SIEM/Elastic Specialist
After School Matters, Inc.
United States
17 days ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Apply on diligentconsultinginc.applytojob.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source
Tech stack
Data Transformation
Query Languages
DevOps
Security Information and Event Management
Software Vulnerability Management
Cyber Threat Analysis
Splunk
Devsecops
Job description
- Be responsible for designing & setting up the ingestion of various customer data flows to include pre-processing data into a useable format, ensuring proper parsing and indexing
- Collaborate with cross-functional teams and responsible for designing & integrating Elastic with a wide variety of data sources and developing associated knowledge objects such as queries, dashboards, reports, alerts for monitoring and analytics
- Perform data transformation using Elastic query language
- Track the health of the Elastic environment and optimize its performance. Troubleshoot and resolve issues related to security, performance, data indexing, and searches
- Perform watch-officer monitoring duties, including:
- monitoring, detecting, investigating, and responding to cybersecurity threats and events using Elastic /SIEM Platform
- Reviewing correlated alerts and logs for compromise scenarios
- Performing triage of security alerts to prioritize response
- Identifying false positives
- Investigating security incidents and determining root cause
- Collecting and preserving logs for analysis
- Escalating confirmed incidents to leadership or SOC teams
- Coordinating with IT or DevOps for containment and remediation
- Creating after-action reports (AAR) post-incident
- In addition, the role may include assistance with monitoring Vulnerability Management tools, such as ACAS and ePO.
Requirements
- Have at least three years of working knowledge and hands-on experience with Elastic/Splunk query languages, monitoring SIEM dashboards and real-time alerts, fine-tuning SIEM rules to reduce noise, and NIST 800-53 & DevSecOps frameworks
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on diligentconsultinginc.applytojob.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
DS
Dhannush Subramani
about 4 years ago
CH
Chris Heilmann
Dev Digest 134 - Where pixels sing?
almost 2 years ago
IK
Igor Khokhriakov
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
24 days ago
CH
Chris Heilmann
Dev Digest 138 - Are you secure about this?
almost 2 years ago
KD
Krissy Davis
Best Coding Boot Camps in Germany
over 3 years ago
DC
Daniel Cranney
Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents
10 months ago