Overview
SITEC - Threat Detection Engineer to support the Special Operations Forces Information Technology Enterprise Contract (SITEC) - 3 Enterprise Operations and Maintenance (EOM) Task Order. Location : MacDill AFB, Florida. Responsible for developing, implementing, and driving continuous improvement of threat detection capabilities and engineering solutions across the USSOCOM enterprise, including defensive cyber operations, monitoring, detection, and response to cyber incidents.
Responsibilities
- Lead internal and external Purple Team engagements to validate continuous hardening of SOCOM networks and enable successful detection and response during real-world cybersecurity incidents and Red Team assessments.
- Lead integration of data from multiple security tools to detect complex, multi-step attacks with high accuracy.
- Explore and implement security technologies and methodologies to modernize security infrastructure and processes.
- Work with the Active Cyber Defense team to design and execute realistic attack simulations that test the effectiveness of current detections.
- Regularly update the system configuration used for endpoint monitoring to reflect evolving threat landscapes, ensuring coverage of new event types and attack techniques aligned with MITRE ATT&CK.
- Create and maintain comprehensive documentation of threat detection rules, processes, and technologies.
- Optimize existing detections and automation for accuracy, performance, and resilience against evolving adversary TTPs.
- Collaborate with Incident Response (IR) to refine detections and automated workflows based on after-action reports.
- Develop and tune detection rules, behavioral analytics, and signatures based on CTI and threat hunt findings.
- Design, validate, and maintain automated response playbooks, workbooks, and orchestration workflows.
Qualifications
8 years with BS / BA, 6 years with MS / MA, 10 years with AS / AA or 12 years with HSA DoD TS / SCI clearance is requiredIAT 2 and CSSP Analyst OR CSSP Incident ResponderPrior cybersecurity detection and response experienceExperience in maintaining comprehensive documentationDesired Qualifications
GIAC Certified Incident Handler Certification (GCIH)CompTIA Advanced Security Practitioner (CASP+ / SecurityX)Ability to communicate security issues clearly to both technical and non-technical stakeholdersStrong understanding of security technologies used to defend enterprise networks such as EDR, XDR, IDS, IPS, SIEM and SOARDetails
Target Salary Range : $104,000 - $166,000. This represents the typical salary range for this position. Salary is determined by various factors, including the scope and responsibilities of the position, the individual's experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.
EEO : Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.
J-18808-Ljbffr