CronJobs

security jobs

SITEC - SOC 1 Operations Lead

Peraton · MacDill AFB, FL, US

onsitesenior$80,000–$128,000Posted Sep 9, 2026SplunkMicrosoft SentinelSIEMEDRIDS/IPSSOARXDR

Apply on the employer site

About this role

## SITEC - SOC 1 Operations Lead (MacDill AFB, FL) ### Responsibilities - Lead daily SOC Tier 1 shift operations, directing and participating in triage of incoming security events from **SIEM, EDR, IDS/IPS, and email security gateways** to achieve rapid **MTTA/MTTT**. - Manage high-tempo queue operations and enforce **strict Service Level Agreements (SLAs)**. - Perform real-time **quality assurance (QA)** on triage notes, scoping decisions, and escalation packages before routing to **SOC 2 / Incident Response**. - Maintain detection health monitoring by taking technical ownership of **SIEM scheduler queues**, tracking **log ingestion latencies**, validating **forwarder uptime**, and ensuring automated alerting pipelines run reliably. - Track real-time log ingestion feeds and sensor availability (e.g., **Splunk Universal Forwarders**, **Syslog collectors**); rapidly flag and troubleshoot data drop-offs, parsing errors, or telemetry delays with engineering teams. - Serve as the immediate technical escalation point for complex or high-priority events. - Author, update, and refine Tier 1 **triage runbooks, investigation guides, and SOPs** to ensure consistent, repeatable alert handling across all shifts. - Identify noisy or redundant detection rules causing high false positives; document findings and submit structured tuning recommendations to **Detection Engineering**. - Provide continuous operational leadership, mentorship, and technical support to Tier 1 analysts across a **24/7/365** schedule. - Conduct structured shift turnovers, deliver real-time investigative guidance during high-tempo alert cycles, and lead technical upskilling initiatives. ### Qualifications **Required** - Minimum **10 years** of experience - **DoD 8570 IAT II** Certification - **DoW TS/SCI** clearance - Must be **DoW 8140 compliant** under **Work Role Code 531 – Cyber Defense Incident Responder (Intermediate level or higher)** **Desired** - Strong analytical and problem-solving skills - Ability to communicate security issues clearly to technical and non-technical stakeholders - Strong understanding of enterprise security technologies (e.g., **EDR, XDR, IDS, IPS, SIEM, SOAR**) - Hands-on experience with **SIEM** solutions such as **Splunk** and **Microsoft Sentinel** - Experience working in a **24/7 SOC** environment ### Target Salary Range **$80,000 – $128,000** (typical range; final offer depends on factors including experience, education, location, and contract/business considerations). May include overtime, shift differential, and a discretionary bonus depending on position. *Peraton is an equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.*

Listing freshness

CronJobs last confirmed this listing 23h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.

Browse all software engineering jobs →

Follow fresh jobs in Discord