Elastic SIEM Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
Design, operate, and continuously enhance an Elastic-based SIEM by ingesting and normalizing diverse security telemetry, building advanced detections and dashboards, and enabling SOC teams to detect, investigate, and respond to threats in a classified federal environment
Requirements
3+ years administering Elastic Stack in security/SIEM environments
Deep experience with Elasticsearch lifecycle management, ECS-based log normalization, and Kibana security analytics
Hands-on with Elastic Security detections, alerting, and case workflows
Proven ability to design and operate log ingestion pipelines across network, endpoint, identity, and cloud sources
Experience supporting DoD, IC, or federal SOC/SIEM operations
Familiarity with AI/ML-driven security analytics (anomaly detection, behavioral analysis, threat scoring)
Active Secret clearance, bachelor’s degree, on-site availability, up to 25% travel
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on dejobs.orgGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Dev Digest 138 - Are you secure about this?
Dev Digest 121 - AI goes offline
Fully Remote Software Engineer Jobs
Dev Digest 164: AI Agents, AI Blindspots and MCP security problems