SITEC - Cyber Threat Detection Engineer - MacDill AFB

Peraton

Tampa (FL)

On-site

USD 110,000 - 170,000

Full time

2 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Peraton is seeking a Cyber Threat Detection Engineer for the SITEC-3 EOM task at MacDill AFB, Florida. You will design and tune detections in Splunk ES and Microsoft Sentinel, map coverage to MITRE ATT&CK, and collaborate on SOAR playbooks to reduce MTTR. You will manage detections as code and maintain thorough runbooks.

The role demands hands-on threat detection experience, SIEM expertise, and the ability to communicate findings to diverse stakeholders within a DoD enterprise environment.

Qualifications

  • Min 12 years with HS degree, 10 years with AS/AA degree, 8 years with BS/BA, 6 years with MS/MA, 3 years with PhD
  • Must be DoW 8140 compliant under Work Role Code 531– Cyber Defense Incident Responder - Intermediate level or higher
  • DoD 8570 IAT II Certification

Responsibilities

  • Design, build, test, and tune complex correlation searches, behavioral analytics, and threat detections within Splunk ES and Microsoft Sentinel with KQL
  • Map and continuously evaluate enterprise detection coverage against the MITRE ATT&CK framework to identify, prioritize, and remediate visibility and detection blind spots
  • Collaborate with automation teams to design, test, and optimize automated SOAR playbooks that trigger on SIEM detections to enrich alerts, execute automated containment actions, and reduce Mean Time to Respond (MTTR)
  • Engineer and maintain bi-directional integrations between Splunk, Sentinel and SOAR platforms to ensure seamless alert handoffs, context ingestion, and closed-loop feedback for continuous alert tuning
  • Conduct regular false-positive analysis and threshold tuning across all active detection rules to eliminate alert fatigue for frontline SOC analysts
  • Analyze cyber threat intelligence (CTI) reports, Indicators of Compromise (IOCs), and zero-day vulnerabilities to rapidly author high-priority detection signatures
  • Maintain comprehensive detection documentation, including alert logic explanations, investigative runbooks, and triage guidance
  • Manage detection logic as code within Git repositories utilizing CI/CD pipelines to review, test, version, and deploy detection content into production environments

Skills

Strong analytical and problem-solving
Clear communication with stakeholders

Education

DoD 8570 IAT II Certification
DoW TS/SCI clearance
DoW 8140 compliant – Work Role Code 531

Tools

Splunk
Microsoft Sentinel

Job description

Required Qualifications:
  • Min 12 years with HS degree, 10 years with AS/AA degree, 8 years with BS/BA, 6 years with MS/MA, 3 years with PhD
  • DoD 8570 IAT II Certification
  • DoW TS/SCI clearance
  • Must be DoW 8140 compliant under the Work Role Code 531– Cyber Defense Incident Responder - Intermediate level or higher
Desired Qualifications:
  • Strong analytical and problem-solving skills
  • Ability to communicate security issues clearly to both technical and non-technical stakeholders
  • Strong understanding of security technologies used to defend Enterprise networks such as EDR, XDR, IDS, IPS, SIEM and SOAR.
  • Hands-on experience using SIEM solutions such as Splunk and Microsoft Sentinel to create threat detections.

Peraton requires a Cyber Threat Detection Engineer to support the Special Operation Command Information Technology Enterprise Contract (SITEC) – 3 EOM. This position is located at MacDill AFB in Florida.

The purpose of the Special Operations Forces Information Technology Enterprise Contract (SITEC) 3 Enterprise Operations and Maintenance (EOM) Task Order (TO) is to provide USSOCOM, its Component Commands, its Theater Special Operations Commands (TSOCs), and its deployed forces with Operations and Maintenance (O&M) services to maintain Network Operations (NetOps); maintain systems and network infrastructure; provide end user and common device support; provide configuration, change, license, and asset management; conduct training, and perform Install, Move, Add, Change (IMACs) services. The responsibilities and tasks associated with each requirement play a pivotal role to USSOCOM, the CIO/J6 organization, and ultimately the end-user who operate around the globe 24x7x365.

TheCyber Threat Detection Engineerserves as the primary technical authority for designing, authoring, validating, and optimizing threat detection capabilities across enterprise cyber defense systems. Operating at the intersection of Threat Intelligence, Security Operations, and Security Engineering, this role is responsible for translating adversary tactics, techniques, and procedures (TTPs) into actionable, high-fidelity detection rules withinSplunk Enterprise Security (ES)and orchestrated response workflows within enterpriseSOARplatforms. The engineer ensures comprehensive visibility into enterprise telemetry, reduces alert fatigue for frontline SOC analysts by eliminating false positives, and adoptsDetection-as-Code (DaC)principles to continuously test, maintain, and mature the organization's defensive posture.

Duties:
  • Design, build, test, and tune complex correlation searches, behavioral analytics, and threat detections within Splunk Enterprise Security (ES) utilizing advanced Splunk Search Processing Language (SPL), and Microsoft Sentinel with Kusto Query Language (KQL).
  • Map and continuously evaluate enterprise detection coverage against the MITRE ATT&CK framework to identify, prioritize, and remediate visibility and detection blind spots across endpoint, cloud, and network environments.
  • Collaborate with automation teams to design, test, and optimize automated SOAR playbooks that trigger on SIEM detections to enrich alerts, execute automated containment actions, and reduce Mean Time to Respond (MTTR).
  • Engineer and maintain bi-directional integrations between Splunk, Sentinel and SOAR platforms to ensure seamless alert handoffs, context ingestion, and closed-loop feedback for continuous alert tuning.
  • Conduct regular false-positive analysis and threshold tuning across all active detection rules to eliminate alert fatigue for frontline Security Operations Center (SOC) analysts.
  • Analyze cyber threat intelligence (CTI) reports, Indicators of Compromise (IOCs), and zero-day vulnerabilities to rapidly author high-priority detection signatures.
  • Maintain comprehensive detection documentation, including alert logic explanations, investigative runbooks, and triage guidance.
  • Manage detection logic as code within version-controlled repositories (e.g., Git) utilizing CI/CD pipelines to review, test, version, and deploy detection content into production environments.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

External Job Posting Title SITEC - Cyber Threat Detection Engineer - MacDill AFB
External Job Posting Title SITEC - Cyber Threat Detection Engineer - MacDill AFB

Peraton • Town of Florida (NY), Northern (KY)

Hybrid
USD 80,000 - 128,000
Cyber Threat Detection Engineer: Splunk, SIEM & SOAR Expert
Cyber Threat Detection Engineer: Splunk, SIEM & SOAR Expert

Peraton • Tampa (FL)

On-site
USD 110,000 - 170,000
Senior Cyber Threat Detection Engineer (Splunk/SOAR)
Senior Cyber Threat Detection Engineer (Splunk/SOAR)

Peraton • Town of Florida (NY), Northern (KY)

Hybrid
USD 80,000 - 128,000
SITEC - Cyber Defense Incident Responder (SR)- Fort Bragg, NC
SITEC - Cyber Defense Incident Responder (SR)- Fort Bragg, NC

Peraton • North Carolina

Hybrid
USD 120,000 - 180,000
SITEC - Network Defense Engineer - MacDill AFB
SITEC - Network Defense Engineer - MacDill AFB

Peraton • United States

On-site
USD 80,000 - 128,000
SITEC - Network Defense Engineer - MacDill AFB
SITEC - Network Defense Engineer - MacDill AFB

Peraton • Tampa (FL)

On-site
USD 80,000 - 128,000
SITEC - Systems Engineer - MacDill AFB
SITEC - Systems Engineer - MacDill AFB

Peraton • Tampa (FL)

On-site
USD 110,000 - 150,000
SITEC - Network Security Administrator - MacDill AFB
SITEC - Network Security Administrator - MacDill AFB

Peraton • Tampa (FL)

On-site
USD 80,000 - 128,000
External Job Posting Title SITEC - SOC Manager - MacDill AFB
External Job Posting Title SITEC - SOC Manager - MacDill AFB

Peraton • Town of Florida (NY), Northern (KY)

Hybrid
USD 86,000 - 138,000
SITEC - Splunk (UEBA) Engineer - MacDill AFB
SITEC - Splunk (UEBA) Engineer - MacDill AFB

Peraton • United States

On-site
USD 86,000 - 138,000