Cyber Security Incident and Event Management/Elastic Specialist Job at Diligent Consulting Inc, Washington DC

N0tuYkZ3SC9yaVlMLzR0d0pkVHk3dHpuaXc9PQ==
  • Diligent Consulting Inc
  • Washington DC

Job Description

US CITIZEN ONLY. SECRET CLEARANCE REQUIRED.  MUST HAVE IT-II CERT (IE SECURITY+)

SIEM/Elastic Specialist will:

• Be responsible for designing & setting up the ingestion of various customer data flows to include pre-processing data into a useable format, ensuring proper parsing and indexing
• Collaborate with cross-functional teams and responsible for designing & integrating Elastic with a wide variety of data sources and developing associated knowledge objects such as queries, dashboards, reports, alerts for monitoring and analytics
• Perform data transformation using Elastic query language 
• Track the health of the Elastic environment and optimize its performance. Troubleshoot and resolve issues related to security, performance, data indexing, and searches
• Perform watch-officer monitoring duties, including:
○ monitoring, detecting, investigating, and responding to cybersecurity threats and events using Elastic /SIEM Platform
○ Reviewing correlated alerts and logs for compromise scenarios
○ Performing triage of security alerts to prioritize response
○ Identifying false positives
○ Investigating security incidents and determining root cause
○ Collecting and preserving logs for analysis
○ Escalating confirmed incidents to leadership or SOC teams
○ Coordinating with IT or DevOps for containment and remediation
○ Creating after-action reports (AAR) post-incident
• In addition, the role may include assistance with monitoring Vulnerability Management tools, such as ACAS and ePO.

QUALIFICATIONS:

• Have at least three years of working knowledge and hands-on experience with Elastic/Splunk query languages, monitoring SIEM dashboards and real-time alerts, fine-tuning SIEM rules to reduce noise, and NIST 800-53 & DevSecOps frameworks

 

Job Tags

Full time,

Similar Jobs

Anthropic

Incentive Compensation System Engineer Job at Anthropic

 ...Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to...  ...However, some roles may require more time in our offices. Visa sponsorship: We do sponsor visas! However, we aren't able to successfully... 

Q - Center

Safety & Security Manager Job at Q - Center

Q Center is looking for a Safety & Security Manager to join our team! Job SummaryThe Safety & Security Manager is responsible for coordinating, supervising and directing all aspects of Safety & Security operations. This position will develop safety and security strategies... 

Boston University

Associate Director, Direct Marketing & Annual Giving Job at Boston University

 ...A prestigious educational institution in Boston is seeking an Associate Director for Direct Marketing to lead its annual giving efforts. This role involves strategizing and managing fundraising campaigns via direct mail and email, collaborating with various internal partners... 

Our Home

Warehouse Lead Job at Our Home

 ...believe that we are Stronger Together : Collaboration is at the center of what we do. We win and lose together . Our Home makes...  ...Loads trailers with finished product for distributors and distribution centers; accuracy is critical. Reads load sheets to determine... 

Bechtel

Sr. HLW Project Controls Engineer, WTP Job at Bechtel

 ...schedule for a specific discipline area or specialty within Engineering, Procurement, Construction, Testing and Commissioning/Operations...  ...to work and remain in the United States without Bechtel visa sponsorship now or in the future. Must be able to complete and pass a...