SITEC - SENTINEL SOAR Automation Engineer - MacDill AFB
Peraton · MacDill AFB, FL, US
About this role
## SITEC - Sentinel SOAR Automation Engineer (MacDill AFB) ### Responsibilities - Design, build, and maintain automation solutions to support enterprise cyber defense capabilities, with a primary focus on **SOAR platforms** and central telemetry systems such as **Splunk** and **Microsoft Sentinel**. - Minimize manual, repetitive tasks for **SOC analysts** and the Enterprise Operations Team; accelerate incident response timelines and ensure consistent enforcement of security policies. - Use scripting and **API integrations** to connect disparate security tools into a cohesive **SIEM/SOAR** architecture for data sharing, optimized alert generation, and automated threat mitigation workflows. - Design, develop, test, and deploy automated workflows, **playbooks**, and scripts for cyber incident triage, investigation, and remediation. - Administer and engineer enterprise SOAR platforms (architecture planning, system health monitoring, and version upgrades). - Develop custom API integrations connecting the SOAR platform with internal/external security tools, **Threat Intelligence Platforms (TIPs)**, and IT service management systems. - Collaborate with incident responders, threat hunters, and cyber analysts to gather requirements, map **SOPs**, and translate them into automated processes. - Write and optimize custom scripts (primarily **Python, PowerShell, or Bash**) for parsing data, enriching alerts, and executing response actions. - Troubleshoot and resolve complex issues (playbook execution errors, failed API integrations, and data ingestion bottlenecks). - Work with the automations team to develop and deploy cohesive enterprise automation solutions. - Maintain comprehensive documentation for custom code, automation architecture, and playbook logic. - Provide technical guidance and training to SOC personnel on using automated workflows effectively. - Design, deploy, and maintain integrations between SIEM platforms (e.g., Splunk, Microsoft Sentinel) and the enterprise SOAR to enable bi-directional automated alert triage and response. ### Required Qualifications - **DoD TS/SCI clearance required** - **DoD 8570 IAT II** - Must be **DoW 8140 compliant** under Work Role Code **451 – System Administrator – Intermediate level or higher** by **1 September 26** - Experience requirements (with education): - **Min 12 years** with HS Diploma - **10 years** with AS/AA degree - **8 years** with BS/BA degree - **6 years** with MS/MA - **3 years** with PhD ### Desired Qualifications - Experience operating within **Department of War (DoW)** or **DoD enterprise network** environments. - Familiarity with **CI/CD**, **DevOps**, and version control (e.g., **Git**) for managing automation code. - Experience with **SIEM engineering**, log management, and **EDR/XDR** technologies (e.g., Splunk Enterprise Security, CrowdStrike). - Experience with cloud-native automation tools (e.g., **AWS Lambda**, **Azure Logic Apps**). ### Salary Range - **$104,000 – $166,000** (typical range; final offer depends on factors including experience, education, location, and contract considerations) ### Company **Peraton** — next-generation national security company supporting critical missions across domains. *EEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.*
Listing freshness
CronJobs last confirmed this listing 1d ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.