Senior Forensic and Malware Analyst Top Secret/SCI w/Poly with Security Clearance
Quick Overview
Job Description
About Peraton Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world's leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace.
The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees solve the most daunting challenges that our customers face. Visit peraton.com to learn how we're keeping people around the world safe and secure. About The Role Peraton seeks a Senior Forensic and Malware Analyst to support ARCYBER G3.
Location: Fort Gordon, GA. Tasks include
- Update FMA portions of SOPs, TTPs, CSSP, and website information
- Coordinate with internal and external mission partners and intelligence professionals to contextualize malware findings within broader adversary TTPs and campaign activity
- Conduct malware analysis/reverse engineering of compiled executable code and non-compiled malicious content in order to characterize and understand its functions and capabilities
- Perform reverse-engineering on executable code
- Analyze and deobfuscate scripts, encoded commands, macros, and other non-compiled malicious content (e.g., PowerShell, VBScript, batch files, Office macros) to determine intent and functionality
- Develop and maintain malware detection signatures (e.g., YARA rules) based on analytic findings to support detection engineering and threat hunting activities
- Develop and maintain malware analysis artifacts, case notes, and all case-related data; produce written reports of findings and deliver regular operational briefings (daily/weekly/monthly) to leadership and mission partners
- Conduct and assist in executing digital media forensics
- Perform dead-box (static) forensic analysis and live (dynamic) forensic/incident handling analysis
- Use static, dynamic, and hybrid analysis techniques to detect and identify anomalous and/or malicious activity/software
- Collect, preserve, and transfer forensic evidence of intrusions to on-premises Information System(s) (IS)
- Analyze images, suspicious/malicious files, intrusion-related artifacts, entry points/vectors
- Perform network forensic analysis including inspection of packet captures (PCAPs) for malicious indicators, protocol anomalies, C2 communications, and other intrusion artifacts
- Conduct mobile device forensic examinations utilizing the Mobile device forensics lab
- Leverage mobile forensics lab tools and capabilities to acquire, examine, and analyze data from mobile devices in support of forensic investigations
- Minimum of 12 years with BS/BA; Minimum of 10 years with MS/MA; Minimum of 7 years with a PhD. Will consider HS with 16 years of relevant experience or Associates degree with 14 years of experience
- Must have an IA certification upon start: CCNA-Security, CCNA-Cybersecurity, CySA+, GICSP, GSEC, Security+, CND, or SSCP
- Able to support surge operations if mission requires
- Experience with scripting languages (e.g., PowerShell, BASH, Python, etc.) for automating analysis tasks, parsing artifacts, or developing tooling in support of malware or forensic workflows
- Able to examine suspicious or malicious software-using static, dynamic, and hybrid techniques
- Experienced in conducting analysis of malicious software to determine what it does, how it works, and how to detect, contain, and remove it
- Experience with dead-box (static) forensic analysis and live (dynamic) forensic/incident handling analysis
- Able to perform reverse-engineering on executable code and analysis of non-compiled malicious content such as scripts, encoded commands, macros, and obfuscated files
- Experience with DOD standards of reporting
- Skilled in inspecting packet captures (PCAPs) for domains, URI paths, protocols, User Agent strings, TLS metadata, and other artifacts that may indicate compromise
- US Citizenship is required
- Active TS with ability to obtain/maintain SCI and PolygraphPreferred Qualifications:
- Active, or previously held, GIAC Certified Forensic Analyst (GCFA) certification
Benefits Statement: Peraton offers eligible employees a variety of benefits including medical, dental, vision, life, health savings account, short/long term disability, EAP, parental leave, 401(k), paid time off (PTO) for vacation, and company paid holidays. A full listing of available benefits can be viewed at https://www.careers.peraton.com/benefits.
Application Statements: The application period for the job is estimated to be 30 days from the job posting date. However, this timeline may be shortened or extended depending on business needs and the availability of qualified candidates. By applying to this job, you are expressing interest in the role and the Company. During the review of your application, you may be required to participate in an on-camera interview, as well as participate in a process to verify your identity. Use of artificial intelligence (AI) tools of any kind during Peraton interviews is strictly prohibited unless the candidate has obtained prior written authorization. All interview responses must be the candidate's own.
EEO:Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.
Similar jobs
- PN
Assistant Head Teller
NewPeoples National Bank
Marion, Illinois🇺🇸$18 - $21/hrOn-site25 minutes agoAdministrative - AD
Security Engineering Lead with Security Clearance
NewAgile Defense, LLC
Reston, VA🇺🇸$165k - $201k/yrHybrid21 hours agoAgileAdministrative - MA
Journeyman Field Office Technician with Security Clearance
NewMANTECH
Albuquerque, NM🇺🇸On-site21 hours agoAgileAdministrative - SE
Quality Control Specialist - (Hybrid with 50% travel) with Security Clearance
NewSerco Inc.
Norfolk, VA🇺🇸Hybrid21 hours agoAdministrative - AM
Network Development Engineer, ADC Networking with Security Clearance
NewAmazon
Bellevue, WA🇺🇸Hybrid21 hours agoAgileAdministrative - RM
Defense Red Switch Network (DRSN) Support Technician III with Security Clearance
NewRMantras
Scott Air Force Base, IL🇺🇸Hybrid21 hours agoAdministrative