USIEM Elastic Engineer
Role details
Job location
Tech stack
Job description
Everforth ECS is hiring for USIEM Elastic Engineer in multiple locations with a preference for candidates in one of the following locations: Schofield Barracks (USAG), HI; Augusta, GA; or, Sierra Vista, AZ. Depending on the location, the position may require ~25% in-office, onsite work to meet customer requirements and operational needs.
As a leading provider of managed cybersecurity services, ECS provides a highly tailored and customized offering to each customer. Our team is responsible for protecting both our customers and corporate environment at ECS. Our mission is very broad, and our team is agile. We will look toward your unique skills to approach and solve problems in your own way. Whether engineering a system to address a technical hurdle, protecting customers data or consulting on a wide range of security topics. You are empowered to engage and lead across multiple groups.
This role of USIEM Elastic Engineer will support ECS's AESS program. This is a technical hands-on role to which you will be responsible for working within a multi-disciplined team to design, build, secure, maintain, optimize, and document multiple Elastic Stack Enterprise solutions (Elasticsearch, Logstash, Kibana, Beats, ML, SIEM) deployed globally in a Federal DoD environment, along with support using Ansible playbook. Additionally, you will perform continuous data normalization support functions and support the delivery of written technical deliverables such as SOPs and/or process workflows to optimize tool usage and contribute to new capabilities. Your infrastructure, data pipelines and reporting automation will directly support internal engineering personnel and external customer requirements.
Requirements
- Compliance with DoD 8140 / 8570 IAT Level II certification prior to start date
- At least 4 years' hands-on experience in deployment, configuration, and solution development using the Elastic Stack for security and logging use-cases. Specific experience with Elastic SIEM is plus
- Demonstrated experience with the full Elastic Stack - Elasticsearch, Logstash, Kibana, Beats, Machine Learning, and REST API integration
- Demonstrated ability to utilize Ansible Playbook