Sr. SIEM Engineer (Elastic + Confluent) jobs in United States
cer-icon
Apply on Employer Site
company-logo

Accenture Federal Services · 15 hours ago

Sr. SIEM Engineer (Elastic + Confluent)

Accenture Federal Services is dedicated to enhancing the US federal government's capabilities through technology and innovation. They are seeking a Senior SIEM Engineer specializing in Elastic Stack and Confluent to support the consolidation of multiple SIEM solutions into one comprehensive system, focusing on deployment, tuning, and security orchestration.

ConsultingFinanceInformation TechnologyManagement ConsultingOnline PortalsProfessional Services
badNo H1BnoteSecurity Clearance RequirednoteU.S. Citizen Onlynote

Responsibilities

Design, deploy, configure, and maintain Elastic stack and Confluent deployments
Manage, patch, and upgrade Elasticsearch, Confluent, and other related systems
Tune and optimize Elastic stack deployments based on application/customer needs
Design and configure ETL data pipelines to ingest customer defined data sets such as application logs, metrics, and or threat events
Create custom visualizations and dashboards using Kibana
Configure and maintain index templates and information lifecycle management (ILM) policies
Develop Elastic alerting solutions using Watcher and/or Kibana Rules and Connectors with integrations to ticketing systems, email, and messaging apps as required
Develop Machine Learning (ML) jobs to dynamically monitor and alert on identified metrics, KPIs, and/or data anomalies
Follow ITIL based change management processes to move solutions from Dev to Test and into Production
Run the day-to-day operations of the security operations center
Investigate incidents and lead response efforts as applicable

Qualification

Elastic StackConfluentSIEM deploymentSOAR developmentCompTIA Security+ CEKibanaMachine LearningAnsiblePythonBashPowerShellPainlessMITRE ATT&CKCloud environmentsRed Hat Enterprise Linux

Required

Secret clearance is required to maintain this position
Compliance with one of the DoD 8140 / 8570 IAT Level II certification prior to start date (CompTIA Security+ CE, CySA+, CCNA Security, GSEC, GICSP)
3+ years of hands-on experience in deployment, configuration, and solution development using the Elastic Stack for security and logging use-cases
Demonstrated experience with the full Elastic Stack: Elasticsearch, Logstash, Kibana, Beats, Machine Learning, and REST API integration
Experience in developing data structures and data mapping from various sources to achieve data normalization using Elastic Common Schema
Experience developing Logstash and/or Elastic Ingest Pipelines
Experience developing custom visualizations and dashboards using Kibana, including creating specialized reporting solutions through Elasticsearch and Kibana APIs to meet complex stakeholder requirements
Certified Elastic Engineer or willingness to gain certification within 90 days of hire

Preferred

Experience using and developing Ansible playbooks for automation of system deployment and/or configuration
Experience with developing in multiple languages (Python, Bash, PowerShell, Painless, etc.)
Understanding of the MITRE ATT&CK framework
Experience with cloud environments (e.g., Azure, AWS, GCP, etc.) and cloud security architecture
Experience integrating Elasticsearch with external systems (e.g., SOAR tools, Threat Intel Platforms) and alternate authentication mechanisms such as SAML, LDAP, and PKI
Experience with data management: hot/warm/cold architectures, shared allocation/re-allocation, snapshots & restoration
Strong experience with evaluating existing Elastic clusters, configuration parameters, indexing, search and query performance tuning, security, and cluster administration
Experience supporting the Elastic Stack in on-prem and SaaS environments, including system monitoring and tuning, securing the Elastic Stack, and hardening hosting environments
Experience with the design and implementation of highly scalable solutions using the Elastic Stack
Experience in end-to-end low-level design, development, administration, and delivery of Elasticsearch-based reporting solutions
Strong technical foundation in building reliable, scalable, and supportable systems
Experience in Red Hat Enterprise Linux deployment and administration

Benefits

Accenture Federal Services offers a wide variety of benefits.

Company

Accenture Federal Services

company-logo
Accenture Federal Services is a leading US federal services company and subsidiary of Accenture.

Funding

Current Stage
Late Stage

Leadership Team

leader-logo
Ron Ash
CEO and Chairman of the Board
linkedin
leader-logo
Bharat Patel
Managing Director, AI Missions
linkedin
Company data provided by crunchbase