> Markdown version of [/jobs/ext/1055509-security-analyst](https://www.wearedevelopers.com/jobs/ext/1055509-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Analyst - **Company:** CCS, LLC - **Location:** San Francisco, CA, United States - **Experience:** Expert - **Salary:** $120,000.0 - $140,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Elastic Compute Cloud, Data Analysis, Cyber Security, Elasticsearch, Monitoring of Systems, Intrusion Detection and Prevention, Logstash, Security Information and Event Management, Data Logging, Kubernetes, Kibana, Splunk - **Published:** June 30, 2026 - **Apply:** https://www.dice.com/job-detail/d1bd26d0-652e-4b4e-97bc-18d9b36ccc00 ## About the Role Active Secret Security Clearance. 3+ years of experience in cybersecurity, security operations, or security monitoring environments. Experience working with SIEM or log management platforms such as Splunk, Elastic, or similar technologies. Experience creating dashboards, visualizations, and operational reporting. Understanding of cybersecurity principles, threat detection, and incident response processes. Strong analytical and troubleshooting skills. Ability to work effectively in a collaborative, onsite environment. Preferred Qualifications Experience with Elastic Stack (Elasticsearch, Kibana, Beats, Logstash). Experience supporting Elastic Cloud on Kubernetes (ECK). Previous involvement in SIEM migration or modernization efforts. Experience supporting Department of Defense or Federal Government environments. Familiarity with security architecture concepts and enterprise monitoring frameworks. ## Description We are seeking a Security Analyst to support a critical cybersecurity and monitoring initiative at Scott Air Force Base. This individual will play a key role in the organization's transition from Splunk to the Elastic ecosystem, helping establish and maintain monitoring capabilities, dashboards, and security visibility across enterprise environments. The ideal candidate will have hands-on experience with security monitoring platforms, log aggregation, and dashboard development, along with a strong understanding of cybersecurity operations and incident detection. This position will work closely with security architects, infrastructure teams, and program stakeholders to ensure successful implementation and ongoing operational support of Elastic-based monitoring solutions., Support the migration of security monitoring and logging capabilities from Splunk to the Elastic platform. Configure, monitor, and maintain Elastic deployments, including Elastic Cloud on Kubernetes (ECK) environments. Develop and maintain dashboards, visualizations, and reporting capabilities to support security operations and leadership visibility. Analyze security events, logs, and system activity to identify potential threats, vulnerabilities, and anomalous behavior. Collaborate with Security Architects and engineering teams to implement monitoring strategies and security best practices. Assist with tuning alerts, correlation rules, and detection mechanisms to improve operational effectiveness. Support incident response efforts through data analysis and investigative activities. Document processes, configurations, and operational procedures related to monitoring and security analytics. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Debug a Kubernetes Operator](https://www.wearedevelopers.com/videos/487-debug-a-kubernetes-operator) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Add Location-based Searching to Site with ElasticSearch](https://www.wearedevelopers.com/videos/77-add-location-based-searching-to-site-with-elasticsearch) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Serverless Observability: where SLOs meet transforms](https://www.wearedevelopers.com/videos/854-serverless-observability-where-slos-meet-transforms) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Top Big Data Technologies That You Need to Know](https://www.wearedevelopers.com/magazine/108-top-big-data-technologies-that-you-need-to-know) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)