Elastic Engineer (EDR/Defend)

INNOVIM, LLC
Redstone Arsenal, AL, United States
12 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
1 year minimum
Compensation
$110,000.0 - $150,000.0
Working hours
Regular working hours

Tech stack

Microsoft Windows Amazon Web Services Microsoft Azure Bash Shell Cloud Computing Cyber Security Shard (Database Architecture) Linux Elasticsearch Information Lifecycle Management Intrusion Detection and Prevention Python (Programming Language)
+18 more
Windows Servers Network Protocols Performance Tuning Windows PowerShell Logstash Ansible Security Information and Event Management Scripting Google Cloud Data Ingestion Cyber Threat Analysis Indexer Containerization Kubernetes Puppet Kibana Data Pipelines Docker

Job description

Be a key contributor to the design, implementation, and maintenance of our Elastic Stack environment, with a primary focus on leveraging Elastic EDR and Defend capabilities to enhance our cybersecurity posture. Be responsible for ensuring the security, scalability, and performance of our Elastic Stack infrastructure, and will work closely with other teams to integrate it with existing security tools and workflows., Architect, deploy, and maintain a highly available and scalable Elastic Stack environment, specializing in Elastic EDR/ Defend. Configure and optimize Elastic EDR/Defend policies and data pipelines for threat detection, prevention, and security event enrichment. Develop and maintain Kibana dashboards and visualizations for real-time security monitoring, threat identification, and incident response tracking. Perform proactive threat hunting and in-depth security analysis using Elastic EDR/Defend capabilities. Troubleshoot complex Elastic Stack issues, develop comprehensive documentation, and mentor junior engineers to ensure operational excellence.

Requirements

Expert knowledge of the Elastic Stack (Elasticsearch, Logstash, Kibana) Expert knowledge of Elastic EDR and Defend capabilities Strong understanding of data indexing, sharding, replication, and data lifecycle management. Strong understanding of Linux and Windows operating systems Strong understanding of security principles, threat detection, and incident response. Knowledge of common coding flaws and security vulnerabilities. Knowledge of network protocols and security concepts. Knowledge of security frameworks and compliance standards (e.g., NIST, FedRAMP). Ability to interpret and incorporate data from multiple tool sources. Ability to analyze complex requirements and translate them into clear, actionable tasks. Ability to work independently and as part of a team. Excellent communication and interpersonal skills.

Basic Requirements: Must have 10, or more, years of general (full-time) work experience May be reduced with completion of advanced education Must have 5, or more, years of experience working with the Elastic Stack (Elasticsearch, Logstash, Kibana). Must have 3, or more, years of experience specifically implementing and managing Elastic EDR and Defend solutions. Must have 2, or more, years of experience in a lead or senior role, mentoring and guiding other team members. Must have 1, or more, years of experience working in a management or leadership role Must have a strong understanding of security principles, threat detection, and incident response. Must have experience with data ingestion, processing, and enrichment techniques. Must be proficient in at least one scripting language (e.g., Python, Bash, PowerShell). Must have a current DoD 8570.01-M IAT Level II certification with Continuing Education (CE) - (CCNA-Security, CySA+, GICSP, GSEC, Security+ CE, CND, SSCP) Must have an active DoD Secret Security Clearance Must be able to obtain an active DoD Top Secret Security Clearance

Desired Requirements: Have experience with Linux and Windows Server administration. Have experience with containerization technologies (Docker, Kubernetes). Have experience with automation tools (Ansible, Puppet, Chef). Have experience with cloud platforms (AWS, Azure, GCP). Have experience with SIEM technologies and security event management. Have experience with security frameworks and compliance standards (e.g., NIST, FedRAMP). Have a strong understanding of network protocols and security concepts. Have experience with threat intelligence platforms and data feeds. Have 1, or more, relevant security certifications (e.g., CISSP, CISM, CEH). Have experience tuning and optimizing Elastic EDR and Defend for specific threat landscapes.

Benefits & conditions

This position is expected to pay $ 110,000 - $ 150,000 annually; depending on experience, education, and any certifications that are directly related to the position.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:20 min

Identifying multi-disciplinary talent for developer experience engineering roles

Hazal Mestci +1 · Coffee With Developers

3:21 min

Deploying a primary Elasticsearch and Kibana cluster configuration

Philipp Krenn · WWC 2022

2:26 min

Understanding Puppeteer and its underlying architectural design

Miki Lombardi · JS Congress

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

1:24 min

Evaluating formal AWS certifications versus raw practical engineering experience

Jan Giacomelli · LIVE

4:51 min

Executing simple full-text search queries using the Kibana interface

Derek Binkley · LIVE

Videos

See all

Related articles

See all