Cyber Security Incident and Event Management/Elastic Specialist Job at Diligent Consulting Inc, Washington DC

N0tuYkZ3SC9yaVlMLzR0d0pkVHk3dHpuaXc9PQ==
  • Diligent Consulting Inc
  • Washington DC

Job Description

US CITIZEN ONLY. SECRET CLEARANCE REQUIRED.  MUST HAVE IT-II CERT (IE SECURITY+)

SIEM/Elastic Specialist will:

• Be responsible for designing & setting up the ingestion of various customer data flows to include pre-processing data into a useable format, ensuring proper parsing and indexing
• Collaborate with cross-functional teams and responsible for designing & integrating Elastic with a wide variety of data sources and developing associated knowledge objects such as queries, dashboards, reports, alerts for monitoring and analytics
• Perform data transformation using Elastic query language 
• Track the health of the Elastic environment and optimize its performance. Troubleshoot and resolve issues related to security, performance, data indexing, and searches
• Perform watch-officer monitoring duties, including:
○ monitoring, detecting, investigating, and responding to cybersecurity threats and events using Elastic /SIEM Platform
○ Reviewing correlated alerts and logs for compromise scenarios
○ Performing triage of security alerts to prioritize response
○ Identifying false positives
○ Investigating security incidents and determining root cause
○ Collecting and preserving logs for analysis
○ Escalating confirmed incidents to leadership or SOC teams
○ Coordinating with IT or DevOps for containment and remediation
○ Creating after-action reports (AAR) post-incident
• In addition, the role may include assistance with monitoring Vulnerability Management tools, such as ACAS and ePO.

QUALIFICATIONS:

• Have at least three years of working knowledge and hands-on experience with Elastic/Splunk query languages, monitoring SIEM dashboards and real-time alerts, fine-tuning SIEM rules to reduce noise, and NIST 800-53 & DevSecOps frameworks

 

Job Tags

Full time,

Similar Jobs

Empowered Staffing

Media Buyer (Paid Search & Social) Job at Empowered Staffing

Empowered Staffing is partnered with an established eCommerce direct-to-consumer brand looking to hire a Media Buyer (Paid Search Social) who will own hands-on execution across Google Ads and Meta Ads. This is a high-impact role for someone who enjoys being in-platform...

Enterprise Medical Recruiting

Internal Medicine in Southwestern California - Visa Supported & Sign-On Job at Enterprise Medical Recruiting

 ...with bonus potential, competitive benefits package, and loan repayment opportunities ~$30K Sign-on/Relocation ~ H1B and J1 visa waiver sponsorship available Community Highlights: Los Banos is a great place to live, especially if you're a hunter, enjoy birdwatching...