Elastic SIEM Engineer

ASRC FEDERAL
Elkridge, United States of America
yesterday

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Shift work
Languages
English
Experience level
Intermediate
Compensation
$ 165K

Job location

Remote
Elkridge, United States of America

Tech stack

Amazon Web Services (AWS)
Azure
Bash
CompTIA Security+
Computer Security
Computer Networks
Data Transformation
DNS
Elasticsearch
Identity and Access Management
Networking Hardware
Intrusion Detection and Prevention
Intrusion Detection Systems
Python
Log Files
Networking Basics
Logstash
Security Information and Event Management
Systems Integration
Scripting (Bash/Python/Go/Ruby)
Google Cloud Platform
Data Ingestion
System Availability
Indexer
SC Clearance
Kibana
Data Pipelines

Job description

ASRC Federal is actively hiring an Elastic SIEM Engineer in support of our Defense Counterintelligence Security Agency (DCSA) program based out of Hanover MD.

Remote flexibility available! Telework offered with a requirement to be onsite up to one (1) day a week at Hanover, MD., As an Elastic SIEM Engineer, your primary duty is to maintain enterprise-scale Elastic Stack security solutions that safeguard our national security systems. You will design and implement advanced detection rules, correlation searches, and analytics pipelines using Elasticsearch, Logstash, Kibana, and Elastic Security to identify sophisticated threats and adversary activity. A key part of your role involves optimizing data ingestion pipelines from diverse sources including cloud platforms (AWS, Azure, GCP), network devices, endpoints, and security tools, ensuring high availability, performance, and scalability of the SIEM infrastructure. You will develop custom dashboards, visualizations, and threat hunting workbenches that empower SOC analysts to detect and respond to incidents effectively, while collaborating with security operations, engineering teams, and government stakeholders to enhance detection capabilities. Additionally, you will be responsible for tuning detection logic to reduce false positives, automating security workflows, integrating threat intelligence feeds, and ensuring all activities align with critical compliance standards like NIST 800-53 and RMF through comprehensive documentation and technical leadership.

Requirements

  • At least five (5) Years - Direct Elastic engineering/administration experience
  • Active Secret Clearance REQUIRED, eligible to be upgraded to TS/SCI
  • Bachelor's degree in information security or related field and/or equivalent combination of experience
  • Certifications:
  • Must meet DoD 8140/8570 IAM or IAT Level II certifications' requirements at the time of hire by having one of the following certifications. (CCNA Security, CySA +, GICSP, GSEC, Security+, SSSP, CAP, CASP CE, CISM, CISSP (or Associate) or GSLC
  • Highly Desired:
  • Two (2) plus years of AWS experience

Basic Qualifications:

  • Experience in the support and maintenance of an Elastic infrastructure in a highly available configuration in an AWS Cloud environment

  • Proven experience as an Elastic Engineer or similar role

  • Strong understanding of Elastic architecture in a cloud environment, including data ingestion, indexing, search, and visualization

  • Prior experience customizing and configuring Elastic environments according to client needs, including developing scripts and apps as necessary

  • Proficiency in scripting languages such as Python or Bash for Elastic app and dashboard development

  • Experience with data transformation and normalization to ensure compatibility with Elastic

  • Troubleshoot Elastic indexers, search heads and forwarder problems

  • Familiarity with networking principles and protocols

  • Excellent problem-solving skills and the ability to work under pressure

  • Strong communication and interpersonal skills, with the ability to explain technical concepts to non-technical stakeholders

  • Experience analyzing log files from network traffic logs, firewall logs, IDS logs, DNS logs and ESS to ID possible security threats e.g., determine rogue systems, infected systems, unauthorized system changes and unauthorized hardware connections

  • Work Environment and Physical Demands

  • This is primarily a Telework position with a requirement to be onsite up to two (2) days a week at Fort Meade, MD

  • If alternate worksite is other than DCSA facilities or corporate office space, must have the reliable ability to communicate over voice (cell phone preferred) and stable, capable internet connection

  • Must be able to work flexible hours to support critical security incidents, maintenance windows, and emergency response activities as needed

We invest in the lives of our employees, both in and out of the workplace, by providing competitive pay and benefits packages. Benefits offered may include health care, dental, vision, life insurance; 401(k); education assistance; paid time off including PTO, holidays, and any other paid leave required by law. The salary offered will depend on several factors including, but not limited to, relevant experience, skills, education, geographic location, internal equity, business needs, and other factors permitted by law. Posted pay ranges are a general guideline only and are not a guarantee of compensation or salary.

Benefits & conditions

We invest in the lives of our employees, both in and out of the workplace, by providing competitive pay and benefit packages. This position is offering a pay range of $150,000.00 - $165,450.00 depending on experience, seniority, geographic locations, and factors permitted by law. Benefits offered may include health care, dental, vision, life insurance; 401k; education assistance; paid time off including Paid Time Off, holidays and any other paid leave required by law.

About the company

Hanover Maryland 26197 ASRC Federal, ASRC Federal is a leading government contractor furthering missions in space, public health and defense. As an Alaska Native owned corporation, our work helps secure an enduring future for our shareholders. Join our team and discover why we are a top veteran employer and Certified Great Place to Work

Apply for this position