Cyber Security Incident and Event Management/Elastic Specialist Job at Diligent Consulting Inc, Washington DC

MUZsSnpwa21keVQrZGtZa2R0K3c0MVk3SlE9PQ==
  • Diligent Consulting Inc
  • Washington DC

Job Description

US CITIZEN ONLY. SECRET CLEARANCE REQUIRED.  MUST HAVE IT-II CERT (IE SECURITY+)

SIEM/Elastic Specialist will:

• Be responsible for designing & setting up the ingestion of various customer data flows to include pre-processing data into a useable format, ensuring proper parsing and indexing
• Collaborate with cross-functional teams and responsible for designing & integrating Elastic with a wide variety of data sources and developing associated knowledge objects such as queries, dashboards, reports, alerts for monitoring and analytics
• Perform data transformation using Elastic query language 
• Track the health of the Elastic environment and optimize its performance. Troubleshoot and resolve issues related to security, performance, data indexing, and searches
• Perform watch-officer monitoring duties, including:
○ monitoring, detecting, investigating, and responding to cybersecurity threats and events using Elastic /SIEM Platform
○ Reviewing correlated alerts and logs for compromise scenarios
○ Performing triage of security alerts to prioritize response
○ Identifying false positives
○ Investigating security incidents and determining root cause
○ Collecting and preserving logs for analysis
○ Escalating confirmed incidents to leadership or SOC teams
○ Coordinating with IT or DevOps for containment and remediation
○ Creating after-action reports (AAR) post-incident
• In addition, the role may include assistance with monitoring Vulnerability Management tools, such as ACAS and ePO.

QUALIFICATIONS:

• Have at least three years of working knowledge and hands-on experience with Elastic/Splunk query languages, monitoring SIEM dashboards and real-time alerts, fine-tuning SIEM rules to reduce noise, and NIST 800-53 & DevSecOps frameworks

 

Job Tags

Full time,

Similar Jobs

Keller Executive Search International

Senior Director of Crisis Management Job at Keller Executive Search International

 ...Our client is seeking a dynamic and experienced Senior Director of Crisis Management to lead their company's crisis response initiatives. In this critical role, you will develop and implement strategies to prepare for, respond to, and recover from various crises affecting... 

Advocates Legal Recruiting

Real Estate Associate - Jr to Mid-level Job at Advocates Legal Recruiting

 ...Real Estate Associate Junior to Mid-Level | Seattle Confidential search on behalf of a premier AmLaw 100 firm. Our AmLaw...  ...ventures across sectors ranging from commercial to mixed-use development. The team is collaborative, fast-moving, and trusted by major... 

Baylor Scott & White Health

Internal Medicine Physician Job at Baylor Scott & White Health

**JOB SUMMARY**Baylor Scott & White Health is seeking a Board Certified/Board Eligible Internal Medicine physician to join an established Primary Care group that is located in Midlothian, Texas. This is an employed career opportunity with a generous benefits package that... 

Integrity Technical Services

MIG and TIG Welder Job at Integrity Technical Services

 ...Multiple Opportunities on 1st, 2nd, and 3rd Shift. Canton, Ohio area Steel Manufacturing and Fabrication Firm seeks experienced MIG and TIG Welders who have hands-on experience welding light gauge aluminum, carbon and stainless steel. REQUIREMENTS: High School, GED,... 

JPMorgan Chase

UX Content Writer, Senior Associate Job at JPMorgan Chase

 ...collaborate closely with design, tech, and product partners while enjoying being part of a wider content community of practice.As a UX Content Writer, Senior Associate at JPMorganChase, you'll play a pivotal role in shaping customer experiences through content and language,...