Cyber Security Incident and Event Management/Elastic Specialist Job at Diligent Consulting Inc, Washington DC

eCtLbVBIbkVlZnZwZ1YyWFRjTlQ2cGdYb1E9PQ==
  • Diligent Consulting Inc
  • Washington DC

Job Description

US CITIZEN ONLY. SECRET CLEARANCE REQUIRED.  MUST HAVE IT-II CERT (IE SECURITY+)

SIEM/Elastic Specialist will:

• Be responsible for designing & setting up the ingestion of various customer data flows to include pre-processing data into a useable format, ensuring proper parsing and indexing
• Collaborate with cross-functional teams and responsible for designing & integrating Elastic with a wide variety of data sources and developing associated knowledge objects such as queries, dashboards, reports, alerts for monitoring and analytics
• Perform data transformation using Elastic query language 
• Track the health of the Elastic environment and optimize its performance. Troubleshoot and resolve issues related to security, performance, data indexing, and searches
• Perform watch-officer monitoring duties, including:
○ monitoring, detecting, investigating, and responding to cybersecurity threats and events using Elastic /SIEM Platform
○ Reviewing correlated alerts and logs for compromise scenarios
○ Performing triage of security alerts to prioritize response
○ Identifying false positives
○ Investigating security incidents and determining root cause
○ Collecting and preserving logs for analysis
○ Escalating confirmed incidents to leadership or SOC teams
○ Coordinating with IT or DevOps for containment and remediation
○ Creating after-action reports (AAR) post-incident
• In addition, the role may include assistance with monitoring Vulnerability Management tools, such as ACAS and ePO.

QUALIFICATIONS:

• Have at least three years of working knowledge and hands-on experience with Elastic/Splunk query languages, monitoring SIEM dashboards and real-time alerts, fine-tuning SIEM rules to reduce noise, and NIST 800-53 & DevSecOps frameworks

 

Job Tags

Full time,

Similar Jobs

CWH Advisors

Senior Healthcare Analyst Job at CWH Advisors

 ...CWH Advisors is hiring a Senior Healthcare Analyst to join our team. This is a full-time, fully remote position. CWH is a healthcare advisory firm built around real-world operating experience. Our team is made up primarily of senior executives and operators who understand... 

Lake Champlain Maritime Museum

Expedition Trip Leader Job at Lake Champlain Maritime Museum

 ...Lake Champlain Maritime Museum is in search of qualified on-water trip leaders for Teen Expeditionary Programs. The summer is broken into four programs: one day camp and three expeditions. First, Kayak Building Camp , is a three-week day program where teens build their... 

Quality Inn near Monument Health Rapid City Hospital

Front Desk Agent Job at Quality Inn near Monument Health Rapid City Hospital

 ...Urgent Opportunity: Talented Front Desk Agent Needed! Are you looking for a dynamic workplace where every day brings new challenges?...  ...shifts Location: Quality Inn near Monument Health Rapid City Hospital 750 Cathedral Dr, Rapid City, SD 57701, USA If you are a... 

Okta

Data Analyst Intern (Summer 2026) Job at Okta

 ...dynamic and motivated contributor to join our team in one of our key office locations: San Francisco. About the Internship We are looking for a Data Analyst who has a passion for storytelling with data. You will be successful if you are detail-oriented, like solving... 

Liberty Personnel Services, Inc.

Building Automation Controls Technician Job at Liberty Personnel Services, Inc.

 ...Details: HVAC Controls Service / Installation Engineer ( Building Automation ) - Sign on Bonus Strong understanding of mechanical...  ...Please send resume to ****@*****.*** HVAC Controls Technician, Building Automation, Energy Management Systems, Alerton...