Cyber Security Incident and Event Management/Elastic Specialist Job at Diligent Consulting Inc, Washington DC

emNva3V4YkMySDVSNGNiRXdzQ0lDbE9zRGc9PQ==
  • Diligent Consulting Inc
  • Washington DC

Job Description

US CITIZEN ONLY. SECRET CLEARANCE REQUIRED.  MUST HAVE IT-II CERT (IE SECURITY+)

SIEM/Elastic Specialist will:

• Be responsible for designing & setting up the ingestion of various customer data flows to include pre-processing data into a useable format, ensuring proper parsing and indexing
• Collaborate with cross-functional teams and responsible for designing & integrating Elastic with a wide variety of data sources and developing associated knowledge objects such as queries, dashboards, reports, alerts for monitoring and analytics
• Perform data transformation using Elastic query language 
• Track the health of the Elastic environment and optimize its performance. Troubleshoot and resolve issues related to security, performance, data indexing, and searches
• Perform watch-officer monitoring duties, including:
○ monitoring, detecting, investigating, and responding to cybersecurity threats and events using Elastic /SIEM Platform
○ Reviewing correlated alerts and logs for compromise scenarios
○ Performing triage of security alerts to prioritize response
○ Identifying false positives
○ Investigating security incidents and determining root cause
○ Collecting and preserving logs for analysis
○ Escalating confirmed incidents to leadership or SOC teams
○ Coordinating with IT or DevOps for containment and remediation
○ Creating after-action reports (AAR) post-incident
• In addition, the role may include assistance with monitoring Vulnerability Management tools, such as ACAS and ePO.

QUALIFICATIONS:

• Have at least three years of working knowledge and hands-on experience with Elastic/Splunk query languages, monitoring SIEM dashboards and real-time alerts, fine-tuning SIEM rules to reduce noise, and NIST 800-53 & DevSecOps frameworks

 

Job Tags

Full time,

Similar Jobs

University Of Central Oklahoma

Regular Student Tutor, Korean - Modern Languages Job at University Of Central Oklahoma

Special Information for Applicants This posting is to create a pool of applicants from which the Department may draw as tutoring positions become available. This posting may or may not result in the hiring of tutors. Language tutors are generally appointed by department...

Mayo Clinic

Patient Transporter Job at Mayo Clinic

 ...in more specialties than any other care provider according to U.S. News & World Report. As we work together to put the needs of the patient first, we are also dedicated to our employees, investing in competitive compensation and comprehensive benefit plans to take... 

Faithful Financial Co, LLC

Non Profit Donation Processor 1 Job at Faithful Financial Co, LLC

 ...Remote Fundraising Support Agent Nonprofit Call Center Were hiring dedicated professionals to join our remote call center team. Support nonprofit organizations by managing donor calls and helping drive their missions forward. Responsibilities:... 

Engie

Power Grid Model, Anlys, SrAdv_TRPG1K Job at Engie

 ...What You Can Expect As a Power Grid Modeling and Forecasting Advisor, you will report to Congestion Trading Director and will lead and develop long term grid scenarios for the Electric Reliability Council of Texas (ERCOT) footprint and forecast nodal price curves using... 

Famous Daves

Server / Waiter Job at Famous Daves

 ...people who know how to Wow a guest and, of course, want to be Famous. We're looking for Full Time & Part Time: ~ SERVERS / WAITERS Requirement: Must be 18 years of age, or older. Previous Customer Service / Restaurant Server experience preferred Must...