Cyber Security Incident and Event Management/Elastic Specialist Job at Diligent Consulting Inc, Washington DC

TjFFNS94c3B4eXdQS3VpeHQ1UUdyRUtrTVE9PQ==
  • Diligent Consulting Inc
  • Washington DC

Job Description

US CITIZEN ONLY. SECRET CLEARANCE REQUIRED.  MUST HAVE IT-II CERT (IE SECURITY+)

SIEM/Elastic Specialist will:

• Be responsible for designing & setting up the ingestion of various customer data flows to include pre-processing data into a useable format, ensuring proper parsing and indexing
• Collaborate with cross-functional teams and responsible for designing & integrating Elastic with a wide variety of data sources and developing associated knowledge objects such as queries, dashboards, reports, alerts for monitoring and analytics
• Perform data transformation using Elastic query language 
• Track the health of the Elastic environment and optimize its performance. Troubleshoot and resolve issues related to security, performance, data indexing, and searches
• Perform watch-officer monitoring duties, including:
○ monitoring, detecting, investigating, and responding to cybersecurity threats and events using Elastic /SIEM Platform
○ Reviewing correlated alerts and logs for compromise scenarios
○ Performing triage of security alerts to prioritize response
○ Identifying false positives
○ Investigating security incidents and determining root cause
○ Collecting and preserving logs for analysis
○ Escalating confirmed incidents to leadership or SOC teams
○ Coordinating with IT or DevOps for containment and remediation
○ Creating after-action reports (AAR) post-incident
• In addition, the role may include assistance with monitoring Vulnerability Management tools, such as ACAS and ePO.

QUALIFICATIONS:

• Have at least three years of working knowledge and hands-on experience with Elastic/Splunk query languages, monitoring SIEM dashboards and real-time alerts, fine-tuning SIEM rules to reduce noise, and NIST 800-53 & DevSecOps frameworks

 

Job Tags

Full time,

Similar Jobs

Confidential

Manufacturing Welder Job at Confidential

 ...Title: Manufacturing Welder Location: Alabama 36605 Contract Duration: 12 months (with potential extension)...  ...opportunity. The ideal candidate will be responsible for performing welding operations in accordance with engineering drawings, specifications... 

Kaleidoscope Education Solutions

Certified ESL Teacher Job at Kaleidoscope Education Solutions

 ...Our client is seeking ESL Teachers in Woodlyn, PA . Does it excite you to make a profound difference in the lives of students by empowering them to succeed and achieve their dreams? If so, send your resume today! CLIENT REQUIRED QUALIFICATIONS: Bachelor's... 

Kaltura

Sales Operations Manager Job at Kaltura

 ...you think this is a role that would make you excited about coming to work every day. REQUIREMENTS The role: The Sales Operations Manager / Business Operations Partner (BOP) plays a crucial role in the operations of our business units. As an operational... 

Pacific Aerospace & Electronics

New Product Introduction Engineer Job at Pacific Aerospace & Electronics

 ...technical skills listening action-oriented composure and values diversity. In addition to the requirements noted above all employees of PAE are expected to: Promote teamwork and cooperative effort Help train and give guidance to employees Maintain a clean safe and... 

NoGigiddy

Chat Support Agent (Remote) - Entry Level, No Degree Required - 15 - 18 per Hour Job at NoGigiddy

About NoGigiddy: NoGigiddy is a premier on-demand staffing app that connects gig workers with flexible job opportunities across various industries. Our platform specializes in offering work that fits your schedule, providing you with the flexibility and convenience...