Cyber Security Incident and Event Management/Elastic Specialist Job at Diligent Consulting Inc, Washington DC

ZXBHR3Q0ZmZlMWQ2TFJzZm1nSWJ2cGVGUkE9PQ==
  • Diligent Consulting Inc
  • Washington DC

Job Description

US CITIZEN ONLY. SECRET CLEARANCE REQUIRED.  MUST HAVE IT-II CERT (IE SECURITY+)

SIEM/Elastic Specialist will:

• Be responsible for designing & setting up the ingestion of various customer data flows to include pre-processing data into a useable format, ensuring proper parsing and indexing
• Collaborate with cross-functional teams and responsible for designing & integrating Elastic with a wide variety of data sources and developing associated knowledge objects such as queries, dashboards, reports, alerts for monitoring and analytics
• Perform data transformation using Elastic query language 
• Track the health of the Elastic environment and optimize its performance. Troubleshoot and resolve issues related to security, performance, data indexing, and searches
• Perform watch-officer monitoring duties, including:
○ monitoring, detecting, investigating, and responding to cybersecurity threats and events using Elastic /SIEM Platform
○ Reviewing correlated alerts and logs for compromise scenarios
○ Performing triage of security alerts to prioritize response
○ Identifying false positives
○ Investigating security incidents and determining root cause
○ Collecting and preserving logs for analysis
○ Escalating confirmed incidents to leadership or SOC teams
○ Coordinating with IT or DevOps for containment and remediation
○ Creating after-action reports (AAR) post-incident
• In addition, the role may include assistance with monitoring Vulnerability Management tools, such as ACAS and ePO.

QUALIFICATIONS:

• Have at least three years of working knowledge and hands-on experience with Elastic/Splunk query languages, monitoring SIEM dashboards and real-time alerts, fine-tuning SIEM rules to reduce noise, and NIST 800-53 & DevSecOps frameworks

 

Job Tags

Full time,

Similar Jobs

University of Maryland Medical System

Career Coach Clinical Pathways Job at University of Maryland Medical System

 ...participants, and current University of Maryland Medical System team members for entry into and advancement within clinical careers through systemwide career coaching, barrier resolution, and wraparound support. This position plays a critical role in strengthening the clinical... 

WK Kellogg Co

Environmental Health and Safety Manager Job at WK Kellogg Co

 ...this effort. The Battle Creek Plant Environmental Health & Safety Manager is a member of the site Senior Leadership Team that is...  ...you to assist in the completion of regulatory reports for EPA, OSHA, and other regulatory agencies. Influence and planning you... 

Sweet Tooth Pediatric Dentistry

Pediatric Dental Hygienist Job at Sweet Tooth Pediatric Dentistry

 ...Pediatric Dental Hygienist Opportunity Job Description Sweet Tooth Pediatric Dentistry is thrilled to announce an opening for a Pediatric Dental Hygienist in our dynamic team. This position (3-4 days) is designed for a dedicated and energetic individual who is passionate... 

GIA Legacy Planning

Independent Sales Agent - Work from Home Job at GIA Legacy Planning

 ...Independent Sales Agent Location: Remote Position/Work from Home Job Type: Full-Time/Part-Time/Uncapped Commission-Based About Us: GIA Legacy Planning is a welcoming, client-focused insurance agency where people come firstboth our clients and our team... 

McEwen & Associates, Inc

Medical Appointment Scheduler Job at McEwen & Associates, Inc

 ...Position Overview: As a Medical Scheduler, you will be the first point of contact for patients seeking to schedule, reschedule, or cancel appointments. Your role is crucial in providing exceptional customer service, ensuring accurate appointment scheduling, and maintaining...