SITEC - Splunk Engineer - MacDill AFB

Peraton

$86K — $138K *
Tampa, FL 33621In-Person
Technical Services
11 - 15 years of experience
Job Overview by Ladders

Qualifications

  • 12+ years with high school diploma or equivalent experience in relevant roles; 10 years with associate's degree; 8 years with bachelor's; 6 years with master's; 3 years with PhD.
  • DoD 8570 IAT II certification required.
  • Current DoD TS/SCI clearance necessary.
  • Preferred background in Department of War or DoD enterprise networks.
  • Active certifications in Splunk Enterprise Security Administration or Splunk Development.
  • Proficient in Python or Bash for automating Splunk tasks and making API connections.
  • Familiarity with the MITRE ATT&CK framework.

Responsibilities

  • Lead the design and implementation of Splunk User Behavior Analytics (UBA).
  • Develop and optimize machine learning models for user behavior baselines.
  • Collaborate with Insider Threat and SOC teams to analyze anomalous activities.
  • Normalize and tag data using the Splunk Common Information Model (CIM).
  • Integrate anomalies into Splunk Security dashboards and SOAR playbooks.
  • Monitor the health of the UEBA system and perform troubleshooting.
  • Document configurations, threat models, and detection playbooks.

Benefits

  • Comprehensive health insurance plan.
  • Paid time off and holidays.
  • Continuing education opportunities.
  • Retirement savings plan with employer matching.
  • Flexible work schedules and options.
Full Job Description
Responsibilities

Peraton requires Splunk Engineers to support the Special Operation Command Information Technology Enterprise Contract (SITEC) - 3 EOM. This position is located at MacDill AFB in Florida.

The purpose of the Special Operations Forces Information Technology Enterprise Contract (SITEC) 3 Enterprise Operations and Maintenance (EOM) Task Order (TO) is to provide USSOCOM, its Component Commands, its Theater Special Operations Commands (TSOCs), and its deployed forces with Operations and Maintenance (O&M) services to maintain Network Operations (NetOps); maintain systems and network infrastructure; provide end user and common device support; provide configuration, change, license, and asset management; conduct training, and perform Install, Move, Add, Change (IMACs) services. The responsibilities and tasks associated with each requirement play a pivotal role to USSOCOM, the CIO/J6 organization, and ultimately the end-user who operate around the globe 24x7x365.

The Splunk Engineer will serve as a technical expert responsible for the design, administration, and optimization of the enterprise Splunk environment, with a specialized and heavy focus on User and Entity Behavior Analytics (UEBA). The engineer will bridge the gap between core log management and advanced behavioral analytics by leveraging Splunk User Behavior Analytics (UBA) and machine learning models to detect compromised accounts, insider threats, and lateral movement. This position ensures that high-fidelity behavioral telemetry is integrated, baselined, and actionable for the Security Operations Center (SOC).
  • Lead the design, engineering and deployment of Splunk User Behavior Analytics (UBA), focusing on the ingestion of identity-centric data sources (e.g., Active Directory, VPN, Cloud Access Security Brokers, and HR systems).
  • Develop, tune, and optimize machine learning models and behavioral algorithms to establish accurate baselines for "normal" user and entity behavior.
  • Collaborate with the Insider Threat and SOC teams to identify anomalous activity, such as credential misuse, unusual data movement, and account takeover (ATO) scenarios.
  • Perform advanced data normalization and tagging using the Splunk Common Information Model (CIM) to ensure behavioral data is properly structured for the UEBA engine.
  • Integrate UEBA-generated anomalies and threats into the Splunk Enterprise Security Incident Review dashboard and Security Orchestration, Automation, and Response (SOAR) playbooks.
  • Monitor UEBA system health, including data ingestion rates, model processing times, and platform stability, performing rapid troubleshooting as required.
  • Document technical configurations, threat modeling logic, and behavioral detection playbooks for the engineering and analyst teams.


Qualifications

Required Qualifications:

  • Min 12 years with HS degree, 10 years with AS/AA degree, 8 years with BS/BA, 6 years with MS/MA, 3 years with PhD
  • DoD 8570 IAT II Certification
  • DoD TS/SCI clearance

Desired Qualifications:
  • Previous experience operating within Department of War (DoW) or DoD enterprise network environments.
  • Active Splunk Enterprise Security Certified Admin or Splunk Certified Developer certifications.
  • Experience using Python or Bash for automation of Splunk administrative tasks and API integrations.
  • Knowledge of the MITRE ATT&CK framework and mapping behavioral anomalies to specific adversary tactics and techniques.


Target Salary Range

$86,000 - $138,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual's experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.

Similar Jobs

More Jobs at Peraton

More Technical Services Jobs

Find similar SITEC - Splunk Engineer - MacDill AFB jobs: