SIEM (Elastic)-Remote

Other Jobs To Apply

No other job posts for this day.

Need 2 Managerial References with LinkedInHighly Preferred To already have clearanceSeeking a Sr.SIEM Engineer specializing in Elastic Stack and Confluent in support of the PEO Enterprise SIEM Consolidation / Cyber Defense effort.This effort is focused on the consolidation of PEO Enterprise multiple SIEM solutions (approx.40) into one consolidated SIEM.This individual should have extensive experience with Security Information and Event Management (SIEM) deployment and tuning as well as Security Orchestration Automation and Response (SOAR) development and implementation.Responsibilities :Design, deploy, configure, and maintain Elastic stack and Confluent deploymentsManage, patch, and upgrade Elasticsearch, Confluent, and other related systemsTune and optimize Elastic stack deployments based on application / customer needsDesign and configure ETL data pipelines to ingest customer defined data sets such as application logs, metrics, and or threat eventsCreate custom visualizations and dashboards using KibanaConfigure and maintain index templates and information lifecycle management (ILM) policiesDevelop Elastic alerting solutions using Watcher and / or Kibana Rules and Connectors with integrations to ticketing systems, email, and messaging apps as requiredDevelop Machine Learning (ML) jobs to dynamically monitor and alert on identified metrics, KPIs, and / or data anomaliesFollow ITIL based change management processes to move solutions from Dev to Test and into ProductionRun the day-to-day operations of the security operations centerInvestigate incidents and lead response efforts as applicableRequired Skills :A Secret clearance will be required to maintain this positionCompliance with DoD 8140 / 8570 IAT Level II certification prior to start dateAt least 5 years of hands-on experience in deployment, configuration, and solution development using the Elastic Stack for security and logging use-cases.Specific experience with Elastic SIEM is plusDemonstrated experience with the full Elastic Stack - Elasticsearch, Logstash, Kibana, Beats, Machine Learning, and REST API integrationExperience integrating Elasticsearch with external systems (e.g.SOAR tools, Threat Intel Platforms)Experience with data management :hot / warm / cold architectures, shard allocation / re-allocation, snapshots & restorationStrong experience with evaluating existing Elastic clusters, configuration parameters, indexing, search and query performance tuning, security, and cluster administrationExperience integrating Elasticsearch with alternate authentication mechanisms such as SAML, LDAP, and PKIExperience with supporting the Elastic Stack in on-prem and SaaS environments including system monitoring and tuningExperience securing the Elastic stack and hardening hosting environmentsExperience with the design and implement of highly scalable solutions using the Elastic StackExperience in developing data structures, data mapping from various sources to achieve data normalization using Elastic Common SchemaExperience developing Logstash and / or Elastic Ingest PipelinesExperience developing custom visualizations and dashboards using Kibana, including creating specialized reporting solutions through Elasticsearch and Kibana APIs to meet complex stakeholder requirementsExperience in end-to-end Low-level design, development, administration, and delivery of Elasticsearch based reporting solutionsStrong technical foundation in building reliable, scalable, and supportable systemsExperienced in Red Hat Enterprise Linux deployment and administrationDesired Skills :Experience using and developing Ansible playbooks for automation of system deployment and / or configurationExperience with developing in multiple languages (Python, Bash, PowerShell, Painless, etc.).Understanding of the MITRE ATT&CK frameworkCertified Elastic Engineer or willingness to gain certification within 90 days of hireExperience with cloud environments (e.g., Azure, AWS, GCP, etc.) and cloud security architectureExperience condensing large environments to a single pane of glass view to facilitate optimal operational efficiencyExperience leading incident response and forensic investigative initiativesDemonstrated ability to create and present executive level briefingsExperience with Army policies, regulations, and processes preferred. Salary: USD 72000 - 108000 per year

Share Share
Apply Now →