Cyber Security Incident and Event Management/Elastic Specialist Job at Diligent Consulting, Washington DC

WHFpRDNYOGxCY21WM2FqS01mMzJVaW5L
  • Diligent Consulting
  • Washington DC

Job Description


US CITIZEN ONLY. SECRET CLEARANCE REQUIRED. MUST HAVE IT-II CERT (IE SECURITY+)

SIEM/Elastic Specialist will:

• Be responsible for designing & setting up the ingestion of various customer data flows to include pre-processing data into a useable format, ensuring proper parsing and indexing
• Collaborate with cross-functional teams and responsible for designing & integrating Elastic with a wide variety of data sources and developing associated knowledge objects such as queries, dashboards, reports, alerts for monitoring and analytics
• Perform data transformation using Elastic query language 
• Track the health of the Elastic environment and optimize its performance. Troubleshoot and resolve issues related to security, performance, data indexing, and searches
• Perform watch-officer monitoring duties, including:
○ monitoring, detecting, investigating, and responding to cybersecurity threats and events using Elastic /SIEM Platform
○ Reviewing correlated alerts and logs for compromise scenarios
○ Performing triage of security alerts to prioritize response
○ Identifying false positives
○ Investigating security incidents and determining root cause
○ Collecting and preserving logs for analysis
○ Escalating confirmed incidents to leadership or SOC teams
○ Coordinating with IT or DevOps for containment and remediation
○ Creating after-action reports (AAR) post-incident
• In addition, the role may include assistance with monitoring Vulnerability Management tools, such as ACAS and ePO.

QUALIFICATIONS:

• Have at least three years of working knowledge and hands-on experience with Elastic/Splunk query languages, monitoring SIEM dashboards and real-time alerts, fine-tuning SIEM rules to reduce noise, and NIST 800-53 & DevSecOps frameworks

Job Tags

Full time,

Similar Jobs

HCAOA

Evening Caregiver 3 PM to 11 PM Okemos and Lansing Job at HCAOA

 ...Evening Caregiver (3 PM 11 PM) | Okemos & Lansing | Full-Time & Part-Time FirstLight Home Care of Greater Lansing & Brighton offers...  ...consistent evening hours, and lets you make a real difference. This 2nd shift role is perfect for night owls who like working evenings and... 

Amazon.com Services LLC

Software Development Engineer Internship - Summer 2026 (US) Job at Amazon.com Services LLC

 ...your application will only be considered for our summer Software Development Engineer (SDE) internship roles. Our summer intern roles have start dates in...  ...specific skills and interests helps us better align your experience with potential roles. Key job responsibilities ... 

Pizza Hut

Pizza Hut - Kitchen Cook - Prairie du Chien - Urgently Hiring (52170) Job at Pizza Hut

Pizza Hut - Kitchen Cook - Prairie du Chien - Urgently Hiring (52170) at Pizza Hut summary: The Kitchen Cook at Pizza Hut in Prairie du Chien is responsible for preparing food items efficiently while adhering to hospitality and safety standards. Duties include following...

Bestica

Travel Nurse RN - Labor and Delivery Job at Bestica

 ...Job Description Bestica is seeking a travel nurse RN Labor and Delivery for a travel nursing job in Smyrna, Tennessee. Job Description & Requirements ~ Specialty: Labor and Delivery ~ Discipline: RN ~ Duration: 13 weeks ~36 hours per week ~ Shift: 12... 

Securitas Electronic Security Inc

Low Voltage Alarm Technician Job at Securitas Electronic Security Inc

 ...Technology Corporation (STC) Technology and Solutions groups are experiencing tremendous success, and we currently have an Embedded Technician opening for team-oriented individuals possessing vocational training in electronics or electromechanical engineering. In this...