SITEC - SPLUNK SOAR Automation Engineer - MacDill AFB
Peraton · MacDill AFB, FL, US
About this role
**SITEC - SPLUNK SOAR Automation Engineer - MacDill AFB** **About the Role** Peraton is seeking an Automation Engineer to support the Special Operations Command Information Technology Enterprise Contract (SITEC) 3 at MacDill AFB. You'll design, build, and maintain automation solutions for enterprise cyber defense, with a focus on Security Orchestration, Automation, and Response (SOAR) platforms and central telemetry systems like Splunk and Microsoft Sentinel. **Key Responsibilities** • Design, develop, test, and deploy automated workflows, playbooks, and scripts for cyber incident triage, investigation, and remediation • Administer and engineer enterprise SOAR platforms, including architecture planning and system health monitoring • Develop custom API integrations connecting SOAR platforms with security tools, Threat Intelligence Platforms, and IT service management systems • Write and optimize custom scripts (Python, PowerShell, Bash) for data parsing, alert enrichment, and response actions • Troubleshoot complex issues related to playbook execution, API integrations, and data ingestion • Design and maintain SIEM/SOAR integrations (Splunk, Microsoft Sentinel) for automated alert triage and response • Collaborate with incident responders, threat hunters, and cyber analysts to translate SOPs into automated processes • Maintain comprehensive documentation and provide technical guidance to SOC personnel **Required Qualifications** • Minimum experience: 12 years (HS Diploma), 10 years (AS/AA), 8 years (BS/BA), 6 years (MS/MA), or 3 years (PhD) • DoD TS/SCI clearance required • DoD 8570 IAT II certification • DoD 8140 compliance under Work Role Code 451 (System Administrator - Intermediate or higher) by September 26, 2026 **Desired Qualifications** • DoD/Department of War enterprise network environment experience • CI/CD pipelines, DevOps practices, and version control systems (Git) • SIEM engineering, log management, EDR/XDR technologies (Splunk Enterprise Security, CrowdStrike) • Cloud-native automation tools (AWS Lambda, Azure Logic Apps) **Compensation** $104,000 - $166,000 (based on experience, education, and qualifications) **Equal Opportunity Employer** | Disability | Protected Veterans
Listing freshness
CronJobs last confirmed this listing 2d ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.