Cyber Threat Detection Engineer: Splunk, SIEM & SOAR Expert

Peraton

Tampa (FL)

On-site

USD 110,000 - 170,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Peraton is seeking a Cyber Threat Detection Engineer for the SITEC-3 EOM task at MacDill AFB, Florida. You will design and tune detections in Splunk ES and Microsoft Sentinel, map coverage to MITRE ATT&CK, and collaborate on SOAR playbooks to reduce MTTR. You will manage detections as code and maintain thorough runbooks.

The role demands hands-on threat detection experience, SIEM expertise, and the ability to communicate findings to diverse stakeholders within a DoD enterprise environment.

Qualifications

  • Min 12 years with HS degree, 10 years with AS/AA degree, 8 years with BS/BA, 6 years with MS/MA, 3 years with PhD
  • Must be DoW 8140 compliant under Work Role Code 531– Cyber Defense Incident Responder - Intermediate level or higher
  • DoD 8570 IAT II Certification

Responsibilities

  • Design, build, test, and tune complex correlation searches, behavioral analytics, and threat detections within Splunk ES and Microsoft Sentinel with KQL
  • Map and continuously evaluate enterprise detection coverage against the MITRE ATT&CK framework to identify, prioritize, and remediate visibility and detection blind spots
  • Collaborate with automation teams to design, test, and optimize automated SOAR playbooks that trigger on SIEM detections to enrich alerts, execute automated containment actions, and reduce Mean Time to Respond (MTTR)
  • Engineer and maintain bi-directional integrations between Splunk, Sentinel and SOAR platforms to ensure seamless alert handoffs, context ingestion, and closed-loop feedback for continuous alert tuning
  • Conduct regular false-positive analysis and threshold tuning across all active detection rules to eliminate alert fatigue for frontline SOC analysts
  • Analyze cyber threat intelligence (CTI) reports, Indicators of Compromise (IOCs), and zero-day vulnerabilities to rapidly author high-priority detection signatures
  • Maintain comprehensive detection documentation, including alert logic explanations, investigative runbooks, and triage guidance
  • Manage detection logic as code within Git repositories utilizing CI/CD pipelines to review, test, version, and deploy detection content into production environments

Skills

Strong analytical and problem-solving
Clear communication with stakeholders

Education

DoD 8570 IAT II Certification
DoW TS/SCI clearance
DoW 8140 compliant – Work Role Code 531

Tools

Splunk
Microsoft Sentinel

Job description

Peraton is seeking a Cyber Threat Detection Engineer for the SITEC-3 EOM task at MacDill AFB, Florida. You will design and tune detections in Splunk ES and Microsoft Sentinel, map coverage to MITRE ATT&CK, and collaborate on SOAR playbooks to reduce MTTR. You will manage detections as code and maintain thorough runbooks.

The role demands hands-on threat detection experience, SIEM expertise, and the ability to communicate findings to diverse stakeholders within a DoD enterprise environment.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cyber Threat Detection Engineer (Splunk/SOAR)
Senior Cyber Threat Detection Engineer (Splunk/SOAR)

Peraton • Town of Florida (NY), Northern (KY)

Hybrid
USD 80,000 - 128,000
SITEC - Cyber Threat Detection Engineer - MacDill AFB
SITEC - Cyber Threat Detection Engineer - MacDill AFB

Peraton • Tampa (FL)

On-site
USD 110,000 - 170,000
Threat Detection Engineer — Splunk SIEM & MITRE ATT&CK
Threat Detection Engineer — Splunk SIEM & MITRE ATT&CK

Peraton • Beltsville (MD)

On-site
USD 80,000 - 128,000
External Job Posting Title SITEC - Cyber Threat Detection Engineer - MacDill AFB
External Job Posting Title SITEC - Cyber Threat Detection Engineer - MacDill AFB

Peraton • Town of Florida (NY), Northern (KY)

Hybrid
USD 80,000 - 128,000
Network Defense Engineer - Threat Detection & Telemetry
Network Defense Engineer - Threat Detection & Telemetry

Peraton • Tampa (FL)

On-site
USD 80,000 - 128,000
Threat Detection Analyst — Splunk ES & MITRE Expert
Threat Detection Analyst — Splunk ES & MITRE Expert

Peraton • Beltsville (MD)

On-site
USD 80,000 - 128,000
Network Defense Engineer – Telemetry & Threat Detection
Network Defense Engineer – Telemetry & Threat Detection

Peraton • United States

On-site
USD 80,000 - 128,000
SOAR Automation Engineer for Enterprise Cyber Defense
SOAR Automation Engineer for Enterprise Cyber Defense

Peraton • Tampa (FL)

On-site
USD 104,000 - 166,000
Intelligence-Led Cyber Threat Hunter
Intelligence-Led Cyber Threat Hunter

Peraton • Tampa (FL)

On-site
USD 80,000 - 128,000
Senior Splunk UEBA Engineer (DoD/TS-SCI)
Senior Splunk UEBA Engineer (DoD/TS-SCI)

Peraton • United States

On-site
USD 86,000 - 138,000