SITEC - Cybersecurity Analytics Systems Administrator - MacDill AFB
Peraton Tampa, Florida, United States · $66K–$106K/yr
Technology, Information and Internet · 10,001+ employees
About the role
The Cybersecurity Analytics Systems Administrator manages the daily operation, health monitoring, and maintenance of enterprise security data and analytics platforms. This role ensures data integrity and operational readiness of SIEM systems while supporting security analysts with dashboard management and troubleshooting.
What they look for
Requirements
Candidates must possess a Top Secret/SCI clearance and a DoD 8570 IAT II certification. A minimum of 6 to 12 years of experience is required depending on the level of education attained.
Full description
Responsibilities
Peraton requires a Cybersecurity Analytics Systems Administrator to support the Special Operation Command Information Technology Enterprise Contract (SITEC) – 3 EOM. This position is located at MacDill AFB in Florida.
The purpose of the Special Operations Forces Information Technology Enterprise Contract (SITEC) 3 Enterprise Operations and Maintenance (EOM) Task Order (TO) is to provide USSOCOM, its Component Commands, its Theater Special Operations Commands (TSOCs), and its deployed forces with Operations and Maintenance (O&M) services to maintain Network Operations (NetOps); maintain systems and network infrastructure; provide end user and common device support; provide configuration, change, license, and asset management; conduct training, and perform Install, Move, Add, Change (IMACs) services. The responsibilities and tasks associated with each requirement play a pivotal role to USSOCOM, the CIO/J6 organization, and ultimately the end-user who operate around the globe 24x7x365.
The Cybersecurity Analytics Systems Administrator is responsible for the daily operation, health monitoring, routine administration, and maintenance of enterprise security data and analytics platforms. Operating primarily within the Operations and Maintenance (O&M) lifecycle, this role ensures sustained availability, data integrity, data integration and operational readiness of centralized Security Information and Event Management (SIEM) systems and other infrastructure required to operate. The administrator serves as the frontline custodian for enterprise security telemetry feeds, managing data forwarders, tracking ingestion pipelines, maintaining user access controls, and assisting security analysts with dashboard views and search queries. For major cluster re-architectures, deep pipeline schema engineering, or critical distributed outages.
- Manage user access, role-based access control (RBAC), index permissions, and routine configurations across analytical platforms, including Splunk Enterprise, Splunk ES, and Microsoft Sentinel workspaces.
- Maintain and administer underlying Red Hat Enterprise Linux (RHEL) servers, including OS-level user management, disk space allocation, system auditing, package updates, and baseline STIG hardening.
- Deploy, configure, and maintain data collection agents (e.g., Splunk Universal/Heavy Forwarders, Sentinel Azure Monitor, syslog daemons) across enterprise endpoints and appliances to ensure reliable data flow.
- Monitor platform operational health, indexer status, search head performance, and disk volume usage (hot/warm/cold storage tiering) to prevent data loss and service disruption.
- Execute scheduled platform upgrades, minor version updates, Splunk technology add-on (TA) updates, and SSL/TLS certificate renewals across all deployment tiers.
- Troubleshoot routine ingestion failures, broken forwarder feeds, missing sourcetypes, and basic search query performance issues submitted by analysts.
- Perform scheduled configuration backups (e.g., Splunk etc directory snapshots, Sentinel workspace templates) and verify restoration procedures for operational resilience.
- Creates alerts and notifications to notify stakeholders of unusual activity such as security breaches or system failures.
- Maintains documentation of all configurations and changes to the system.
- Performs basic troubleshooting when issues occur with the system to identify the cause.
- Analyzes data in order to identify patterns, trends, or other useful information.
- Provides support to users who are having problems with the system or using it incorrectly.
- Manage dashboard permissions, schedule automated PDF report generation, and ensure dashboards load consistently across user groups without permissions-related errors.
- Monitor real-time data ingestion rates, track sourcetype volumes, and alert on sudden data drops, silence gaps, or duplicate event streams across deployed inputs.
- Assist security analysts with basic dashboard troubleshooting, updating broken filters, fixing simple SPL/KQL query syntax errors, and validating input dropdown tokens
Qualifications
Required Qualifications:
- Min 12 years with HS degree, 10 years with AS/AA degree, 8 years with BS/BA, 6 years with MS/MA
- DoW TS/SCI clearance
- DoD 8570 IAT II Certification
- Must be with DoW 8140 compliant under the Work Role Code 451 – Systems Administrator Intermediate - Intermediate level or higher
Peraton Overview
Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world’s leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees do the can’t be done by solving the most daunting challenges facing our customers. Visit peraton.com to learn how we’re keeping people around the world safe and secure.
Target Salary Range
$66,000 - $106,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual’s experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay. EEO
EEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.
Similar roles
-
Staff Security Engineer, Abuse Control
Stripe London, England, United Kingdom
-
Senior Infrastructure and Cloud Security Engineer (m/f/d)
ICE Services London, England, United Kingdom
-
Lead - Product Security Engineer
Rocketlane Chennai, Tamil Nadu, India
-
Lead Manager, IT Security Engineer
Make-A-Wish America $70K–$84K/yr
-
Staff Cloud Security Engineer
Xometry Quinte West, Ontario, Canada · $205K–$233K/yr
-
Fire Security Engineer
Allsaved Ltd Glasgow, Scotland, United Kingdom · £38K–£45K/yr