Elastic SIEM Engineer

Insight Global
Hampton, VA, United States
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$104,000.0 - $145,600.0
Working hours
Regular working hours
Job source

Tech stack

Artificial Intelligence Elasticsearch Machine Learning Security Information and Event Management Data Ingestion SC Clearance Kibana

Job description

Design, operate, and continuously enhance an Elastic-based SIEM by ingesting and normalizing diverse security telemetry, building advanced detections and dashboards, and enabling SOC teams to detect, investigate, and respond to threats in a classified federal environment

Requirements

3+ years administering Elastic Stack in security/SIEM environments

Deep experience with Elasticsearch lifecycle management, ECS-based log normalization, and Kibana security analytics

Hands-on with Elastic Security detections, alerting, and case workflows

Proven ability to design and operate log ingestion pipelines across network, endpoint, identity, and cloud sources

Experience supporting DoD, IC, or federal SOC/SIEM operations

Familiarity with AI/ML-driven security analytics (anomaly detection, behavioral analysis, threat scoring)

Active Secret clearance, bachelor’s degree, on-site availability, up to 25% travel

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dejobs.org

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:21 min

Deploying a primary Elasticsearch and Kibana cluster configuration

Philipp Krenn · WWC 2022

1:09 min

Core functions of security information and event monitoring

Mathias Palmersheim Mathias Palmersheim · Europe 2026 Virtual

2:34 min

Understanding the fundamentals of the Elasticsearch engine

Derek Binkley · LIVE

1:31 min

Exploring the core components of the ELK stack

Derek Binkley · LIVE

4:51 min

Executing simple full-text search queries using the Kibana interface

Derek Binkley · LIVE

1:13 min

Defining indexes and documents in the Elasticsearch data structure

Derek Binkley · LIVE

Videos

See all

Related articles

See all