Cyber Security Incident and Event Management/Elastic Specialist Job at Diligent Consulting Inc, Washington DC

U2JKYkU5SWxkSk5BNHBNbFBOeFJibUFSNFE9PQ==
  • Diligent Consulting Inc
  • Washington DC

Job Description

US CITIZEN ONLY. SECRET CLEARANCE REQUIRED.  MUST HAVE IT-II CERT (IE SECURITY+)

SIEM/Elastic Specialist will:

• Be responsible for designing & setting up the ingestion of various customer data flows to include pre-processing data into a useable format, ensuring proper parsing and indexing
• Collaborate with cross-functional teams and responsible for designing & integrating Elastic with a wide variety of data sources and developing associated knowledge objects such as queries, dashboards, reports, alerts for monitoring and analytics
• Perform data transformation using Elastic query language 
• Track the health of the Elastic environment and optimize its performance. Troubleshoot and resolve issues related to security, performance, data indexing, and searches
• Perform watch-officer monitoring duties, including:
○ monitoring, detecting, investigating, and responding to cybersecurity threats and events using Elastic /SIEM Platform
○ Reviewing correlated alerts and logs for compromise scenarios
○ Performing triage of security alerts to prioritize response
○ Identifying false positives
○ Investigating security incidents and determining root cause
○ Collecting and preserving logs for analysis
○ Escalating confirmed incidents to leadership or SOC teams
○ Coordinating with IT or DevOps for containment and remediation
○ Creating after-action reports (AAR) post-incident
• In addition, the role may include assistance with monitoring Vulnerability Management tools, such as ACAS and ePO.

QUALIFICATIONS:

• Have at least three years of working knowledge and hands-on experience with Elastic/Splunk query languages, monitoring SIEM dashboards and real-time alerts, fine-tuning SIEM rules to reduce noise, and NIST 800-53 & DevSecOps frameworks

 

Job Tags

Full time,

Similar Jobs

Link Jobs

Physical Therapist (FT) Home Health - South Fulton Job at Link Jobs

 ...Company : LinkJobs was founded in Atlanta, Georgia, by a medical doctor with 30+ years of experience owning and operating businesses...  ...: ~ Autonomy to create your own Schedule!~ Medical Insurance ~ Dental Insurance ~ Vision Insurance ~ Paid Days Off ~... 

Electrical Solutions, Inc.

Electrical Project Manager Job at Electrical Solutions, Inc.

Summary: Perform electrical estimating and project management oversight on projects of various sizes including commercial and industrial type projects. The successful candidate should have a background not only in managing electrical construction but also in electrical... 

Pacific Shipyards International, LLC

Marine Mechanic Job at Pacific Shipyards International, LLC

 ...Candidates must have access to reliable transportation to get to work and other job sites on time for the start of shift Pacific Shipyards International, LLC Expectations of Employee Is committed to the company values and adheres to all Pacific Shipyards policies... 

LifeMD

Compounding Pharmacy Technician Job at LifeMD

 ...healthcare company committed to expanding access to virtual care, pharmacy services, and diagnostics by making them more affordable...  ..., and compassionate care. About the role The Compounding Pharmacy Technician plays a critical role in the preparation of customized... 

Freshpoint

Non CDL Driver Job at Freshpoint

Happy Holidays FreshPoint Is Hiring Non CDL Drivers !! Walk in Event every WednesdayTime 10am -230pmBase Pay $21.57Requirements One-year route delivery experience or applicable background driving a straight truckValid Class C Driver's License (No CDL Required)...