SITEC - Splunk (UEBA) Engineer - MacDill AFB

Peraton

United States

On-site

USD 86,000 - 138,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Peraton is seeking a Splunk Engineer to design, administer, and optimize an enterprise Splunk environment with a focus on User and Entity Behavior Analytics (UEBA). The role supports SITEC 3 EOM at MacDill AFB, FL, working with SOC teams to detect anomalies and protect critical networks.

The engineer will use UEBA, CIM, and ML models to identify insider threats and account compromise, ensuring data is modeled and actionable for security operations. Strong collaboration across teams is required.

Qualifications

  • Must have DoD 8570 IAT II Certification.
  • DoD TS/SCI clearance required.
  • Minimum education aligned with DoD standards per position.

Responsibilities

  • Lead the design, engineering and deployment of Splunk User Behavior Analytics (UBA).
  • Ingest identity-centric data sources (Active Directory, VPN, Cloud, HR systems).
  • Develop machine learning models to baseline normal user behavior.
  • Collaborate with Insider Threat and SOC teams to identify anomalies.
  • Perform data normalization using Splunk CIM for UEBA.
  • Integrate UEBA anomalies into Splunk Enterprise Security dashboards and SOAR playbooks.
  • Monitor UEBA health and troubleshoot performance.

Skills

IAT II Certification
DoD TS/SCI clearance
Python
Bash

Education

High school diploma
AS/AA degree
BS/BA degree
MS/MA degree
PhD

Tools

Python
Splunk
Splunk CIM

Job description

Responsibilities

Peraton requires Splunk Engineers to support the Special Operation Command Information Technology Enterprise Contract (SITEC) - 3 EOM. This position is located at MacDill AFB in Florida.

The purpose of the Special Operations Forces Information Technology Enterprise Contract (SITEC) 3 Enterprise Operations and Maintenance (EOM) Task Order (TO) is to provide USSOCOM, its Component Commands, its Theater Special Operations Commands (TSOCs), and its deployed forces with Operations and Maintenance (O&M) services to maintain Network Operations (NetOps); maintain systems and network infrastructure; provide end user and common device support; provide configuration, change, license, and asset management; conduct training, and perform Install, Move, Add, Change (IMACs) services. The responsibilities and tasks associated with each requirement play a pivotal role to USSOCOM, the CIO/J6 organization, and ultimately the end-user who operate around the globe 24x7x365.

The Splunk Engineer will serve as a technical expert responsible for the design, administration, and optimization of the enterprise Splunk environment, with a specialized and heavy focus on User and Entity Behavior Analytics (UEBA). The engineer will bridge the gap between core log management and advanced behavioral analytics by leveraging Splunk User Behavior Analytics (UBA) and machine learning models to detect compromised accounts, insider threats, and lateral movement. This position ensures that high-fidelity behavioral telemetry is integrated, baselined, and actionable for the Security Operations Center (SOC).

  • Lead the design, engineering and deployment of Splunk User Behavior Analytics (UBA), focusing on the ingestion of identity-centric data sources (e.g., Active Directory, VPN, Cloud Access Security Brokers, and HR systems).
  • Develop, tune, and optimize machine learning models and behavioral algorithms to establish accurate baselines for "normal" user and entity behavior.
  • Collaborate with the Insider Threat and SOC teams to identify anomalous activity, such as credential misuse, unusual data movement, and account takeover (ATO) scenarios.
  • Perform advanced data normalization and tagging using the Splunk Common Information Model (CIM) to ensure behavioral data is properly structured for the UEBA engine.
  • Integrate UEBA-generated anomalies and threats into the Splunk Enterprise Security Incident Review dashboard and Security Orchestration, Automation, and Response (SOAR) playbooks.
  • Monitor UEBA system health, including data ingestion rates, model processing times, and platform stability, performing rapid troubleshooting as required.
  • Document technical configurations, threat modeling logic, and behavioral detection playbooks for the engineering and analyst teams.
Qualifications
Required Qualifications:
  • Min 12 years with HS degree, 10 years with AS/AA degree, 8 years with BS/BA, 6 years with MS/MA, 3 years with PhD
  • DoD 8570 IAT II Certification
  • DoD TS/SCI clearance
Desired Qualifications:
  • Must be DoW 8140 compliant under the Work Role Code 451 - System Administrator - Intermediate level or higher by 1 Oct 26.
  • Previous experience operating within Department of War (DoW) or DoD enterprise network environments.
  • Active Splunk Enterprise Security Certified Admin or Splunk Certified Developer certifications.
  • Experience using Python or Bash for automation of Splunk administrative tasks and API integrations.
  • Knowledge of the MITRE ATT&CK framework and mapping behavioral anomalies to specific adversary tactics and techniques.
Peraton Overview

Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world's leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees do the can't be done by solving the most daunting challenges facing our customers. Visit peraton.com to learn how we're keeping people around the world safe and secure.

Target Salary Range

$86,000 - $138,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual's experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.

EEO

EEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.

All

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SITEC - Splunk Data Engineer - MacDill AFB
SITEC - Splunk Data Engineer - MacDill AFB

Peraton • United States

On-site
USD 104,000 - 166,000
SITEC - Splunk Data Engineer - MacDill AFB
SITEC - Splunk Data Engineer - MacDill AFB

Peraton • Tampa (FL)

On-site
USD 104,000 - 166,000
Overtime
Shift differential
Discretionary bonuses
External Job Posting Title SITEC - Cyber Threat Detection Engineer - MacDill AFB
External Job Posting Title SITEC - Cyber Threat Detection Engineer - MacDill AFB

Peraton • Town of Florida (NY), Northern (KY)

Hybrid
USD 80,000 - 128,000
SITEC - SPLUNK SOAR Automation Engineer - MacDill AFB
SITEC - SPLUNK SOAR Automation Engineer - MacDill AFB

Peraton • Tampa (FL)

On-site
USD 104,000 - 166,000
SITEC - Data Engineer - Camp H.M. Smith, HI
SITEC - Data Engineer - Camp H.M. Smith, HI

Peraton • United States

On-site
USD 112,000 - 179,000
External Job Posting Title SITEC - SPLUNK SOAR Automation Engineer - MacDill AFB
External Job Posting Title SITEC - SPLUNK SOAR Automation Engineer - MacDill AFB

Peraton • Town of Florida (NY), Northern (KY)

Hybrid
USD 104,000 - 166,000
SITEC - Segmentation Engineer - MacDill AFB
SITEC - Segmentation Engineer - MacDill AFB

Peraton • United States

On-site
USD 135,000 - 216,000
Systems Engineer - Splunk Administrator, Senior Advisor - TS/SCI w/poly
Systems Engineer - Splunk Administrator, Senior Advisor - TS/SCI w/poly

Peraton • United States

On-site
USD 176,000 - 282,000
PTO 280 hours
Health benefits
Annual bonus
SITEC - Network Security Administrator - MacDill AFB
SITEC - Network Security Administrator - MacDill AFB

Peraton • United States

On-site
USD 80,000 - 128,000
SITEC - SOC 1 Operations Lead
SITEC - SOC 1 Operations Lead

Peraton • Tampa (FL)

On-site
USD 80,000 - 128,000