CronJobs

security jobs

SITEC - Cyber Threat Hunter - MacDill AFB

Peraton · MacDill AFB, FL, US

onsiteunknown$80,000–$128,000Posted Sep 9, 2026Splunk SPLKQLSQLMicrosoft SentinelSIEMSOAREDRMITRE ATT&CK

Apply on the employer site

About this role

## Cyber Threat Hunter (SITEC) — MacDill AFB, FL ### Responsibilities - Proactively identify, track, and disrupt sophisticated cyber adversaries that bypass traditional perimeter defenses and automated security controls. - Develop, test, and execute intelligence-led threat hunt hypotheses across enterprise endpoints, networks, and cloud workloads to discover undetected intrusions and advanced persistent threats (APTs). - Analyze tactical and operational Cyber Threat Intelligence (CTI) reports, actor profiles, and technical indicators to extract adversary TTPs and translate them into focused, enterprise-wide search patterns. - Map hunting activities, discovered gaps, and behavioral analytics to the **MITRE ATT&CK** framework to ensure comprehensive coverage across the cyber kill chain. - Query, analyze, and correlate large-scale enterprise data sets using advanced search languages (e.g., **Splunk SPL, KQL, SQL**) across sources such as **EDR**, **Sysmon**, Windows Event Logs, network flow, and authentication logs. - Partner with Detection Engineers and SOC analysts to convert confirmed hunt techniques and malicious patterns into durable, automated **SIEM** correlation rules and **SOAR** response workflows. - Produce detailed hunt reports, executive summaries, and tactical findings dossiers (including root cause analysis, coverage metrics, and defensive gap remediation recommendations). - Perform end-to-end hunt operations: formulate behavioral queries, extract/normalize telemetry, and use data stacking/frequency analysis to identify statistical outliers, anomalous parent-child process relationships, and unauthorized binary executions. ### Qualifications **Required** - Minimum experience based on education: - **12 years** with **HS degree** - **10 years** with **AS/AA degree** - **8 years** with **BS/BA** - **6 years** with **MS/MA** - **3 years** with **PhD** - **DoD 8570 IAT II** certification - **DoD TS/SCI clearance** - Must be **DoD 8140 compliant** under Work Role Code **531 — Cyber Defense Incident Responder (Intermediate or higher)** **Desired** - Strong analytical and problem-solving skills - Ability to communicate security issues clearly to technical and non-technical stakeholders - Strong understanding of enterprise security technologies (e.g., **EDR, XDR, IDS, IPS, SIEM, SOAR**) - Hands-on experience with **SIEM** tools such as **Splunk** and **Microsoft Sentinel** to create threat detections - Experience tracking adversarial TTPs and developing threat hunts ### Location - **MacDill AFB, Florida** ### Salary Range - **$80,000 – $128,000** (typical range; final offer depends on experience, education, location, and contract/business factors) ### Company **Peraton** — next-generation national security company supporting critical missions across domains.

Listing freshness

CronJobs last confirmed this listing 23h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.

Browse all software engineering jobs →

Follow fresh jobs in Discord