> Markdown version of [/jobs/ext/2988408-sitec-cybersecurity-analytics-systems-administrator-macdill](https://www.wearedevelopers.com/jobs/ext/2988408-sitec-cybersecurity-analytics-systems-administrator-macdill). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # SITEC - Cybersecurity Analytics Systems Administrator - MacDill - **Company:** Peraton Inc - **Location:** Tampa, FL, United States - **Salary:** $66,000.0 - $106,000.0 - **Contract:** Permanent contract - **Skills:** Adobe Analytics, Query Performance, Business Analytics Applications, IMac, Cyber Security, Data Integration, Data Integrity, Data Loss, Data Systems, Network Architecture, Role-Based Access Control, Red Hat Enterprise Linux, Kusto Query Language, Security Information and Event Management, Data Streaming, Computer Network Operations, Data Ingestion, Information Technology, Microsoft Sentinel, Real Time Data, Splunk, Network Server, User Administration - **Published:** September 18, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9172094/sitec-cybersecurity-analytics-systems-administrator-macdill ## About the Role * Min 12 years with HS degree, 10 years with AS/AA degree, 8 years with BS/BA, 6 years with MS/MA * DoW TS/SCI clearance * DoD 8570 IAT II Certification * Must be with DoW 8140 compliant under the Work Role Code 451 - Systems Administrator Intermediate - Intermediate level or higher ## Description Peraton requires a Cybersecurity Analytics Systems Administrator to support the Special Operation Command Information Technology Enterprise Contract (SITEC) - 3 EOM. This position is located at MacDill AFB in Florida. The purpose of the Special Operations Forces Information Technology Enterprise Contract (SITEC) 3 Enterprise Operations and Maintenance (EOM) Task Order (TO) is to provide USSOCOM, its Component Commands, its Theater Special Operations Commands (TSOCs), and its deployed forces with Operations and Maintenance (O&M) services to maintain Network Operations (NetOps); maintain systems and network infrastructure; provide end user and common device support; provide configuration, change, license, and asset management; conduct training, and perform Install, Move, Add, Change (IMACs) services. The responsibilities and tasks associated with each requirement play a pivotal role to USSOCOM, the CIO/J6 organization, and ultimately the end-user who operate around the globe 24x7x365. The Cybersecurity Analytics Systems Administrator is responsible for the daily operation, health monitoring, routine administration, and maintenance of enterprise security data and analytics platforms. Operating primarily within the Operations and Maintenance (O&M) lifecycle, this role ensures sustained availability, data integrity, data integration and operational readiness of centralized Security Information and Event Management (SIEM) systems and other infrastructure required to operate. The administrator serves as the frontline custodian for enterprise security telemetry feeds, managing data forwarders, tracking ingestion pipelines, maintaining user access controls, and assisting security analysts with dashboard views and search queries. For major cluster re-architectures, deep pipeline schema engineering, or critical distributed outages. * Manage user access, role-based access control (RBAC), index permissions, and routine configurations across analytical platforms, including Splunk Enterprise, Splunk ES, and Microsoft Sentinel workspaces. * Maintain and administer underlying Red Hat Enterprise Linux (RHEL) servers, including OS-level user management, disk space allocation, system auditing, package updates, and baseline STIG hardening. * Deploy, configure, and maintain data collection agents (e.g., Splunk Universal/Heavy Forwarders, Sentinel Azure Monitor, syslog daemons) across enterprise endpoints and appliances to ensure reliable data flow. * Monitor platform operational health, indexer status, search head performance, and disk volume usage (hot/warm/cold storage tiering) to prevent data loss and service disruption. * Execute scheduled platform upgrades, minor version updates, Splunk technology add-on (TA) updates, and SSL/TLS certificate renewals across all deployment tiers. * Troubleshoot routine ingestion failures, broken forwarder feeds, missing sourcetypes, and basic search query performance issues submitted by analysts. * Perform scheduled configuration backups (e.g., Splunk etc directory snapshots, Sentinel workspace templates) and verify restoration procedures for operational resilience. * Creates alerts and notifications to notify stakeholders of unusual activity such as security breaches or system failures. * Maintains documentation of all configurations and changes to the system. * Performs basic troubleshooting when issues occur with the system to identify the cause. * Analyzes data in order to identify patterns, trends, or other useful information. * Provides support to users who are having problems with the system or using it incorrectly. * Manage dashboard permissions, schedule automated PDF report generation, and ensure dashboards load consistently across user groups without permissions-related errors. * Monitor real-time data ingestion rates, track sourcetype volumes, and alert on sudden data drops, silence gaps, or duplicate event streams across deployed inputs. * Assist security analysts with basic dashboard troubleshooting, updating broken filters, fixing simple SPL/KQL query syntax errors, and validating input dropdown tokens ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [How to Avoid LLM Pitfalls - Mete Atamel and Guillaume Laforge](https://www.wearedevelopers.com/videos/1328-how-to-avoid-llm-pitfalls-mete-atamel-and-guillaume-laforge) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [From Shadow AI to Secure Intelligence: Safe AI Usage in the Enterprise](https://www.wearedevelopers.com/videos/2093-from-shadow-ai-to-secure-intelligence-safe-ai-usage-in-the-enterprise) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 139 - Soft and hard queries](https://www.wearedevelopers.com/magazine/487-dev-digest-139-soft-and-hard-queries) - [Dev Digest 129 - Now that's what I call private data!](https://www.wearedevelopers.com/magazine/468-dev-digest-129-now-that-s-what-i-call-private-data) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)