Yesterday
Secret
Mid Level Career (5+ yrs experience)
IT - Security
Fort Belvoir, VA (On-Site/Office)
Seeking a Sr. SIEM Engineer specializing in Elastic Stack and Confluent in support of the PEO Enterprise SIEM Consolidation / Cyber Defense effort. This effort is focused on the consolidation of PEO Enterprise multiple SIEM solutions (approx. 40) into one consolidated SIEM. This individual should have extensive experience with Security Information and Event Management (SIEM) deployment and tuning as well as Security Orchestration Automation and Response (SOAR) development and implementation.
Responsibilities:
• Design, deploy, configure, and maintain Elastic stack and Confluent deployments
• Manage, patch, and upgrade Elasticsearch, Confluent, and other related systems
• Tune and optimize Elastic stack deployments based on application/customer needs
• Design and configure ETL data pipelines to ingest customer defined data sets such as application logs, metrics, and or threat events
• Create custom visualizations and dashboards using Kibana
• Configure and maintain index templates and information lifecycle management (ILM) policies
• Develop Elastic alerting solutions using Watcher and/or Kibana Rules and Connectors with integrations to ticketing systems, email, and messaging apps as required
• Develop Machine Learning (ML) jobs to dynamically monitor and alert on identified metrics, KPIs, and/or data anomalies
• Follow ITIL based change management processes to move solutions from Dev to Test and into Production
• Run the day-to-day operations of the security operations center
• Investigate incidents and lead response efforts as applicable
Desired Skills:
• Experience using and developing Ansible playbooks for automation of system deployment and/or configuration
• Experience with developing in multiple languages (Python, Bash, PowerShell, Painless, etc.).
• Understanding of the MITRE ATT&CK framework
• Certified Elastic Engineer or willingness to gain certification within 90 days of hire
• Experience with cloud environments (e.g., Azure, AWS, GCP, etc.) and cloud security architecture
• Experience condensing large environments to a single pane of glass view to facilitate optimal operational efficiency
• Experience leading incident response and forensic investigative initiatives
• Demonstrated ability to create and present executive level briefings
• Experience with Army policies, regulations, and processes preferred
Pay range: $140,000-$160,000
Eligibility requirements apply to some benefits and may depend on your job classification and length of employment. Benefits are subject to change and may be subject to specific elections, plan, or program terms. If eligible, the benefits available for this temporary role may include the following:
• Medical, dental & vision
• Critical Illness, Accident, and Hospital
• 401(k) Retirement Plan – Pre-tax and Roth post-tax contributions available
• Life Insurance (Voluntary Life & AD&D for the employee and dependents)
• Short and long-term disability
• Health Spending Account (HSA)
• Transportation benefits
• Employee Assistance Program
• Time Off/Leave (PTO, Vacation or Sick Leave)
· This position requires an active DoD Clearance (Secret, Top Secret, Top Secret/SCI) or the ability to be obtain an (Interim Secret, Interim Top Secret)
· Because an active or interim DoD clearance is required, U.S. Citizenship is required
Eligibility requirements apply to some benefits and may depend on your job classification and length of employment. Benefits are subject to change and may be subject to specific elections, plan, or program terms. If eligible, the benefits available for this temporary role may include the following:
• Medical, dental & vision
• Critical Illness, Accident, and Hospital
• 401(k) Retirement Plan – Pre-tax and Roth post-tax contributions available
• Life Insurance (Voluntary Life & AD&D for the employee and dependents)
• Short and long-term disability
• Health Spending Account (HSA)
• Transportation benefits
• Employee Assistance Program
• Time Off/Leave (PTO, Vacation or Sick Leave)
· This position requires an active DoD Clearance (Secret, Top Secret, Top Secret/SCI) or the ability to be obtain an (Interim Secret, Interim Top Secret)
· Because an active or interim DoD clearance is required, U.S. Citizenship is required
Responsibilities:
• Design, deploy, configure, and maintain Elastic stack and Confluent deployments
• Manage, patch, and upgrade Elasticsearch, Confluent, and other related systems
• Tune and optimize Elastic stack deployments based on application/customer needs
• Design and configure ETL data pipelines to ingest customer defined data sets such as application logs, metrics, and or threat events
• Create custom visualizations and dashboards using Kibana
• Configure and maintain index templates and information lifecycle management (ILM) policies
• Develop Elastic alerting solutions using Watcher and/or Kibana Rules and Connectors with integrations to ticketing systems, email, and messaging apps as required
• Develop Machine Learning (ML) jobs to dynamically monitor and alert on identified metrics, KPIs, and/or data anomalies
• Follow ITIL based change management processes to move solutions from Dev to Test and into Production
• Run the day-to-day operations of the security operations center
• Investigate incidents and lead response efforts as applicable
Desired Skills:
• Experience using and developing Ansible playbooks for automation of system deployment and/or configuration
• Experience with developing in multiple languages (Python, Bash, PowerShell, Painless, etc.).
• Understanding of the MITRE ATT&CK framework
• Certified Elastic Engineer or willingness to gain certification within 90 days of hire
• Experience with cloud environments (e.g., Azure, AWS, GCP, etc.) and cloud security architecture
• Experience condensing large environments to a single pane of glass view to facilitate optimal operational efficiency
• Experience leading incident response and forensic investigative initiatives
• Demonstrated ability to create and present executive level briefings
• Experience with Army policies, regulations, and processes preferred
Pay range: $140,000-$160,000
Eligibility requirements apply to some benefits and may depend on your job classification and length of employment. Benefits are subject to change and may be subject to specific elections, plan, or program terms. If eligible, the benefits available for this temporary role may include the following:
• Medical, dental & vision
• Critical Illness, Accident, and Hospital
• 401(k) Retirement Plan – Pre-tax and Roth post-tax contributions available
• Life Insurance (Voluntary Life & AD&D for the employee and dependents)
• Short and long-term disability
• Health Spending Account (HSA)
• Transportation benefits
• Employee Assistance Program
• Time Off/Leave (PTO, Vacation or Sick Leave)
· This position requires an active DoD Clearance (Secret, Top Secret, Top Secret/SCI) or the ability to be obtain an (Interim Secret, Interim Top Secret)
· Because an active or interim DoD clearance is required, U.S. Citizenship is required
Eligibility requirements apply to some benefits and may depend on your job classification and length of employment. Benefits are subject to change and may be subject to specific elections, plan, or program terms. If eligible, the benefits available for this temporary role may include the following:
• Medical, dental & vision
• Critical Illness, Accident, and Hospital
• 401(k) Retirement Plan – Pre-tax and Roth post-tax contributions available
• Life Insurance (Voluntary Life & AD&D for the employee and dependents)
• Short and long-term disability
• Health Spending Account (HSA)
• Transportation benefits
• Employee Assistance Program
• Time Off/Leave (PTO, Vacation or Sick Leave)
· This position requires an active DoD Clearance (Secret, Top Secret, Top Secret/SCI) or the ability to be obtain an (Interim Secret, Interim Top Secret)
· Because an active or interim DoD clearance is required, U.S. Citizenship is required
group id: 10105424
Accelerating IT transformation in the public sector