SIEM / Elastic Specialist will :
Be responsible for designing & setting up the ingestion of various customer data flows to include pre-processing data into a useable format, ensuring proper parsing and indexing.
Collaborate with cross-functional teams and responsible for designing & integrating Elastic with a wide variety of data sources and developing associated knowledge objects such as queries, dashboards, reports, alerts for monitoring and analytics.
Perform data transformation using Elastic query language.
Track the health of the Elastic environment and optimize its performance.
Troubleshoot and resolve issues related to security, performance, data indexing, and searches
Perform watch-officer monitoring duties, including :
In addition, the role may include assistance with monitoring Vulnerability Management tools, such as ACAS and ePO
Specialist Specialist • Alexandria, VA, US