Elastic SIEM Platform Engineer

TekSynap Corporation
Fort Belvoir, VA, United States
2 days ago
Apply on www.clearancejobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Compensation
$170,000.0 - $210,000.0
Working hours
Shift work

Tech stack

Amazon Elastic Compute Cloud Systems Engineering Cyber Security Elasticsearch Information Lifecycle Management Intrusion Detection and Prevention Python (Programming Language) Network Security Linux System Administration Network Forensics Performance Tuning Windows PowerShell
+20 more
Role-Based Access Control Red Hat Enterprise Linux Cloud Services Logstash Shell Script Security Information and Event Management Data Streaming Systems Integration SSL Certificate Management Mitre Att&ck Cyber Threat Analysis SC Clearance Kubernetes Infrastructure Automation Frameworks Cybercrime Bare Metal Kibana Cyber Warfare Splunk Docker

Job description

The Elastic Cyber Defense Platform Engineer will support the migration from Splunk to an enterprise Elastic Security platform and the continued operation and improvement of that environment. The engineer will help design, deploy, secure, integrate, and sustain Elastic capabilities across three network enclaves while preserving continuous cyber defense operations. This hands-on engineering role requires close coordination with customer stakeholders, cybersecurity analysts, infrastructure teams, and program leadership., * Design, deploy, configure, upgrade, and sustain self-managed Elastic Stack environments, including Elasticsearch, Kibana, Fleet, Elastic Agents, Beats, Logstash, and related integrations.

  • Support the phased migration of priority data sources, searches, dashboards, detections, alerts, and analyst workflows from Splunk to Elastic Security.
  • Build and troubleshoot ingest pipelines, parsers, index templates, data streams, mappings, and Index Lifecycle Management policies for high-volume security telemetry.
  • Monitor and tune cluster health, capacity, performance, availability, shard allocation, retention, snapshots, and recovery processes.
  • Implement secure access and data protection controls, including TLS or mTLS, certificate management, CAC or enterprise identity integration, role-based access control, Kibana spaces, and data segregation.
  • Develop and refine dashboards, detection rules, alerting, and threat-hunting content aligned to mission use cases and MITRE ATT&CK.
  • Integrate Elastic with endpoint, network, vulnerability, identity, ticketing, and security automation technologies used by the Agency CSSP.
  • Support deployment and troubleshooting in disconnected, air-gapped, and classified environments, including offline repositories and controlled software transfer processes.
  • Participate in customer workshops, testing, dual-run validation, cutover, and post-migration optimization at Fort Belvoir and other approved locations.
  • Produce architecture, configuration, test, operating, troubleshooting, and knowledge-transfer documentation; train government and contractor personnel as required.

Requirements

  • Five or more years of experience in cybersecurity, systems engineering, network engineering, or a closely related technical field.
  • Two or more years of hands-on experience engineering or operating Elastic Stack environments, or equivalent experience demonstrating the ability to perform the responsibilities of this role.
  • Practical experience with Elasticsearch cluster architecture, Kibana, Fleet, Elastic Agents, ingest pipelines, data lifecycle management, monitoring, and troubleshooting.
  • Experience securing enterprise platforms with TLS, certificates, identity integration, role-based access, and logical data separation.
  • Linux administration experience, preferably Red Hat Enterprise Linux, and working knowledge of platform tuning such as vm.max_map_count, ulimits, memory, storage, and swap settings.
  • Experience supporting DoD, federal, classified, or otherwise highly regulated environments and applying RMF, STIG, and NIST security controls.
  • Experience supporting DoD CSSP or comparable SOC operations across multiple network enclaves.
  • Ability to communicate technical issues clearly, work directly with customers, document solutions, and operate effectively during time-sensitive migration and cutover activities.
  • Active Secret clearance and ability to maintain required access. Candidates supporting JWICS activities must be eligible for the applicable TS/SCI access.
  • Ability to travel regularly to Fort Belvoir, Virginia, including on short notice when required for customer access, classified work, testing, or operational milestones.

Certification and Training Qualifications

  • Elastic Certified Engineer is strongly preferred at the time of hire.
  • Candidates who have completed official Elasticsearch Engineer training and possess substantial hands-on Elastic engineering experience may be considered in lieu of the certification, provided they can obtain Elastic Certified Engineer within 90 days of hire or assignment.
  • Elastic Certified Analyst and Elastic Certified Observability Engineer are preferred and may be obtained after assignment based on program needs.
  • DoD 8140 or 8570-aligned baseline certification, such as Security+ or an approved higher-level certification, is preferred or must be obtained as required by the assigned position category.

Preferred Qualifications

  • Residence within commuting distance of Fort Belvoir or the National Capital Region.
  • Active TS/SCI clearance and prior work on SIPRNet or JWICS.
  • Experience with Elastic self-managed, bare metal, Elastic Cloud Enterprise, Elastic Cloud on Kubernetes, Docker, Kubernetes, or hybrid on-premises and cloud deployments.
  • Experience migrating SIEM content or security operations from Splunk to Elastic, including SPL analysis, field normalization, ECS mapping, dashboards, detections, and SOAR workflows.
  • Experience with high-volume security data, searchable snapshots, object storage, backup and recovery, and multi-site resilience.
  • Defensive cyber operations, incident response, network security analytics, threat hunting, memory or network forensics, and detection engineering experience.
  • Python, PowerShell, shell scripting, API integration, or infrastructure automation experience.
  • Experience delivering technical instruction, operational briefings, and knowledge transfer to government teams.

Expected Outcomes

  • Operational, secure, and supportable Elastic Security capabilities across authorized Agency environments.
  • Reliable ingestion and normalized security telemetry with validated dashboards, detections, alerts, and analyst workflows.
  • Documented configuration, testing, troubleshooting, operating procedures, and knowledge transfer supporting migration, cutover, and sustainment., While performing the duties of this job, the employee is regularly required to use hands to handle, feel, touch; reach with hands and arms; talk and hear. The employee is regularly required to stand; walk; sit; climb or balance; and stoop, kneel, crouch, or crawl. The employee is regularly required to lift up to 10 pounds. The employee is frequently required to lift up to 25 pounds; and up to 50 pounds. The vision requirements include close vision, distance vision, peripheral vision, depth perception, and ability to adjust focus.

WORK AUTHORIZATION/SECURITY CLEARANCE

  • Active United States Citizenship is required.
  • Must possess a minimum of a DOD Secret Clearance.

Benefits & conditions

We offer our full-time employees a competitive benefits package to include health, dental, vision, 401K, life insurance, short-term and long-term disability plans, vacation time and holidays., Target salary range: $170,000.00 - $210,000.00. The salary range displayed is an estimate only and is not a guarantee of compensation or salary, and will be determined on several factors regarding the individual’s particular combination of education, knowledge, skills, competencies and experience, as well as contract parameters and organizational requirements. The displayed salary is one component of the total compensation package for employees.

About the company

TekSynap is a fast-growing high-tech company that understands both the pace of technology today and the need to have a comprehensive well planned information management environment. ā€œTechnology moving at the speed of thoughtā€ embodies these principles - the need to nimbly utilize the best that information technology offers to meet the business needs of our Federal Government customers.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com
Prepare application

Good distractions

Loading talks and stories from around this role…