Job Requirements
Hanscom AFB, MA Boston, MA
Clearance Unspecified Polygraph not specified
Mid Level Career (5+ yrs experience)
$120,000 - $250,000
Job Description
TEKsystems is seeking an experienced Elasticsearch Engineer to support a critical Department of Defense cybersecurity modernization initiative. This position is focused on designing, implementing, and maintaining enterprise Elastic Stack solutions in support of advanced security operations, threat detection, and defensive cyber missions.
The ideal candidate will have deep expertise with Elasticsearch and the broader Elastic ecosystem, experience supporting SIEM and SOC operations, and a strong background working within secure government environments.
Responsibilities
Design, implement, integrate, and maintain Elastic Stack solutions supporting cybersecurity operations
Administer and optimize Elasticsearch, Kibana, Logstash, Beats, and Fleet deployments
Build and maintain Kibana dashboards, visualizations, and security analytics
Develop and manage Elasticsearch index lifecycle policies, templates, and data streams
Create and optimize log ingestion pipelines across network, endpoint, identity, and cloud sources
Implement Elastic Security detection rules, alerting capabilities, and case management workflows
Normalize and enrich security data using Elastic Common Schema (ECS)
Support threat hunting, incident response, and SIEM operations
Optimize logging and security visibility across AWS environments and enterprise infrastructure
Provide technical leadership and mentorship while solving highly complex cybersecurity challenges
Required Qualifications
Active Secret Clearance or ability to obtain a Secret Clearance
Bachelor's degree
5+ years of hands-on experience administering Elastic Stack technologies:
Elasticsearch
Kibana
Logstash
Beats
Fleet
Experience with:
Elasticsearch index lifecycle management (ILM)
Index templates and data streams
Kibana dashboards and security visualizations
Elastic Security detections, alerts, and case management
Log ingestion design, parsing, enrichment, and normalization
Elastic Common Schema (ECS)
SIEM, SOC, or defensive cyber operations
AWS security and log collection optimization
Familiarity with AI/ML concepts for security analytics, anomaly detection, and threat scoring
Preferred Qualifications
Previous experience supporting Department of Defense programs
Experience in Agile environments
Elastic Machine Learning (ML) jobs and UEBA use cases
Experience integrating AI/LLM capabilities into security workflows
Python, scikit-learn, or PyTorch experience for security analytics
Elastic Agent fleet management at scale
Cross-domain and multi-classification environment experience (IL4/IL5/IL6)
ES|QL and EQL threat hunting experience
Kubernetes certifications or hands-on Kubernetes administration experience
Top Skills
Elastic Stack
Elasticsearch
Kibana
Logstash
Elastic Security
AWS
SIEM Engineering
Cybersecurity Operations
SOC Support
Threat Detection
Why Apply?
This is an opportunity to join a high-impact DoD cybersecurity program focused on modernizing security capabilities in mission-critical environments. You'll work with cutting-edge Elastic technologies, support advanced cyber operations, and help shape the future of enterprise security architectures.
The ideal candidate will have deep expertise with Elasticsearch and the broader Elastic ecosystem, experience supporting SIEM and SOC operations, and a strong background working within secure government environments.
Responsibilities
Design, implement, integrate, and maintain Elastic Stack solutions supporting cybersecurity operations
Administer and optimize Elasticsearch, Kibana, Logstash, Beats, and Fleet deployments
Build and maintain Kibana dashboards, visualizations, and security analytics
Develop and manage Elasticsearch index lifecycle policies, templates, and data streams
Create and optimize log ingestion pipelines across network, endpoint, identity, and cloud sources
Implement Elastic Security detection rules, alerting capabilities, and case management workflows
Normalize and enrich security data using Elastic Common Schema (ECS)
Support threat hunting, incident response, and SIEM operations
Optimize logging and security visibility across AWS environments and enterprise infrastructure
Provide technical leadership and mentorship while solving highly complex cybersecurity challenges
Required Qualifications
Active Secret Clearance or ability to obtain a Secret Clearance
Bachelor's degree
5+ years of hands-on experience administering Elastic Stack technologies:
Elasticsearch
Kibana
Logstash
Beats
Fleet
Experience with:
Elasticsearch index lifecycle management (ILM)
Index templates and data streams
Kibana dashboards and security visualizations
Elastic Security detections, alerts, and case management
Log ingestion design, parsing, enrichment, and normalization
Elastic Common Schema (ECS)
SIEM, SOC, or defensive cyber operations
AWS security and log collection optimization
Familiarity with AI/ML concepts for security analytics, anomaly detection, and threat scoring
Preferred Qualifications
Previous experience supporting Department of Defense programs
Experience in Agile environments
Elastic Machine Learning (ML) jobs and UEBA use cases
Experience integrating AI/LLM capabilities into security workflows
Python, scikit-learn, or PyTorch experience for security analytics
Elastic Agent fleet management at scale
Cross-domain and multi-classification environment experience (IL4/IL5/IL6)
ES|QL and EQL threat hunting experience
Kubernetes certifications or hands-on Kubernetes administration experience
Top Skills
Elastic Stack
Elasticsearch
Kibana
Logstash
Elastic Security
AWS
SIEM Engineering
Cybersecurity Operations
SOC Support
Threat Detection
Why Apply?
This is an opportunity to join a high-impact DoD cybersecurity program focused on modernizing security capabilities in mission-critical environments. You'll work with cutting-edge Elastic technologies, support advanced cyber operations, and help shape the future of enterprise security architectures.
group id: 10105424