SITEC - Cyber Threat Detection Engineer - MacDill AFB

Peraton - Tampa, FL

Hiring: SITEC - Cyber Threat Detection Engineer - MacDill AFB Company: Peraton Location: Tampa, FL Job Posted Time: 2026-09-09 18:07:06 Employment Type: Contract Target Skills & Keywords : Elasticsearch, Move, SAFe, SIEM, SOC, Splunk, jQuery About the job Required Skills: •Peraton requires a •Cyber Threat Detection Engineer •to support the Special Operation Command Information Technology Enterprise Contract (SITEC) - 3 EOM. This position is located at MacDill AFB in Florida. •The purpose of the Special Operations Forces Information Technology Enterprise Contract (SITEC) 3 Enterprise Operations and Maintenance (EOM) Task Order (TO) is to provide USSOCOM, its Component Commands, its Theater Special Operations Commands (TSOCs), and its deployed forces with Operations and Maintenance (O&M) services to maintain Network Operations (NetOps); maintain systems and network infrastructure; provide end user and common device support; provide configuration, change, license, and asset management; conduct training, and perform Install, Move, Add, Change (IMACs) services. The responsibilities and tasks associated with each requirement play a pivotal role to USSOCOM, the CIO/J6 organization, and ultimately the end-user who operate around the globe 24x7x365. •Cyber Threat •Detection Engineer •serves as the primary technical authority for designing, authoring, validating, and optimizing threat detection capabilities across enterprise cyber defense systems. Operating at the intersection of Threat Intelligence, Security Operations, and Security Engineering, this role is responsible for translating adversary tactics, techniques, and procedures (TTPs) into actionable, high-fidelity detection rules within Splunk Enterprise Security (ES) and orchestrated response workflows within enterprise SOAR platforms. The engineer ensures comprehensive visibility into enterprise telemetry, reduces alert fatigue for frontline SOC analysts by eliminating false positives, and adopts Detection-as-Code (DaC) principles to continuously test, maintain, and mature the organization's defensive posture. •Design, build, test, and tune complex correlation searches, behavioral analytics, and threat detections within Splunk Enterprise Security (ES) utilizing advanced Splunk Search Processing Language (SPL), and Microsoft Sentinel with Kusto Query Language (KQL). •Map and continuously evaluate enterprise detection coverage against the MITRE ATT&CK framework to identify, prioritize, and remediate visibility and detection blind spots across endpoint, cloud, and network environments. •Collaborate with automation teams to design, test, and optimize automated SOAR playbooks that trigger on SIEM detections to enrich ale Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!