> Markdown version of [/jobs/ext/1368658-sitec-network-defense-engineer-macdill-afb](https://www.wearedevelopers.com/jobs/ext/1368658-sitec-network-defense-engineer-macdill-afb). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # SITEC - Network Defense Engineer - MacDill AFB - **Company:** Peraton Inc - **Location:** Tampa, FL, United States - **Salary:** $80,000.0 - $128,000.0 - **Contract:** Permanent contract - **Skills:** Adobe Analytics, IMac, Bash Shell, Big Data, Complex Networks, Computer Networks, Deep Packet Inspection, Domain Name System (DNS), Emulators, Hypertext Transfer Protocols (HTTP), Intrusion Detection and Prevention, Python (Programming Language), Network Security, NetFlow, Network Architecture, Network Forensics, Packet Analyzer, Network Protocols, Windows PowerShell, TCP/IP, Traffic Analysis, Wireshark, Snort (Software), Scripting, Transport Layer Security, Computer Network Operations, Cyber Threat Analysis, Information Technology, Cybercrime, Cyber Warfare - **Published:** July 21, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9042580/sitec-network-defense-engineer-macdill-afb ## About the Role * Min 12 years with HS degree, 10 years with AS/AA degree, 8 years with BS/BA, 6 years with MS/MA, 3 years with PhD * DoD 8570 IAT II Certification; AND * CCNA * DoD TS/SCI clearance, * Must be with DoW 8140 compliant under the Work Role Code 521- Cyber Defense Infrastructure Support Specialist - Intermediate level or higher by 1 Oct 26. * Deep Packet & Protocol Analysis: Mastery of network protocols (TCP/IP, DNS, HTTP, TLS/SSL, SMB) and advanced packet analysis tools (e.g., Wireshark, Tshark) to dissect malicious payloads and identify evasive command-and-control (C2) traffic. * Automation & Scripting: Proficiency in scripting languages (such as Python, PowerShell, or Bash) to automate the processing of network logs, parse large datasets, and integrate threat intelligence feeds. * Threat Hunting & Emulation: Ability to think like an adversary to proactively hunt for hidden threats within network metadata and reconstruct complex multi-stage attack paths. * Detection Engineering: Direct experience writing, testing, and deploying custom high-fidelity detection signatures using industry-standard formats (such as Snort, Suricata, Yara, Sigma, or Zeek scripts). ## Description Peraton requires a Network Defense Engineer to support the Special Operation Command Information Technology Enterprise Contract (SITEC) - 3 EOM. This position is located at MacDill AFB in Florida. The purpose of the Special Operations Forces Information Technology Enterprise Contract (SITEC) 3 Enterprise Operations and Maintenance (EOM) Task Order (TO) is to provide USSOCOM, its Component Commands, its Theater Special Operations Commands (TSOCs), and its deployed forces with Operations and Maintenance (O&M) services to maintain Network Operations (NetOps); maintain systems and network infrastructure; provide end user and common device support; provide configuration, change, license, and asset management; conduct training, and perform Install, Move, Add, Change (IMACs) services. The responsibilities and tasks associated with each requirement play a pivotal role to USSOCOM, the CIO/J6 organization, and ultimately the end-user who operate around the globe 24x7x365. The Network Defense Engineer is responsible for designing the organization's network threat detection and countermeasure capabilities. This role focuses on engineering sophisticated telemetry collection systems that provide total visibility into network traffic and adversary behaviors. As the definitive technical authority on network-based cyber events, the engineer translates complex threat intelligence and attack characterizations into actionable, enterprise-wide countermeasures. This position requires deep expertise in network protocols, traffic analysis, and defensive architecture to proactively shield critical mission networks from advanced persistent threats, passing validated mitigation designs to administrative teams for implementation. * Engineer Telemetry Systems: Design, develop, and integrate advanced network telemetry detection mechanisms (e.g., deep packet inspection, NetFlow analysis, and sensors) to ensure comprehensive visibility across the enterprise network boundary and internal segments. * Network Traffic Analysis: Serve as the primary technical authority for identifying, analyzing, and characterizing complex network-based cyber events, anomalous traffic patterns, and Advanced Persistent Threat (APT) behaviors within the environment. * Countermeasures: Develop and test network-based countermeasures and active defense strategies designed to detect, disrupt, or neutralize adversary network operations before they impact mission-critical systems. * Design Mitigations: Assist in advising enterprise security design. * Threat Intelligence Integration: Automate the ingestion threat intelligence into network sensor grids to build proactive, high-fidelity detection pipelines. * Strategic Capability Planning: Continuously evaluate emerging network defense technologies, conducting proof-of-concept testing to transition new detection capabilities into the enterprise production architecture. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Turning Container security up to 11 with Capabilities](https://www.wearedevelopers.com/videos/718-turning-container-security-up-to-11-with-capabilities) - [Debunking the Top 10 Myths about Web 3](https://www.wearedevelopers.com/videos/634-debunking-the-top-10-myths-about-web-3) - [The Developer Workstation Blind Spot: Why Your Security Stack Can't See What Matters Most](https://www.wearedevelopers.com/videos/100254-the-developer-workstation-blind-spot-why-your-security-stack-can-t-see-what-matters-most) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)