
location_on904, McDaniel Court, Herndon, Fairfax County, Virginia, 20170, United States
Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world's leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. We operate at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. Our employees serve as valued partners to essential government agencies and support every branch of the U.S. armed forces, solving the most daunting challenges our customers face every day.
We are seeking a highly skilled and innovative Correlation Engineer to join our team in the greater DMV area, specifically supporting the Army National Guard. In this role, you will be the architect behind the security narratives that protect our critical infrastructure. Your work will bridge the gap between raw telemetry and actionable intelligence, transforming complex data streams into clear stories of threat activity.
You will partner with SOC analysts, threat hunters, and data engineers to refine the logic that detects multi-stage campaigns, lateral movement, and stealthy insider behaviors. Your day-to-day involves designing and tuning correlation rules for enterprise SIEM platforms, ensuring that detection coverage is balanced against analyst workload. You will lead post-incident analysis to derive new detection use cases and drive continuous improvement through measurable metrics like precision, recall, and mean time to detect (MTTD). Beyond technical development, you will mentor SOC staff on investigative workflows and collaborate across teams to ensure data quality and scalable analytics.
The application period for this role is estimated to be 30 days from the posting date, though this timeline may be adjusted based on business needs and candidate availability. By applying, you express interest in the role and the Company. During the review process, selected candidates may be required to participate in an on-camera interview and a process to verify their identity.
Peraton is an equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.
Work model: On-site
904, McDaniel Court, Herndon, Fairfax County, Virginia, 20170, United States
Skills: Cybersecurity Analytics, Detection Engineering, Soc Content Development, Correlation Rule Development, Enterprise Siems, Log Formats, Telemetry Sources, Normalization, Mapping, Analytic Pipelines.
Education: Master's degree in specified fields OR equivalent DoD training or certification; PhD in specified fields OR equivalent DoD training or certification.
Herndon, Virginia
Prior DoD/enterprise SOC detection engineering experience and familiarity with MITRE ATT&CK mapping for correlation use cases. Experience with multiple SIEM platforms and analytics toolchains (Splunk, Elastic, QRadar, Sumo Logic, Microsoft Sentinel). Background in threat hunting, adversary emulation, or purple-team activities to validate and stress-test correlation content.
Recrutus helps candidates discover roles that match their skills and helps teams reach qualified applicants faster. Browse by metro, discipline, or work style — from internships to senior leadership.