Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.
Peraton is seeking a Cyber Threat Detection Engineer for the SITEC-3 EOM task at MacDill AFB, Florida. You will design and tune detections in Splunk ES and Microsoft Sentinel, map coverage to MITRE ATT&CK, and collaborate on SOAR playbooks to reduce MTTR. You will manage detections as code and maintain thorough runbooks.
The role demands hands-on threat detection experience, SIEM expertise, and the ability to communicate findings to diverse stakeholders within a DoD enterprise environment.
Peraton requires a Cyber Threat Detection Engineer to support the Special Operation Command Information Technology Enterprise Contract (SITEC) – 3 EOM. This position is located at MacDill AFB in Florida.
The purpose of the Special Operations Forces Information Technology Enterprise Contract (SITEC) 3 Enterprise Operations and Maintenance (EOM) Task Order (TO) is to provide USSOCOM, its Component Commands, its Theater Special Operations Commands (TSOCs), and its deployed forces with Operations and Maintenance (O&M) services to maintain Network Operations (NetOps); maintain systems and network infrastructure; provide end user and common device support; provide configuration, change, license, and asset management; conduct training, and perform Install, Move, Add, Change (IMACs) services. The responsibilities and tasks associated with each requirement play a pivotal role to USSOCOM, the CIO/J6 organization, and ultimately the end-user who operate around the globe 24x7x365.
TheCyber Threat Detection Engineerserves as the primary technical authority for designing, authoring, validating, and optimizing threat detection capabilities across enterprise cyber defense systems. Operating at the intersection of Threat Intelligence, Security Operations, and Security Engineering, this role is responsible for translating adversary tactics, techniques, and procedures (TTPs) into actionable, high-fidelity detection rules withinSplunk Enterprise Security (ES)and orchestrated response workflows within enterpriseSOARplatforms. The engineer ensures comprehensive visibility into enterprise telemetry, reduces alert fatigue for frontline SOC analysts by eliminating false positives, and adoptsDetection-as-Code (DaC)principles to continuously test, maintain, and mature the organization's defensive posture.