The Cybersecurity Analytics Systems Administrator will support daily operations, health monitoring, and routine administration of enterprise security data and analytics platforms for SITEC 3 EOM. This onsite role at Macdill AFB, FL focuses on maintaining centralized SIEM capabilities, telemetry ingestion, access control, and platform reliability across multiple tiers.
Key Responsibilities
- Administer user access and role-based access control (RBAC), including index permissions and routine configurations for Splunk Enterprise, Splunk ES, and Microsoft Sentinel workspaces.
- Operate and harden underlying Red Hat Enterprise Linux (RHEL) infrastructure, covering OS-level user management, disk allocation, system auditing, package updates, and baseline STIG hardening.
- Deploy, configure, and maintain data collection agents such as Splunk Universal/Heavy Forwarders, Sentinel Azure Monitor, and syslog daemons to support reliable data flow from enterprise endpoints and appliances.
- Monitor platform operational health, including indexer status, search head performance, and disk volume usage across hot/warm/cold storage tiering to prevent data loss and service disruption.
- Perform scheduled platform and component maintenance, including Splunk upgrades, minor version updates, Splunk technology add-on (TA) updates, and SSL/TLS certificate renewals across all deployment tiers.
- Troubleshoot ingestion and indexing issues such as routine ingestion failures, broken forwarder feeds, missing sourcetypes, and basic analyst-submitted search query performance concerns.
- Conduct scheduled configuration backups (for example, Splunk etc directory snapshots and Sentinel workspace templates) and verify restoration procedures to support operational resilience.
- Create alerts and notifications to notify stakeholders of unusual activity, including security breaches or system failures.
- Maintain configuration and change documentation for the analytics environment.
- Perform basic system troubleshooting to identify causes when issues occur.
- Analyze stored data to identify patterns, trends, and other useful insights.
- Support users experiencing difficulties with the system or improper usage.
- Manage dashboard permissions and coordinate automated PDF report generation, ensuring dashboards load consistently across user groups without permissions-related errors.
- Monitor real-time ingestion rates, track sourcetype volumes, and alert on sudden data drops, silence gaps, or duplicate event streams across deployed inputs.
- Support analysts with foundational dashboard troubleshooting, updating broken filters, correcting simple SPL/KQL syntax issues, and validating input dropdown tokens.
Required Qualifications
- Minimum experience based on education level: 6 years with MS/MA, or 8 years with BS/BA, or 10 years with AS/AA, or 12 years with HS degree.
- DoW TS/SCI clearance
- DoD 8570 IAT II Certification
- Must be DoD 8140 compliant under Work Role Code 451 – Systems Administrator Intermediate (Intermediate level or higher)
Technologies
- Splunk Enterprise
- Splunk ES
- Microsoft Sentinel
- Red Hat Enterprise Linux (RHEL)
- Splunk Universal/Heavy Forwarders
- Sentinel Azure Monitor
- syslog daemons
- hot/warm/cold storage tiering
- STIG
- SSL/TLS
- Splunk technology add-on (TA)
- SPL
- KQL
Benefits
- Medical, dental, vision, and life insurance
- Health savings account
- Short/long term disability
- EAP
- Parental leave
- 401(k)
- Paid time off (PTO) for vacation
- Company paid holidays
Role Details
Location: Macdill AFB, FL (onsite)
Target Salary Range: USD 66,000 - 106,000 per year
Education: MS/MA
Application period: estimated at 30 days from the job posting date
Peraton offers eligible employees a variety of benefits including medical, dental, vision, life, health savings account, short/long term disability, EAP, parental leave, 401(k), paid time off (PTO) for vacation, and company paid holidays.
During the application review process, candidates may be required to participate in an on-camera interview and a process to verify identity. Use of artificial intelligence (AI) tools during Peraton interviews is strictly prohibited unless the candidate has obtained prior written authorization. All interview responses must be the candidate’s own.
EEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.