Cyber Security Incident and Event Management/Elastic Specialist Job at Diligent Consulting Inc, Washington DC

NjhwVUJBaWczdzRtYlRaanArZGp0Sk5nUHc9PQ==
  • Diligent Consulting Inc
  • Washington DC

Job Description

US CITIZEN ONLY. SECRET CLEARANCE REQUIRED.  MUST HAVE IT-II CERT (IE SECURITY+)

SIEM/Elastic Specialist will:

• Be responsible for designing & setting up the ingestion of various customer data flows to include pre-processing data into a useable format, ensuring proper parsing and indexing
• Collaborate with cross-functional teams and responsible for designing & integrating Elastic with a wide variety of data sources and developing associated knowledge objects such as queries, dashboards, reports, alerts for monitoring and analytics
• Perform data transformation using Elastic query language 
• Track the health of the Elastic environment and optimize its performance. Troubleshoot and resolve issues related to security, performance, data indexing, and searches
• Perform watch-officer monitoring duties, including:
○ monitoring, detecting, investigating, and responding to cybersecurity threats and events using Elastic /SIEM Platform
○ Reviewing correlated alerts and logs for compromise scenarios
○ Performing triage of security alerts to prioritize response
○ Identifying false positives
○ Investigating security incidents and determining root cause
○ Collecting and preserving logs for analysis
○ Escalating confirmed incidents to leadership or SOC teams
○ Coordinating with IT or DevOps for containment and remediation
○ Creating after-action reports (AAR) post-incident
• In addition, the role may include assistance with monitoring Vulnerability Management tools, such as ACAS and ePO.

QUALIFICATIONS:

• Have at least three years of working knowledge and hands-on experience with Elastic/Splunk query languages, monitoring SIEM dashboards and real-time alerts, fine-tuning SIEM rules to reduce noise, and NIST 800-53 & DevSecOps frameworks

 

Job Tags

Full time,

Similar Jobs

Donnelley Financial Solutions

Customer Success Manager - Remote Job at Donnelley Financial Solutions

 ...One mentality ensures that our teams success is directly linked to Client,...  ...is seeking a proactive and strategic Customer Success Manager to serve as a trusted advisor for our...  ...Customer Success and is designated as Remote. Location: This is a fully remote... 

Aramark

General Utility Worker - UH Hilton - UH - Hilton Job at Aramark

Job Description Are you self-motivated and proud of the work you do? Here at Aramark, we take pride in the level of service and safety we provide! As a General Utility Worker on our team of other service stars, youll take on the important task of maintaining the cleanliness...

New Haven Assisted Living of Schertz

Caregiver Job at New Haven Assisted Living of Schertz

 ...personal care and psychosocial support to residents. You will assist with activities of daily living, housekeeping, cooking and activities. You will...  ...school diploma or GED.* Must have experience as a caregiver and working with individuals diagnosed with Dementia.... 

GP Mobile

T Mobile Authorized Retailer Store Manager Job at GP Mobile

 ...#ConnectedCulture Be unstoppable with us! Job Overview: As a Retail Store Manager, youre ready to lead by example, go All IN, and rally...  ...Knowledge, Skills and Abilities: Communication (Required) Microsoft Office (Required) Store Management (Required) Store... 

HB Travels

Online Travel Agent (Remote) Job at HB Travels

About Us: We are a travel services company committed to helping clients plan and book memorable travel experiences. By working with top travel providers, we deliver reliable support, personalized recommendations, and smooth booking processes. Position Overview:...