Talent.com
SIEM Engineer
SIEM EngineerSeneca Resources • Fort Belvoir, Virginia, United States
No longer accepting applications
SIEM Engineer

SIEM Engineer

Seneca Resources • Fort Belvoir, Virginia, United States
19 days ago
Job type
  • Full-time
Job description

Job Title : Sr. SIEM Engineer (Elastic + Confluent)

Location : 100% Onsite at Fort Belvoir, VA

Mode : Contract

Required Certification : Security +

JD :

Seeking a Sr. SIEM Engineer specializing in Elastic Stack and Confluent in support of the PEO Enterprise SIEM Consolidation / Cyber Defense effort. This effort is focused on the consolidation of PEO Enterprise multiple SIEM solutions (approx. 40) into one consolidated SIEM. This individual should have extensive experience with Security Information and Event Management (SIEM) deployment and tuning as well as Security Orchestration Automation and Response (SOAR) development and implementation.

Responsibilities :

  • Design, deploy, configure, and maintain Elastic stack and Confluent deployments
  • Manage, patch, and upgrade Elasticsearch, Confluent, and other related systems
  • Tune and optimize Elastic stack deployments based on application / customer needs
  • Design and configure ETL data pipelines to ingest customer defined data sets such as application logs, metrics, and or threat events
  • Create custom visualizations and dashboards using Kibana
  • Configure and maintain index templates and information lifecycle management (ILM) policies
  • Develop Elastic alerting solutions using Watcher and / or Kibana Rules and Connectors with integrations to ticketing systems, email, and messaging apps as required
  • Develop Machine Learning (ML) jobs to dynamically monitor and alert on identified metrics, KPIs, and / or data anomalies
  • Follow ITIL based change management processes to move solutions from Dev to Test and into Production
  • Run the day-to-day operations of the security operations center
  • Investigate incidents and lead response efforts as applicable

Required Skills :

  • A Secret clearance will be required to maintain this position
  • Compliance with DoD 8140 / 8570 IAT Level II certification prior to start date
  • At least 5 years of hands-on experience in deployment, configuration, and solution development using the Elastic Stack for security and logging use-cases. Specific experience with Elastic SIEM is plus
  • Demonstrated experience with the full Elastic Stack - Elasticsearch, Logstash, Kibana, Beats, Machine Learning, and REST API integration
  • Experience integrating Elasticsearch with external systems (e.g. SOAR tools, Threat Intel Platforms)
  • Experience with data management : hot / warm / cold architectures, shard allocation / re-allocation, snapshots & restoration
  • Strong experience with evaluating existing Elastic clusters, configuration parameters, indexing, search and query performance tuning, security, and cluster administration
  • Experience integrating Elasticsearch with alternate authentication mechanisms such as SAML, LDAP, and PKI
  • Experience with supporting the Elastic Stack in on-prem and SaaS environments including system monitoring and tuning
  • Experience securing the Elastic stack and hardening hosting environments
  • Experience with the design and implement of highly scalable solutions using the Elastic Stack
  • Experience in developing data structures, data mapping from various sources to achieve data normalization using Elastic Common Schema
  • Experience developing Logstash and / or Elastic Ingest Pipelines
  • Experience developing custom visualizations and dashboards using Kibana, including creating specialized reporting solutions through Elasticsearch and Kibana APIs to meet complex stakeholder requirements
  • Experience in end-to-end Low-level design, development, administration, and delivery of Elasticsearch based reporting solutions
  • Strong technical foundation in building reliable, scalable, and supportable systems
  • Experienced in Red Hat Enterprise Linux deployment and administration
  • Desired Skills :

  • Experience using and developing Ansible playbooks for automation of system deployment and / or configuration
  • Experience with developing in multiple languages (Python, Bash, PowerShell, Painless, etc.).
  • Understanding of the MITRE ATT&CK framework
  • Certified Elastic Engineer or willingness to gain certification within 90 days of hire
  • Experience with cloud environments (e.g., Azure, AWS, GCP, etc.) and cloud security architecture
  • Experience condensing large environments to a single pane of glass view to facilitate optimal operational efficiency
  • Experience leading incident response and forensic investigative initiatives
  • Demonstrated ability to create and present executive level briefings
  • Experience with Army policies, regulations, and processes preferred
  • About Seneca Resources

    At Seneca Resources, we are more than just a staffing and consulting firm, we are a trusted career partner. With offices across the U.S. and clients ranging from Fortune 500 companies to government organizations, we provide opportunities that help professionals grow their careers while making an impact.

    When you work with Seneca, you’re choosing a company that invests in your success, celebrates your achievements, and connects you to meaningful work with leading organizations nationwide. We take the time to understand your goals and match you with roles that align with your skills and career path. Our consultants and contractors enjoy competitive pay, comprehensive health, dental, and vision coverage, 401(k) retirement plans, and the support of a dedicated team who will advocate for you every step of the way.

    Seneca Resources is proud to be an Equal Opportunity Employer, committed to fostering a diverse and inclusive workplace where all qualified individuals are encouraged to apply.

    Create a job alert for this search

    Engineer Engineer • Fort Belvoir, Virginia, United States

    Related jobs
    Sr. SIEM Engineer (Elastic+Con

    Sr. SIEM Engineer (Elastic+Con

    USM • Fort Belvoir, VA, United States
    Temporary
    Company : Accenture (supporting Army).SIEM Engineer (Elastic+Confluence).Citizenship : US Citizen (able to obtain Secret Clearance). Security+ or any IAT Level II Cert.Design, deploy, configure, and m...Show more
    Last updated: 16 hours ago • Promoted • New!
    Senior Lead AI Engineer

    Senior Lead AI Engineer

    Capital One • Fredericksburg, VA, US
    Full-time +1
    At Capital One, we are creating responsible and reliable AI systems, changing banking for good.For years, Capital One has been an industry leader in using machine learning to create real-time, pers...Show more
    Last updated: 30+ days ago • Promoted
    Sr MRI Technologist

    Sr MRI Technologist

    MedStar Health • Upper Marlboro, MD, US
    Full-time
    Now offering a limited-time $10,000 sign-on bonus!.Medstar Health is seeking a Sr MRI Technologist to join our team at Medstar Washington Hospital Center!. The Sr MRI Technologist performs magnetic ...Show more
    Last updated: 2 days ago • Promoted
    NAVAIR- Journeyman Linux System Administrator

    NAVAIR- Journeyman Linux System Administrator

    SimVentions, Inc • Compton, MD, US
    Full-time +1
    SimVentions is a 100% employee-owned business and has consistently been voted one of Virginia's Best Places to Work.SimVentions is seeking a System Administrator to maintain servers for compliance ...Show more
    Last updated: 8 hours ago • Promoted • New!
    Engineer, Strategic / Reliability

    Engineer, Strategic / Reliability

    Constellation Energy • Huntingtown, MD, US
    Full-time
    As the nation's largest producer of clean, carbon-free energy, Constellation is focused on our purpose : accelerating the transition to a carbon-free future. We have been the leader in clean ener...Show more
    Last updated: 4 hours ago • Promoted • New!
    Manager Engineering

    Manager Engineering

    Constellation Energy • Saint Leonard, MD, US
    Full-time
    As the nation's largest producer of clean, carbon-free energy, Constellation is focused on our purpose : accelerating the transition to a carbon-free future. We have been the leader in clean ener...Show more
    Last updated: 21 days ago • Promoted
    SIEM Engineers

    SIEM Engineers

    eTeam • Arlington, VA, United States
    Full-time
    Arlington, VA | Buffalo, NY | Des Moines, IA | Louisville, KY | Omaha, NE | Milwaukee, WI.AI-Driven Threat Detection & Response. Cybersecurity Engineering - SIEM Operations.This role is central to e...Show more
    Last updated: 16 hours ago • Promoted • New!
    Sr. SIEM Engineer (Elastic + Confluent)

    Sr. SIEM Engineer (Elastic + Confluent)

    Accenture Federal Services • Fort Belvoir, VA, United States
    Full-time
    At Accenture Federal Services, nothing matters more than helping the US federal government make the nation stronger and safer and life better for people. Our 13,000+ people are united in a shared pu...Show more
    Last updated: 16 hours ago • Promoted • New!
    Distinguished AI Engineer

    Distinguished AI Engineer

    Capital One • FREDERICKSBURG, Virginia, United States
    Full-time +1
    At Capital One, we are creating responsible and reliable AI systems, changing banking for good.For years, Capital One has been an industry leader in using machine learning to create real-time, pers...Show more
    Last updated: 30+ days ago • Promoted
    Collision Estimator

    Collision Estimator

    Crash Champions • MECHANICSVILLE, Maryland, US
    Full-time
    As one of the fastest-growing and most exciting brands in the industry, Crash Champions is the largest founder-led multi-shop operator (MSO) of high-quality collision repair service in the U.The co...Show more
    Last updated: 13 hours ago • Promoted • New!
    Senior AFSIM Analyst

    Senior AFSIM Analyst

    The Johns Hopkins University Applied Physics Laboratory • Laurel, MD, United States
    Temporary
    Are you searching for an opportunity to apply your AFSIM modeling and simulation experience to analyze interesting and complex problems with innovative software and computing capabilities?.If so, w...Show more
    Last updated: 30+ days ago • Promoted
    AFSIM Analyst

    AFSIM Analyst

    The Johns Hopkins University Applied Physics Laboratory • Laurel, MD, United States
    Temporary
    Are you searching for an opportunity to apply your modeling and simulation analysis background in an engaging, collegiate environment?. Are you passionate about analyzing complex problems with state...Show more
    Last updated: 30+ days ago • Promoted
    SIEM Specialist

    SIEM Specialist

    Dunhill Professional Search • Alexandria, VA, US
    Full-time
    Be responsible for designing & setting up the ingestion of various customer data flows to include pre-processing data into a useable format, ensuring proper parsing and indexing.Collaborate with cr...Show more
    Last updated: 19 days ago • Promoted
    Sr. SIEM Engineer (Elastic + Confluent)

    Sr. SIEM Engineer (Elastic + Confluent)

    Accenture • Fort Belvoir, VA, United States
    Full-time
    At Accenture Federal Services, nothing matters more than helping the US federal government make the nation stronger and safer and life better for people. Our 13,000+ people are united in a shared pu...Show more
    Last updated: 14 hours ago • Promoted • New!
    SIEM Engineer

    SIEM Engineer

    Tyto Athene, LLC • Washington, DC, United States
    Full-time
    Tyto Athene is seeking an experienced.In addition to SIEM engineering, you will be helping to administer a variety of other security tools within the client environment. Administer the client's SaaS...Show more
    Last updated: 30+ days ago • Promoted
    Sr Electronics Design Engineer

    Sr Electronics Design Engineer

    Leidos • Accokeek, MD, US
    Full-time
    The National Airspace Systems Integration Support (NISC) program at Leidos is seeking.Senior Electronics Design Engineers. Federal Aviation Administration (FAA) Eastern Service Area - Engineering Se...Show more
    Last updated: 10 days ago • Promoted
    Engineering Analyst, Strategic / Reliability

    Engineering Analyst, Strategic / Reliability

    Constellation Energy • Benedict, MD, US
    Full-time
    As the nation's largest producer of clean, carbon-free energy, Constellation is focused on our purpose : accelerating the transition to a carbon-free future. We have been the leader in clean ener...Show more
    Last updated: less than 1 hour ago • Promoted • New!
    NAVAIR - Software Development and Acquisitions Analyst

    NAVAIR - Software Development and Acquisitions Analyst

    SimVentions, Inc • Coltons Point, MD, US
    Full-time
    SimVentions is a 100% employee-owned business and has consistently been voted one of Virginia's Best Places to Work.We are seeking a detail-oriented candidate with extensive knowledge of computer o...Show more
    Last updated: 8 hours ago • Promoted • New!