> Markdown version of [/jobs/ext/3610074-elastic-siem-platform-engineer](https://www.wearedevelopers.com/jobs/ext/3610074-elastic-siem-platform-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Elastic SIEM Platform Engineer - **Company:** TekSynap Corporation - **Location:** Fort Belvoir, VA, United States - **Experience:** Experienced - **Salary:** $170,000.0 - $210,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Elastic Compute Cloud, Systems Engineering, Cyber Security, Elasticsearch, Information Lifecycle Management, Intrusion Detection and Prevention, Python (Programming Language), Network Security, Linux System Administration, Network Forensics, Performance Tuning, Windows PowerShell, Role-Based Access Control, Red Hat Enterprise Linux, Cloud Services, Logstash, Shell Script, Security Information and Event Management, Data Streaming, Systems Integration, SSL Certificate Management, Mitre Att&ck, Cyber Threat Analysis, SC Clearance, Kubernetes, Infrastructure Automation Frameworks, Cybercrime, Bare Metal, Kibana, Cyber Warfare, Splunk, Docker - **Published:** October 7, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9221401/elastic-siem-platform-engineer ## About the Role * Five or more years of experience in cybersecurity, systems engineering, network engineering, or a closely related technical field. * Two or more years of hands-on experience engineering or operating Elastic Stack environments, or equivalent experience demonstrating the ability to perform the responsibilities of this role. * Practical experience with Elasticsearch cluster architecture, Kibana, Fleet, Elastic Agents, ingest pipelines, data lifecycle management, monitoring, and troubleshooting. * Experience securing enterprise platforms with TLS, certificates, identity integration, role-based access, and logical data separation. * Linux administration experience, preferably Red Hat Enterprise Linux, and working knowledge of platform tuning such as vm.max_map_count, ulimits, memory, storage, and swap settings. * Experience supporting DoD, federal, classified, or otherwise highly regulated environments and applying RMF, STIG, and NIST security controls. * Experience supporting DoD CSSP or comparable SOC operations across multiple network enclaves. * Ability to communicate technical issues clearly, work directly with customers, document solutions, and operate effectively during time-sensitive migration and cutover activities. * Active Secret clearance and ability to maintain required access. Candidates supporting JWICS activities must be eligible for the applicable TS/SCI access. * Ability to travel regularly to Fort Belvoir, Virginia, including on short notice when required for customer access, classified work, testing, or operational milestones. Certification and Training Qualifications * Elastic Certified Engineer is strongly preferred at the time of hire. * Candidates who have completed official Elasticsearch Engineer training and possess substantial hands-on Elastic engineering experience may be considered in lieu of the certification, provided they can obtain Elastic Certified Engineer within 90 days of hire or assignment. * Elastic Certified Analyst and Elastic Certified Observability Engineer are preferred and may be obtained after assignment based on program needs. * DoD 8140 or 8570-aligned baseline certification, such as Security+ or an approved higher-level certification, is preferred or must be obtained as required by the assigned position category. Preferred Qualifications * Residence within commuting distance of Fort Belvoir or the National Capital Region. * Active TS/SCI clearance and prior work on SIPRNet or JWICS. * Experience with Elastic self-managed, bare metal, Elastic Cloud Enterprise, Elastic Cloud on Kubernetes, Docker, Kubernetes, or hybrid on-premises and cloud deployments. * Experience migrating SIEM content or security operations from Splunk to Elastic, including SPL analysis, field normalization, ECS mapping, dashboards, detections, and SOAR workflows. * Experience with high-volume security data, searchable snapshots, object storage, backup and recovery, and multi-site resilience. * Defensive cyber operations, incident response, network security analytics, threat hunting, memory or network forensics, and detection engineering experience. * Python, PowerShell, shell scripting, API integration, or infrastructure automation experience. * Experience delivering technical instruction, operational briefings, and knowledge transfer to government teams. Expected Outcomes * Operational, secure, and supportable Elastic Security capabilities across authorized Agency environments. * Reliable ingestion and normalized security telemetry with validated dashboards, detections, alerts, and analyst workflows. * Documented configuration, testing, troubleshooting, operating procedures, and knowledge transfer supporting migration, cutover, and sustainment., While performing the duties of this job, the employee is regularly required to use hands to handle, feel, touch; reach with hands and arms; talk and hear. The employee is regularly required to stand; walk; sit; climb or balance; and stoop, kneel, crouch, or crawl. The employee is regularly required to lift up to 10 pounds. The employee is frequently required to lift up to 25 pounds; and up to 50 pounds. The vision requirements include close vision, distance vision, peripheral vision, depth perception, and ability to adjust focus. WORK AUTHORIZATION/SECURITY CLEARANCE * Active United States Citizenship is required. * Must possess a minimum of a DOD Secret Clearance. ## Description The Elastic Cyber Defense Platform Engineer will support the migration from Splunk to an enterprise Elastic Security platform and the continued operation and improvement of that environment. The engineer will help design, deploy, secure, integrate, and sustain Elastic capabilities across three network enclaves while preserving continuous cyber defense operations. This hands-on engineering role requires close coordination with customer stakeholders, cybersecurity analysts, infrastructure teams, and program leadership., * Design, deploy, configure, upgrade, and sustain self-managed Elastic Stack environments, including Elasticsearch, Kibana, Fleet, Elastic Agents, Beats, Logstash, and related integrations. * Support the phased migration of priority data sources, searches, dashboards, detections, alerts, and analyst workflows from Splunk to Elastic Security. * Build and troubleshoot ingest pipelines, parsers, index templates, data streams, mappings, and Index Lifecycle Management policies for high-volume security telemetry. * Monitor and tune cluster health, capacity, performance, availability, shard allocation, retention, snapshots, and recovery processes. * Implement secure access and data protection controls, including TLS or mTLS, certificate management, CAC or enterprise identity integration, role-based access control, Kibana spaces, and data segregation. * Develop and refine dashboards, detection rules, alerting, and threat-hunting content aligned to mission use cases and MITRE ATT&CK. * Integrate Elastic with endpoint, network, vulnerability, identity, ticketing, and security automation technologies used by the Agency CSSP. * Support deployment and troubleshooting in disconnected, air-gapped, and classified environments, including offline repositories and controlled software transfer processes. * Participate in customer workshops, testing, dual-run validation, cutover, and post-migration optimization at Fort Belvoir and other approved locations. * Produce architecture, configuration, test, operating, troubleshooting, and knowledge-transfer documentation; train government and contractor personnel as required.