Sr Security Analyst

CCS, LLC
Scott Air Force Base, IL, United States
about 2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Compensation
$120,000.0 - $140,000.0
Working hours
Regular working hours

Tech stack

Amazon Elastic Compute Cloud Data Analysis Cyber Security Elasticsearch Monitoring of Systems Intrusion Detection and Prevention Logstash Security Information and Event Management Data Logging Kubernetes Kibana Splunk

Job description

We are seeking a Security Analyst to support a critical cybersecurity and monitoring initiative at Scott Air Force Base. This individual will play a key role in the organization’s transition from Splunk to the Elastic ecosystem, helping establish and maintain monitoring capabilities, dashboards, and security visibility across enterprise environments.

The ideal candidate will have hands-on experience with security monitoring platforms, log aggregation, and dashboard development, along with a strong understanding of cybersecurity operations and incident detection. This position will work closely with security architects, infrastructure teams, and program stakeholders to ensure successful implementation and ongoing operational support of Elastic-based monitoring solutions., Support the migration of security monitoring and logging capabilities from Splunk to the Elastic platform. Configure, monitor, and maintain Elastic deployments, including Elastic Cloud on Kubernetes (ECK) environments. Develop and maintain dashboards, visualizations, and reporting capabilities to support security operations and leadership visibility. Analyze security events, logs, and system activity to identify potential threats, vulnerabilities, and anomalous behavior. Collaborate with Security Architects and engineering teams to implement monitoring strategies and security best practices. Assist with tuning alerts, correlation rules, and detection mechanisms to improve operational effectiveness. Support incident response efforts through data analysis and investigative activities. Document processes, configurations, and operational procedures related to monitoring and security analytics.

Requirements

Active Secret Security Clearance. 3+ years of experience in cybersecurity, security operations, or security monitoring environments. Experience working with SIEM or log management platforms such as Splunk, Elastic, or similar technologies. Experience creating dashboards, visualizations, and operational reporting. Understanding of cybersecurity principles, threat detection, and incident response processes. Strong analytical and troubleshooting skills. Ability to work effectively in a collaborative, onsite environment.

Preferred Qualifications Experience with Elastic Stack (Elasticsearch, Kibana, Beats, Logstash). Experience supporting Elastic Cloud on Kubernetes (ECK). Previous involvement in SIEM migration or modernization efforts. Experience supporting Department of Defense or Federal Government environments. Familiarity with security architecture concepts and enterprise monitoring frameworks.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:31 min

Exploring the core components of the ELK stack

Derek Binkley · LIVE

6:51 min

Audience questions on cloud security and operational capacity

Steffen Heilmann · WWC 2021

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

3:21 min

Deploying a primary Elasticsearch and Kibana cluster configuration

Philipp Krenn · WWC 2022

1:53 min

Transitioning toward DevSecOps with dynamic scanning and secrets management

Christoph Ruggenthaler · LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

Videos

See all

Related articles

See all