Cyber Security Incident and Event Management/Elastic Specialist Job at Diligent Consulting Inc, Washington DC

bFYwTzJjdTZwZmZUUjA4N041V1hLNjNDVVE9PQ==
  • Diligent Consulting Inc
  • Washington DC

Job Description

US CITIZEN ONLY. SECRET CLEARANCE REQUIRED.  MUST HAVE IT-II CERT (IE SECURITY+)

SIEM/Elastic Specialist will:

• Be responsible for designing & setting up the ingestion of various customer data flows to include pre-processing data into a useable format, ensuring proper parsing and indexing
• Collaborate with cross-functional teams and responsible for designing & integrating Elastic with a wide variety of data sources and developing associated knowledge objects such as queries, dashboards, reports, alerts for monitoring and analytics
• Perform data transformation using Elastic query language 
• Track the health of the Elastic environment and optimize its performance. Troubleshoot and resolve issues related to security, performance, data indexing, and searches
• Perform watch-officer monitoring duties, including:
○ monitoring, detecting, investigating, and responding to cybersecurity threats and events using Elastic /SIEM Platform
○ Reviewing correlated alerts and logs for compromise scenarios
○ Performing triage of security alerts to prioritize response
○ Identifying false positives
○ Investigating security incidents and determining root cause
○ Collecting and preserving logs for analysis
○ Escalating confirmed incidents to leadership or SOC teams
○ Coordinating with IT or DevOps for containment and remediation
○ Creating after-action reports (AAR) post-incident
• In addition, the role may include assistance with monitoring Vulnerability Management tools, such as ACAS and ePO.

QUALIFICATIONS:

• Have at least three years of working knowledge and hands-on experience with Elastic/Splunk query languages, monitoring SIEM dashboards and real-time alerts, fine-tuning SIEM rules to reduce noise, and NIST 800-53 & DevSecOps frameworks

 

Job Tags

Full time,

Similar Jobs

COOLSOFT

Agile Development Salesforce Experience SCRUM Consultant Job at COOLSOFT

Agile Development Salesforce Experience SCRUM Consultant(Jobs in Columbus, OH) Requirement id 156111 Job title Consultant Job location in Columbus, OH Skills required Sales Cloud, SFDC Experience, Data Migration, Agile Development Salesforce Experience Open Date... 

Melinda Instal

Home Based Data Entry Clerk Job at Melinda Instal

Ez egy tvmunkban vgezhet lls. We are looking for a detail-oriented and efficient Home Based Data Entry Clerk to join our team at Melinda Instal. As a key player in the Construction industry, you will be responsible for accurately entering and updating data to ...

Teton Science Schools

AmeriCorps Service Member at Teton Science Schools Job at Teton Science Schools

 ...The Teton Science Schools (TSS) AmeriCorps program develops service members as educators. Our service members are actively engaged in growing Science, Technology, Engineering and Math (STEM) literacy in the community. Through involvement with TSS and other local partners... 

AECOM

Senior Project Archaeologist Job at AECOM

 ...requirement of the position. The Senior Project Archaeologist will have extensive knowledge of field excavation techniques, implement archaeological inventory, evaluation, and data recovery efforts, analyze prehistoric and historic artifacts, and prepare compliance reports.... 

SmartHire Inc

LEGAL OPERATIONS MANAGER Job at SmartHire Inc

 ...Legal Operations Manager Location: Seattle, WA 98101 (On-site) Job Type: Full-Time | Direct Hire (Confidential Posted by SmartHire on behalf of our client) About the Company Founded over 40 years ago, our client is a global leader in Alternative Dispute...