Bachelor's degree in cybersecurity or computer science
  • 8+ years of cybersecurity experience with demonstrated hands-on incident response leadership
  • Active GCIH or GCIA certification
  • Hands-on experience with enterprise SIEM and SOAR platforms (for example Splunk or Microsoft Sentinel), including detection engineering, log source onboarding, and alert tuning
  • Demonstrated threat hunting experience using MITRE ATT&CK, plus malware triage and network and host forensics fundamentals
  • Demonstrated experience leading incidents as the incident lead or commander, including evidence handling, chain of custody, executive incident communication, and post-incident reporting
  • Working knowledge of NIST SP 800-61 incident handling practice within a NIST SP 800-53 Rev. 5 control context
  • Scripting ability for response and detection automation
  • US Citizenship
  • The ability to pass a California criminal background clearance (Gov. Code §1043 / 10 CCR §6456)

Desired Qualifications

  • GCFA certification
  • CISSP, GCED, or GNFA
  • Incident response experience in environments containing PII, PHI, and federal tax information
  • Experience in CMS-regulated environments or state health benefit exchange environments
  • Familiarity with ARC-AMPE and IRS Publication 1075 incident handling and reporting obligations
  • Experience in California state government or comparable public-sector environments
  • Experience coordinating with external forensic providers, law enforcement, and regulators during an incident
  • Experience building or maturing a detection engineering practice, including detection-as-code

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce