Cyber Security Incident and Event Management/Elastic Specialist jobs in United States
cer-icon
Apply on Employer Site
company-logo

Diligent Consulting Inc ยท 2 months ago

Cyber Security Incident and Event Management/Elastic Specialist

Diligent Consulting Inc is seeking a Cyber Security Incident and Event Management/Elastic Specialist. The role involves designing and setting up data ingestion, collaborating with teams for Elastic integration, and performing monitoring duties related to cybersecurity threats and incidents.

HardwareSoftware
check
Work & Life Balance
badNo H1BnoteSecurity Clearance RequirednoteU.S. Citizen Onlynote

Responsibilities

Be responsible for designing & setting up the ingestion of various customer data flows to include pre-processing data into a useable format, ensuring proper parsing and indexing
Collaborate with cross-functional teams and responsible for designing & integrating Elastic with a wide variety of data sources and developing associated knowledge objects such as queries, dashboards, reports, alerts for monitoring and analytics
Perform data transformation using Elastic query language
Track the health of the Elastic environment and optimize its performance. Troubleshoot and resolve issues related to security, performance, data indexing, and searches
Perform watch-officer monitoring duties, including:
Monitoring, detecting, investigating, and responding to cybersecurity threats and events using Elastic /SIEM Platform
Reviewing correlated alerts and logs for compromise scenarios
Performing triage of security alerts to prioritize response
Identifying false positives
Investigating security incidents and determining root cause
Collecting and preserving logs for analysis
Escalating confirmed incidents to leadership or SOC teams
Coordinating with IT or DevOps for containment and remediation
Creating after-action reports (AAR) post-incident
In addition, the role may include assistance with monitoring Vulnerability Management tools, such as ACAS and ePO

Qualification

Elastic/Splunk query languagesSIEM monitoringNIST 800-53DevSecOps frameworksCybersecurity incident responseData transformationPerformance optimization

Required

US CITIZEN ONLY
SECRET CLEARANCE REQUIRED
MUST HAVE IT-II CERT (IE SECURITY+)
At least three years of working knowledge and hands-on experience with Elastic/Splunk query languages
Monitoring SIEM dashboards and real-time alerts
Fine-tuning SIEM rules to reduce noise
NIST 800-53 & DevSecOps frameworks

Company

Diligent Consulting Inc

twittertwitter
company-logo
Diligent Consulting Inc is an IT services provider delivering high quality solutions in Enterprise Architecture, Legacy System Revitalization & Transformation, Application Development, Cyber Security and Professional Services.

Funding

Current Stage
Growth Stage

Leadership Team

leader-logo
David Cerminaro
CEO/Owner
linkedin
Company data provided by crunchbase