> Markdown version of [/jobs/ext/2397434-sitec-splunk-engineer-macdill-afb-job-in-macdill-afb](https://www.wearedevelopers.com/jobs/ext/2397434-sitec-splunk-engineer-macdill-afb-job-in-macdill-afb). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # SITEC - Splunk Engineer - MacDill AFB job in MacDill AFB - **Company:** Peraton Inc - **Location:** Tampa, FL, United States - **Salary:** $86,000.0 - $138,000.0 - **Contract:** Permanent contract - **Skills:** Adobe Analytics, Active Directory, IMac, Bash Shell, Cloud Computing, Extract Transform Load (ETL), Data Normalization, Information Model, Virtual Private Networks (VPN), Python (Programming Language), Machine Learning, Network Architecture, Computer Network Operations, Data Ingestion, Mitre Att&ck, HR Software, Information Technology, Splunk, Api Management, Security Orchestration, Automation & Response - **Published:** August 1, 2026 - **Apply:** https://jobs.diversity.com/career/2437026/sitec-splunk-engineer-macdill-afb-florida-fl-macdill-afb ## About the Role * Min 12 years with HS degree, 10 years with AS/AA degree, 8 years with BS/BA, 6 years with MS/MA, 3 years with PhD * DoD 8570 IAT II Certification * DoD TS/SCI clearance, * Previous experience operating within Department of War (DoW) or DoD enterprise network environments. * Active Splunk Enterprise Security Certified Admin or Splunk Certified Developer certifications. * Experience using Python or Bash for automation of Splunk administrative tasks and API integrations. * Knowledge of the MITRE ATT&CK framework and mapping behavioral anomalies to specific adversary tactics and techniques. ## Description Peraton requires Splunk Engineers to support the Special Operation Command Information Technology Enterprise Contract (SITEC) - 3 EOM. This position is located at MacDill AFB in Florida. The purpose of the Special Operations Forces Information Technology Enterprise Contract (SITEC) 3 Enterprise Operations and Maintenance (EOM) Task Order (TO) is to provide USSOCOM, its Component Commands, its Theater Special Operations Commands (TSOCs), and its deployed forces with Operations and Maintenance (O&M) services to maintain Network Operations (NetOps) maintain systems and network infrastructure provide end user and common device support provide configuration, change, license, and asset management conduct training, and perform Install, Move, Add, Change (IMACs) services. The responsibilities and tasks associated with each requirement play a pivotal role to USSOCOM, the CIO/J6 organization, and ultimately the end-user who operate around the globe 24x7x365. The Splunk Engineer will serve as a technical expert responsible for the design, administration, and optimization of the enterprise Splunk environment, with a specialized and heavy focus on User and Entity Behavior Analytics (UEBA). The engineer will bridge the gap between core log management and advanced behavioral analytics by leveraging Splunk User Behavior Analytics (UBA) and machine learning models to detect compromised accounts, insider threats, and lateral movement. This position ensures that high-fidelity behavioral telemetry is integrated, baselined, and actionable for the Security Operations Center (SOC). * Lead the design, engineering and deployment of Splunk User Behavior Analytics (UBA), focusing on the ingestion of identity-centric data sources (e.g., Active Directory, VPN, Cloud Access Security Brokers, and HR systems). * Develop, tune, and optimize machine learning models and behavioral algorithms to establish accurate baselines for "normal" user and entity behavior. * Collaborate with the Insider Threat and SOC teams to identify anomalous activity, such as credential misuse, unusual data movement, and account takeover (ATO) scenarios. * Perform advanced data normalization and tagging using the Splunk Common Information Model (CIM) to ensure behavioral data is properly structured for the UEBA engine. * Integrate UEBA-generated anomalies and threats into the Splunk Enterprise Security Incident Review dashboard and Security Orchestration, Automation, and Response (SOAR) playbooks. * Monitor UEBA system health, including data ingestion rates, model processing times, and platform stability, performing rapid troubleshooting as required. * Document technical configurations, threat modeling logic, and behavioral detection playbooks for the engineering and analyst teams. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Old tools, new tricks](https://www.wearedevelopers.com/videos/1916-old-tools-new-tricks) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) - [MCP doesn’t suck — your agent does](https://www.wearedevelopers.com/videos/100202-mcp-doesn-t-suck-your-agent-does) - [SRE Methods In an Agency Environment](https://www.wearedevelopers.com/videos/348-sre-methods-in-an-agency-environment) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Dev Digest 152: Chrome Extensions Hack, CSS Spy Sheets, Deepseek OSS AI](https://www.wearedevelopers.com/magazine/540-dev-digest-152-chrome-extensions-hack-css-spy-sheets-deepseek-oss-ai)