Job Requirements
San Antonio, TX
Top Secret/SCI Polygraph Unspecified
Career Level not specified
Salary not specified
Join Premium to unlock estimated salaries
Job Description
Description & Requirements
Maximus is seeking a Senior Cybersecurity Engineer - Elastic SIEM.
This role is on-site in San Antonio, TX and requires an active TS/SCI security clearance.
Maximus TCS (Technology and Consulting Services) Internal Job Profile Code: TCS058, T4, Band 7
Job-Specific Essential Duties and Responsibilities:
- Lead complex SIEM engineering tasks with minimal supervision and provide technical guidance to the team.
- Administer, operate, and sustain the Elastic SIEM platform (Elasticsearch, Kibana, Logstash, Beats/Elastic Agent) across NIPRNet, SIPRNet, and JWICS environments.
- Monitor SIEM health, perform capacity planning, and resolve complex platform outages and degradations in accordance with defined SLAs.
- Develop, tune, and maintain detection rules, alerts, dashboards, and visualizations in Elastic to support DCO mission requirements.
- Ingest, normalize, and validate log data from diverse sources including endpoint, network, cloud, and application telemetry.
- Collaborate with cyber operators and analysts to support threat detection, alert triage, and cyber incident investigation workflows.
- Identify opportunities to improve SIEM coverage, data quality, and detection fidelity; lead implementation of improvements in coordination with the Government PMO.
- Support Cyber Security Service Provider (CSSP) activities including continuous monitoring and security event analysis.
- Create and maintain technical documentation including runbooks, standard operating procedures (SOPs), and knowledge base articles.
- Provide technical guidance and mentoring to journeyman engineers and review SIEM configurations and detection rules.
- Participate in Agile/SAFe Program Increment (PI) planning and sprint execution in support of platform delivery.
- Adhere to Air Force cybersecurity standards and all applicable DoD, IC, and USAF policy and directives across all enclaves.
Job-Specific Minimum Requirements:
- Active Top Secret / SCI (TS/SCI) security clearance.
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field (or equivalent experience).
- 7+ years of hands-on cybersecurity engineering experience.
- Advanced proficiency level: demonstrated experience leading complex Elastic SIEM integrations and troubleshooting, reviewing technical work, and mentoring engineers.
- Demonstrated hands-on experience with Elastic Stack (Elasticsearch, Kibana, Logstash, Beats/Elastic Agent) in an operational SIEM environment.
- Experience supporting threat detection, alert triage, and/or cyber incident investigation.
- Familiarity with DCO concepts, CSSP operations, and defensive cyber frameworks.
- Experience working across multiple network security domains (NIPR, SIPR, or JWICS).
- Meet applicable DoD 8140 requirements for the assigned work role. DCWF 521, Cyber Defense Infrastructure Support Specialist, Advanced Proficiency; specific required certifications pending contract confirmation.
Preferred Skills and Qualifications:
- Experience with SIEM/SOAR integrations (e.g., Elastic, Palo Alto Cortex XSOAR, or similar).
- Familiarity with Elastic's Fleet/Agent management and integration development.
- Experience with AWS GovCloud environments (IL4/IL5/IL6).
- Knowledge of MITRE ATT&CK framework and its application to detection engineering.
- Experience with scripting/automation (Python, Bash, KQL/EQL) for SIEM rule development and data pipeline management.
- Familiarity with container-based deployments (Kubernetes/EKS) in classified environments.
- Prior experience supporting USAF or DoD DCO programs.
- One or more of the following certifications preferred: Elastic Certified Engineer, CompTIA CySA+, GCIA, or GCIH.
#techjobs #clearance #veteransPage
Minimum Requirements
TCS058, T4, Band 7
EEO Statement
Maximus is an equal opportunity employer. We evaluate qualified applicants without regard to race, color, religion, sex, age, national origin, disability, veteran status, genetic information and other legally protected characteristics.
Pay Transparency
Maximus compensation is based on various factors including but not limited to job location, a candidate's education, training, experience, expected quality and quantity of work, required travel (if any), external market and internal value analysis including seniority and merit systems, as well as internal pay alignment. Annual salary is just one component of Maximus's total compensation package. Other rewards may include short- and long-term incentives as well as program-specific awards. Additionally, Maximus provides a variety of benefits to employees, including health insurance coverage, life and disability insurance, a retirement savings plan, paid holidays and paid time off. Compensation ranges may differ based on contract value but will be commensurate with job duties and relevant work experience. An applicant's salary history will not be used in determining compensation. Maximus will comply with regulatory minimum wage rates and exempt salary thresholds in all instances.
Accommodations
Maximus provides reasonable accommodations to individuals requiring assistance during any phase of the employment process due to a disability, medical condition, or physical or mental impairment. If you require assistance at any stage of the employment process-including accessing job postings, completing assessments, or participating in interviews,-please contact People Operations at applicantaccom@maximus.com .
Maximus is seeking a Senior Cybersecurity Engineer - Elastic SIEM.
This role is on-site in San Antonio, TX and requires an active TS/SCI security clearance.
Maximus TCS (Technology and Consulting Services) Internal Job Profile Code: TCS058, T4, Band 7
Job-Specific Essential Duties and Responsibilities:
- Lead complex SIEM engineering tasks with minimal supervision and provide technical guidance to the team.
- Administer, operate, and sustain the Elastic SIEM platform (Elasticsearch, Kibana, Logstash, Beats/Elastic Agent) across NIPRNet, SIPRNet, and JWICS environments.
- Monitor SIEM health, perform capacity planning, and resolve complex platform outages and degradations in accordance with defined SLAs.
- Develop, tune, and maintain detection rules, alerts, dashboards, and visualizations in Elastic to support DCO mission requirements.
- Ingest, normalize, and validate log data from diverse sources including endpoint, network, cloud, and application telemetry.
- Collaborate with cyber operators and analysts to support threat detection, alert triage, and cyber incident investigation workflows.
- Identify opportunities to improve SIEM coverage, data quality, and detection fidelity; lead implementation of improvements in coordination with the Government PMO.
- Support Cyber Security Service Provider (CSSP) activities including continuous monitoring and security event analysis.
- Create and maintain technical documentation including runbooks, standard operating procedures (SOPs), and knowledge base articles.
- Provide technical guidance and mentoring to journeyman engineers and review SIEM configurations and detection rules.
- Participate in Agile/SAFe Program Increment (PI) planning and sprint execution in support of platform delivery.
- Adhere to Air Force cybersecurity standards and all applicable DoD, IC, and USAF policy and directives across all enclaves.
Job-Specific Minimum Requirements:
- Active Top Secret / SCI (TS/SCI) security clearance.
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field (or equivalent experience).
- 7+ years of hands-on cybersecurity engineering experience.
- Advanced proficiency level: demonstrated experience leading complex Elastic SIEM integrations and troubleshooting, reviewing technical work, and mentoring engineers.
- Demonstrated hands-on experience with Elastic Stack (Elasticsearch, Kibana, Logstash, Beats/Elastic Agent) in an operational SIEM environment.
- Experience supporting threat detection, alert triage, and/or cyber incident investigation.
- Familiarity with DCO concepts, CSSP operations, and defensive cyber frameworks.
- Experience working across multiple network security domains (NIPR, SIPR, or JWICS).
- Meet applicable DoD 8140 requirements for the assigned work role. DCWF 521, Cyber Defense Infrastructure Support Specialist, Advanced Proficiency; specific required certifications pending contract confirmation.
Preferred Skills and Qualifications:
- Experience with SIEM/SOAR integrations (e.g., Elastic, Palo Alto Cortex XSOAR, or similar).
- Familiarity with Elastic's Fleet/Agent management and integration development.
- Experience with AWS GovCloud environments (IL4/IL5/IL6).
- Knowledge of MITRE ATT&CK framework and its application to detection engineering.
- Experience with scripting/automation (Python, Bash, KQL/EQL) for SIEM rule development and data pipeline management.
- Familiarity with container-based deployments (Kubernetes/EKS) in classified environments.
- Prior experience supporting USAF or DoD DCO programs.
- One or more of the following certifications preferred: Elastic Certified Engineer, CompTIA CySA+, GCIA, or GCIH.
#techjobs #clearance #veteransPage
Minimum Requirements
TCS058, T4, Band 7
EEO Statement
Maximus is an equal opportunity employer. We evaluate qualified applicants without regard to race, color, religion, sex, age, national origin, disability, veteran status, genetic information and other legally protected characteristics.
Pay Transparency
Maximus compensation is based on various factors including but not limited to job location, a candidate's education, training, experience, expected quality and quantity of work, required travel (if any), external market and internal value analysis including seniority and merit systems, as well as internal pay alignment. Annual salary is just one component of Maximus's total compensation package. Other rewards may include short- and long-term incentives as well as program-specific awards. Additionally, Maximus provides a variety of benefits to employees, including health insurance coverage, life and disability insurance, a retirement savings plan, paid holidays and paid time off. Compensation ranges may differ based on contract value but will be commensurate with job duties and relevant work experience. An applicant's salary history will not be used in determining compensation. Maximus will comply with regulatory minimum wage rates and exempt salary thresholds in all instances.
Accommodations
Maximus provides reasonable accommodations to individuals requiring assistance during any phase of the employment process due to a disability, medical condition, or physical or mental impairment. If you require assistance at any stage of the employment process-including accessing job postings, completing assessments, or participating in interviews,-please contact People Operations at applicantaccom@maximus.com .
group id: 50050274
Maximus makes it easier for people to access public services and positions governments to meet complex policy and service delivery challenges with agility, resilience, and impact.