Cyber Security Incident and Event Management/Elastic Specialist Job at Diligent Consulting Inc, Washington DC

N0tuYkZ3SC9yaVlMLzR0d0pkVHk3dHpuaXc9PQ==
  • Diligent Consulting Inc
  • Washington DC

Job Description

US CITIZEN ONLY. SECRET CLEARANCE REQUIRED.  MUST HAVE IT-II CERT (IE SECURITY+)

SIEM/Elastic Specialist will:

• Be responsible for designing & setting up the ingestion of various customer data flows to include pre-processing data into a useable format, ensuring proper parsing and indexing
• Collaborate with cross-functional teams and responsible for designing & integrating Elastic with a wide variety of data sources and developing associated knowledge objects such as queries, dashboards, reports, alerts for monitoring and analytics
• Perform data transformation using Elastic query language 
• Track the health of the Elastic environment and optimize its performance. Troubleshoot and resolve issues related to security, performance, data indexing, and searches
• Perform watch-officer monitoring duties, including:
○ monitoring, detecting, investigating, and responding to cybersecurity threats and events using Elastic /SIEM Platform
○ Reviewing correlated alerts and logs for compromise scenarios
○ Performing triage of security alerts to prioritize response
○ Identifying false positives
○ Investigating security incidents and determining root cause
○ Collecting and preserving logs for analysis
○ Escalating confirmed incidents to leadership or SOC teams
○ Coordinating with IT or DevOps for containment and remediation
○ Creating after-action reports (AAR) post-incident
• In addition, the role may include assistance with monitoring Vulnerability Management tools, such as ACAS and ePO.

QUALIFICATIONS:

• Have at least three years of working knowledge and hands-on experience with Elastic/Splunk query languages, monitoring SIEM dashboards and real-time alerts, fine-tuning SIEM rules to reduce noise, and NIST 800-53 & DevSecOps frameworks

 

Job Tags

Full time,

Similar Jobs

Acloché

Forklift Operator Job at Acloché

 ...Forklift Operator - Groveport, OH Acloche has immediate openings for a Forklift Operator in Groveport! If youre looking for...  ...Primary duties of the Forklift Operator include: Operate a Cherry Picker. Operate a Stand Up. Operate a Reach Truck. Follow all... 

Sapsol Technologies Inc

Entry level SAP Consultant Needed for Project Implementation- Remote Job at Sapsol Technologies Inc

 ...gathering workshops and document functional design documents. Configuration and integration of respective modules as per blueprint. Develop test strategy and document test results. Troubleshoot and resolve issues for cross-functional areas. Develop support model... 

Kelly Services

13790 - Recruiter (Professional & Industrial) College Park, GA Job at Kelly Services

 ...value your contribution, we work with integrity, and we always put people first so your impact really will change lives. Our Recruiter is accountable for: Full life cycle recruiting for a variety of positions across multiple levels, supporting our Industrial... 

cdcb

Mortgage Specialist Job at cdcb

Position Title: Mortgage Specialist Supervisor: Chief Lending Officer Classification: Full time, Non-Exempt Compensation based on experience: $15.50 - $17.50 About Us cdcb | come dream. come build. is a private 501(c)(3) nonprofit organization founded in... 

Memco

Scaffold Builder Job at Memco

 ...MEMCO is immediately hiring Scaffold Builders in Rome, GA! Schedule: M-F Location: Rome, GA Pay: $21- $25/hr; BOE ASAP Start! MEMCO ATL is hiring experienced commercial scaffold builders for a project in Rome, GA . The ideal candidate must have their...