Cyber Security Incident and Event Management/Elastic Specialist Job at Diligent Consulting Inc, Washington DC

eVk3VTdVYythQlpWL1pCQ0lPMTFQSGFDcGc9PQ==
  • Diligent Consulting Inc
  • Washington DC

Job Description

US CITIZEN ONLY. SECRET CLEARANCE REQUIRED.  MUST HAVE IT-II CERT (IE SECURITY+)

SIEM/Elastic Specialist will:

• Be responsible for designing & setting up the ingestion of various customer data flows to include pre-processing data into a useable format, ensuring proper parsing and indexing
• Collaborate with cross-functional teams and responsible for designing & integrating Elastic with a wide variety of data sources and developing associated knowledge objects such as queries, dashboards, reports, alerts for monitoring and analytics
• Perform data transformation using Elastic query language 
• Track the health of the Elastic environment and optimize its performance. Troubleshoot and resolve issues related to security, performance, data indexing, and searches
• Perform watch-officer monitoring duties, including:
○ monitoring, detecting, investigating, and responding to cybersecurity threats and events using Elastic /SIEM Platform
○ Reviewing correlated alerts and logs for compromise scenarios
○ Performing triage of security alerts to prioritize response
○ Identifying false positives
○ Investigating security incidents and determining root cause
○ Collecting and preserving logs for analysis
○ Escalating confirmed incidents to leadership or SOC teams
○ Coordinating with IT or DevOps for containment and remediation
○ Creating after-action reports (AAR) post-incident
• In addition, the role may include assistance with monitoring Vulnerability Management tools, such as ACAS and ePO.

QUALIFICATIONS:

• Have at least three years of working knowledge and hands-on experience with Elastic/Splunk query languages, monitoring SIEM dashboards and real-time alerts, fine-tuning SIEM rules to reduce noise, and NIST 800-53 & DevSecOps frameworks

 

Job Tags

Full time,

Similar Jobs

Keurig Dr Pepper Inc.

Demand Planning Manager Job at Keurig Dr Pepper Inc.

 ...for KDPs Hard Goods portfolio and our Away From Home (AFH) and Keurig.com channels. With the assistance of Marketing and Sales, the...  ...for the Made to stock and Made to order items produced by Keurig Dr Pepper. The incumbent will lead the monthly forecast review with sales... 

Tiffany & Co.

Internship - Cloud & Platform Engineering Job at Tiffany & Co.

Internship - Cloud & Platform EngineeringPosition OverviewThe Cloud & Platform Engineering Summer Intern will gain hands-on experience across various IT domains, including cloud, infrastructure, databases, IT Service Management (ITSM), and other technology... 

AXA Group

Talent Management Program Lead, Americas Job at AXA Group

 ...independently own and drive key programs. What we OFFER Inclusion AXA XL is committed to equal employment opportunity and will...  ...Enhanced family-friendly leave benefits Named to the Diversity Best Practices Index Signatory to the UK Women in Finance Charter... 

Addison Group

Executive Assistant - Contract to hire Job at Addison Group

 ...Financial Services Compensation: $30$35/hour Work Schedule: MondayFriday, 8:00am5:00pm Hybrid schedule : 34 days in office Benefits: This position is eligible for medical, dental, vision, and 401(k). About Our Client: Addison Group is hiring... 

ANCO

Tower Technician- Cellular Maintenance Job at ANCO

 ...Position Overview We are seeking a motivated and safety-conscious Tower Technician to join our team, specializing in cellular...  ...quality standards. Qualifications Previous experience in tower climbing, cellular maintenance, or related telecommunications work...