SITEC - Splunk Engineer - MacDill AFB

PeratonTampa, FL
$86,000 - $138,000Onsite

About The Position

Peraton requires Splunk Engineers to support the Special Operation Command Information Technology Enterprise Contract (SITEC) – 3 EOM. This position is located at MacDill AFB in Florida. The purpose of the Special Operations Forces Information Technology Enterprise Contract (SITEC) 3 Enterprise Operations and Maintenance (EOM) Task Order (TO) is to provide USSOCOM, its Component Commands, its Theater Special Operations Commands (TSOCs), and its deployed forces with Operations and Maintenance (O&M) services to maintain Network Operations (NetOps); maintain systems and network infrastructure; provide end user and common device support; provide configuration, change, license, and asset management; conduct training, and perform Install, Move, Add, Change (IMACs) services. The responsibilities and tasks associated with each requirement play a pivotal role to USSOCOM, the CIO/J6 organization, and ultimately the end-user who operate around the globe 24x7x365. The Splunk Engineer will serve as a technical expert responsible for the design, administration, and optimization of the enterprise Splunk environment, with a specialized and heavy focus on User and Entity Behavior Analytics (UEBA). The engineer will bridge the gap between core log management and advanced behavioral analytics by leveraging Splunk User Behavior Analytics (UBA) and machine learning models to detect compromised accounts, insider threats, and lateral movement. This position ensures that high-fidelity behavioral telemetry is integrated, baselined, and actionable for the Security Operations Center (SOC).

Requirements

  • Min 12 years with HS degree, 10 years with AS/AA degree, 8 years with BS/BA, 6 years with MS/MA, 3 years with PhD
  • DoD 8570 IAT II Certification
  • DoD TS/SCI clearance

Nice To Haves

  • Previous experience operating within Department of War (DoW) or DoD enterprise network environments.
  • Active Splunk Enterprise Security Certified Admin or Splunk Certified Developer certifications.
  • Experience using Python or Bash for automation of Splunk administrative tasks and API integrations.
  • Knowledge of the MITRE ATT&CK framework and mapping behavioral anomalies to specific adversary tactics and techniques.

Responsibilities

  • Lead the design, engineering and deployment of Splunk User Behavior Analytics (UBA), focusing on the ingestion of identity-centric data sources (e.g., Active Directory, VPN, Cloud Access Security Brokers, and HR systems).
  • Develop, tune, and optimize machine learning models and behavioral algorithms to establish accurate baselines for "normal" user and entity behavior.
  • Collaborate with the Insider Threat and SOC teams to identify anomalous activity, such as credential misuse, unusual data movement, and account takeover (ATO) scenarios.
  • Perform advanced data normalization and tagging using the Splunk Common Information Model (CIM) to ensure behavioral data is properly structured for the UEBA engine.
  • Integrate UEBA-generated anomalies and threats into the Splunk Enterprise Security Incident Review dashboard and Security Orchestration, Automation, and Response (SOAR) playbooks.
  • Monitor UEBA system health, including data ingestion rates, model processing times, and platform stability, performing rapid troubleshooting as required.
  • Document technical configurations, threat modeling logic, and behavioral detection playbooks for the engineering and analyst teams.

Benefits

  • overtime
  • shift differential
  • discretionary bonus
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service