Cyber Security Incident and Event Management/Elastic Specialist Job at Diligent Consulting Inc, Washington DC

TXVVY05kckRUbnV2TGNPenNRSUdDb0YwdlE9PQ==
  • Diligent Consulting Inc
  • Washington DC

Job Description

US CITIZEN ONLY. SECRET CLEARANCE REQUIRED.  MUST HAVE IT-II CERT (IE SECURITY+)

SIEM/Elastic Specialist will:

• Be responsible for designing & setting up the ingestion of various customer data flows to include pre-processing data into a useable format, ensuring proper parsing and indexing
• Collaborate with cross-functional teams and responsible for designing & integrating Elastic with a wide variety of data sources and developing associated knowledge objects such as queries, dashboards, reports, alerts for monitoring and analytics
• Perform data transformation using Elastic query language 
• Track the health of the Elastic environment and optimize its performance. Troubleshoot and resolve issues related to security, performance, data indexing, and searches
• Perform watch-officer monitoring duties, including:
○ monitoring, detecting, investigating, and responding to cybersecurity threats and events using Elastic /SIEM Platform
○ Reviewing correlated alerts and logs for compromise scenarios
○ Performing triage of security alerts to prioritize response
○ Identifying false positives
○ Investigating security incidents and determining root cause
○ Collecting and preserving logs for analysis
○ Escalating confirmed incidents to leadership or SOC teams
○ Coordinating with IT or DevOps for containment and remediation
○ Creating after-action reports (AAR) post-incident
• In addition, the role may include assistance with monitoring Vulnerability Management tools, such as ACAS and ePO.

QUALIFICATIONS:

• Have at least three years of working knowledge and hands-on experience with Elastic/Splunk query languages, monitoring SIEM dashboards and real-time alerts, fine-tuning SIEM rules to reduce noise, and NIST 800-53 & DevSecOps frameworks

 

Job Tags

Full time,

Similar Jobs

NorthPoint Search Group

Corporate Tax Partner Job at NorthPoint Search Group

 ...major market practice and play a pivotal role in expanding tax compliance and provision outsourcing services for middle-market and private equitybacked clients. Office Environment: An entrepreneurial, collaborative, growth-focused culture that blends big-firm resources... 

Signature Healthcare

Physician Assistant, Critical Care Unit Job at Signature Healthcare

 ...Signature Healthcare is recruiting for a Physician Assistant role, who by virtue of advanced training and experience, is qualified to function in a collaborative role with the attending surgeon in the Critical Care Unit at the hospital. Graduate of an approved Physician... 

Dogtopia

Canine Coach Playroom Attendant Job at Dogtopia

Bring your dog to work? Thats right! Dogtopia, the industry leader in dog daycare, boarding, and spa services has an immediate opening for an energetic, organized, and safety-minded individual that will ensure our dogs are safe and having fun as a Canine Coach. This person...

Jacobs & CO Mortgage

Mortgage Loan Originator Job at Jacobs & CO Mortgage

 ...to clients, tailoring services to meet their unique needs and circumstances. We are seeking a dedicated and experienced Mortgage Loan Originator to join our team on-site. The ideal candidate will be responsible for assisting clients in securing mortgage loans, providing... 

GDIT

Senior Salesforce Scrum Master Job at GDIT

 ...this Position Location: Any Location / Remote Full Part/Time: Full time Job Req:...  ...JIRA, Leadership, Salesforce (Software), Scrum Certifications: None Experience:...  ...our work depends on a Salesforce Scrum Master remotely joining our Federal Services...