Senior Elastic SIEM Migration Engineer

Marathon TS Inc
Quantico, VA, United States
3 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
4 years minimum
Compensation
$185,000.0 - $220,000.0
Working hours
Regular working hours
Job source

Tech stack

Amazon Elastic Compute Cloud Bash Shell Cyber Security Elasticsearch Intrusion Detection and Prevention Python (Programming Language) Windows PowerShell Security Information and Event Management Kubernetes Kibana Splunk Data Pipelines

Job description

Marathon TS is seeking a highly skilled Splunk to Elastic Migration Engineer to lead and execute end-to-end SIEM modernization initiatives. This role is responsible for designing and implementing Elastic deployments using the Elastic Cloud on Kubernetes (ECK) model, migrating legacy Splunk knowledge objects, detections, and data pipelines, and ensuring operational readiness through cutover validation and workflow integrations. The ideal candidate has deep hands-on experience with SIEM engineering, detection engineering, Elastic Stack architecture, and security operations workflows-particularly within enterprise or federal environments.

Requirements

Do you have experience in Splunk?, Do you have a Bachelor’s degree?, * 5+ years’ experience in SIEM engineering or security operations

  • Hands-on experience with Elastic Stack (Elasticsearch, Kibana, Elastic Security)
  • Proven experience migrating from Splunk to Elastic or similar SIEM platforms
  • Strong understanding of:SIEM data models and schemas
  • Elastic Common Schema (ECS) Field Mappings
  • Detection engineering and alert tuning
  • Experience with Kubernetes and the ECK deployment model
  • Strong scripting or automation skills (Python, Bash, etc.)
  • Provide post-cutover from legacy platforms to Elastic, ensuring continuity of operations
  • Migrate an existing Splunk SIEM environment (approximately 6 TB/day of data) to Elastic SIEM.
  • Active TS clearance, * Bachelor’s (Required), * Elastic Stack: 5 years (Required)
  • supported a SIEM migration: 5 years (Required)
  • Python, Bash, PowerShell, or similar tools: 4 years (Required)

Security clearance:

  • Top Secret (Required)

Benefits & conditions

Pulled from the full job description

  • Opportunities for advancement, Marathon TS is committed to the development of a creative, diverse and inclusive work environment. In order to provide equal employment and advancement opportunities to all individuals, employment decisions at Marathon TS will be based on merit, qualifications, and abilities. Marathon TS does not discriminate against any person because of race, color, creed, religion, sex, national origin, disability, age or any other characteristic protected by law (referred to as ā€œprotected statusā€).

Pay: $185,000.00 - $220,000.00 per year

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:21 min

Deploying a primary Elasticsearch and Kibana cluster configuration

Philipp Krenn Ā· World Congress 2022

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 Ā· LIVE

3:52 min

Avoiding remote code execution from unsanitized inputs

Alexander Pirker Ā· World Congress 2022

4:36 min

Hiring passionate software engineers to tackle unprecedented scaling challenges

Dana Lawson Dana Lawson +1 Ā· World Congress 2026 Europe

4:51 min

Executing simple full-text search queries using the Kibana interface

Derek Binkley Ā· LIVE

3:09 min

Balancing data science skillings alongside systems engineering rigor

Nico Schmidt Ā· LIVE

Videos

See all

Related articles

See all