Cyber Security Incident and Event Management/Elastic Specialist Job at Diligent Consulting, Washington DC

MFdTeU0vTUFPVUJxdzZsbzA2M1M4S2s2
  • Diligent Consulting
  • Washington DC

Job Description


US CITIZEN ONLY. SECRET CLEARANCE REQUIRED. MUST HAVE IT-II CERT (IE SECURITY+)

SIEM/Elastic Specialist will:

• Be responsible for designing & setting up the ingestion of various customer data flows to include pre-processing data into a useable format, ensuring proper parsing and indexing
• Collaborate with cross-functional teams and responsible for designing & integrating Elastic with a wide variety of data sources and developing associated knowledge objects such as queries, dashboards, reports, alerts for monitoring and analytics
• Perform data transformation using Elastic query language 
• Track the health of the Elastic environment and optimize its performance. Troubleshoot and resolve issues related to security, performance, data indexing, and searches
• Perform watch-officer monitoring duties, including:
○ monitoring, detecting, investigating, and responding to cybersecurity threats and events using Elastic /SIEM Platform
○ Reviewing correlated alerts and logs for compromise scenarios
○ Performing triage of security alerts to prioritize response
○ Identifying false positives
○ Investigating security incidents and determining root cause
○ Collecting and preserving logs for analysis
○ Escalating confirmed incidents to leadership or SOC teams
○ Coordinating with IT or DevOps for containment and remediation
○ Creating after-action reports (AAR) post-incident
• In addition, the role may include assistance with monitoring Vulnerability Management tools, such as ACAS and ePO.

QUALIFICATIONS:

• Have at least three years of working knowledge and hands-on experience with Elastic/Splunk query languages, monitoring SIEM dashboards and real-time alerts, fine-tuning SIEM rules to reduce noise, and NIST 800-53 & DevSecOps frameworks

Job Tags

Full time,

Similar Jobs

Lockheed Martin

Senior AI/ML Engineer Job at Lockheed Martin

Senior AI/ML Engineer at Lockheed Martin summary: The Senior AI/ML Engineer at Lockheed Martin designs, develops, and deploys scalable artificial intelligence and machine learning models to address complex business and defense challenges. The role requires advanced ...

HCAOA

CNA or PCA Job at HCAOA

 ...) $300 hire bonus. Please only apply if you are a CNA, HHA, or PCA in Virginia, have a driver's license and...  ..., and activities! Meal preparation Personal Care Homewatch CareGivers offers comprehensive home care services and believes that exceptional training... 

LocumTenens.com

Vascular Surgeon Job at LocumTenens.com

 ...Inpatient Call Required: Yes Board Certification Required: Negotiable Job Duration: Locums About the Facility A facility is seeking a Vascular Surgeon for locum tenens coverage. About the Facility Location The facility is located in Aurora, Colorado. About the Clinician's... 

Recruit Monitor

Remote Customer Service Specialist - Work From Home Job at Recruit Monitor

 ...A leading remote service provider is looking for a Remote Customer Service Specialist to assist clients with prescription inquiries. This permanent position requires a high school diploma and at least one year of customer service experience. Candidates should possess... 

Texas Periodontics and Dental Implants

Registered Dental Assistant - Oral Surgery Job at Texas Periodontics and Dental Implants

 ...Bldg 3, Suite 103, Austin, TX 78748 Position Highlights: Step into the fast-paced world of oral surgery as a Registered Dental Assistant (RDA)! Your role is essential in supporting surgeons during procedures and ensuring accurate, thorough documentation of patient...