SIEM/Elastic Specialist

After School Matters, Inc.
United States
17 days ago
Apply on diligentconsultinginc.applytojob.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours

Tech stack

Data Transformation Query Languages DevOps Security Information and Event Management Software Vulnerability Management Cyber Threat Analysis Splunk Devsecops

Job description

  • Be responsible for designing & setting up the ingestion of various customer data flows to include pre-processing data into a useable format, ensuring proper parsing and indexing
  • Collaborate with cross-functional teams and responsible for designing & integrating Elastic with a wide variety of data sources and developing associated knowledge objects such as queries, dashboards, reports, alerts for monitoring and analytics
  • Perform data transformation using Elastic query language
  • Track the health of the Elastic environment and optimize its performance. Troubleshoot and resolve issues related to security, performance, data indexing, and searches
  • Perform watch-officer monitoring duties, including:
  • monitoring, detecting, investigating, and responding to cybersecurity threats and events using Elastic /SIEM Platform
  • Reviewing correlated alerts and logs for compromise scenarios
  • Performing triage of security alerts to prioritize response
  • Identifying false positives
  • Investigating security incidents and determining root cause
  • Collecting and preserving logs for analysis
  • Escalating confirmed incidents to leadership or SOC teams
  • Coordinating with IT or DevOps for containment and remediation
  • Creating after-action reports (AAR) post-incident
  • In addition, the role may include assistance with monitoring Vulnerability Management tools, such as ACAS and ePO.

Requirements

  • Have at least three years of working knowledge and hands-on experience with Elastic/Splunk query languages, monitoring SIEM dashboards and real-time alerts, fine-tuning SIEM rules to reduce noise, and NIST 800-53 & DevSecOps frameworks

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on diligentconsultinginc.applytojob.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · World Congress 2026 Europe

1:09 min

Core functions of security information and event monitoring

Mathias Palmersheim Mathias Palmersheim · Europe 2026 Virtual

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

Videos

See all

Related articles

See all