SITEC - Splunk Engineer - MacDill AFB job in MacDill AFB

Peraton Inc
Tampa, FL, United States
about 1 month ago
Apply on jobs.diversity.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
$86,000.0 - $138,000.0
Working hours
Regular working hours

Tech stack

Adobe Analytics Active Directory IMac Bash Shell Cloud Computing Extract Transform Load (ETL) Data Normalization Information Model Virtual Private Networks (VPN) Python (Programming Language) Machine Learning Network Architecture
+8 more
Computer Network Operations Data Ingestion Mitre Att&ck HR Software Information Technology Splunk Api Management Security Orchestration, Automation & Response

Job description

Peraton requires Splunk Engineers to support the Special Operation Command Information Technology Enterprise Contract (SITEC) - 3 EOM. This position is located at MacDill AFB in Florida.

The purpose of the Special Operations Forces Information Technology Enterprise Contract (SITEC) 3 Enterprise Operations and Maintenance (EOM) Task Order (TO) is to provide USSOCOM, its Component Commands, its Theater Special Operations Commands (TSOCs), and its deployed forces with Operations and Maintenance (O&M) services to maintain Network Operations (NetOps) maintain systems and network infrastructure provide end user and common device support provide configuration, change, license, and asset management conduct training, and perform Install, Move, Add, Change (IMACs) services. The responsibilities and tasks associated with each requirement play a pivotal role to USSOCOM, the CIO/J6 organization, and ultimately the end-user who operate around the globe 24x7x365.

The Splunk Engineer will serve as a technical expert responsible for the design, administration, and optimization of the enterprise Splunk environment, with a specialized and heavy focus on User and Entity Behavior Analytics (UEBA). The engineer will bridge the gap between core log management and advanced behavioral analytics by leveraging Splunk User Behavior Analytics (UBA) and machine learning models to detect compromised accounts, insider threats, and lateral movement. This position ensures that high-fidelity behavioral telemetry is integrated, baselined, and actionable for the Security Operations Center (SOC).

  • Lead the design, engineering and deployment of Splunk User Behavior Analytics (UBA), focusing on the ingestion of identity-centric data sources (e.g., Active Directory, VPN, Cloud Access Security Brokers, and HR systems).
  • Develop, tune, and optimize machine learning models and behavioral algorithms to establish accurate baselines for “normal” user and entity behavior.
  • Collaborate with the Insider Threat and SOC teams to identify anomalous activity, such as credential misuse, unusual data movement, and account takeover (ATO) scenarios.
  • Perform advanced data normalization and tagging using the Splunk Common Information Model (CIM) to ensure behavioral data is properly structured for the UEBA engine.
  • Integrate UEBA-generated anomalies and threats into the Splunk Enterprise Security Incident Review dashboard and Security Orchestration, Automation, and Response (SOAR) playbooks.
  • Monitor UEBA system health, including data ingestion rates, model processing times, and platform stability, performing rapid troubleshooting as required.
  • Document technical configurations, threat modeling logic, and behavioral detection playbooks for the engineering and analyst teams.

Requirements

  • Min 12 years with HS degree, 10 years with AS/AA degree, 8 years with BS/BA, 6 years with MS/MA, 3 years with PhD
  • DoD 8570 IAT II Certification
  • DoD TS/SCI clearance, * Previous experience operating within Department of War (DoW) or DoD enterprise network environments.
  • Active Splunk Enterprise Security Certified Admin or Splunk Certified Developer certifications.
  • Experience using Python or Bash for automation of Splunk administrative tasks and API integrations.
  • Knowledge of the MITRE ATT&CK framework and mapping behavioral anomalies to specific adversary tactics and techniques.

Benefits & conditions

$86,000 - $138,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual’s experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.

About the company

Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world’s leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees do the can’t be done by solving the most daunting challenges facing our customers. Visit peraton.com to learn how we’re keeping people around the world safe and secure.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobs.diversity.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 ¡ LIVE

3:52 min

Avoiding remote code execution from unsanitized inputs

Alexander Pirker ¡ World Congress 2022

2:47 min

Exploring career opportunities and recruitment open positions

Kurt Eder ¡ LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 ¡ LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

54 sec

Interpreting complex terminal commands safely using external explanation utilities

Dan Cranney +2 ¡ LIVE

Videos

See all

Related articles

See all