Cyber Security Incident and Event Management/Elastic Specialist Job at Diligent Consulting Inc, Washington DC

ZkYvR2hxTXFRRmVucHhCM0RPVVZQRytrVkE9PQ==
  • Diligent Consulting Inc
  • Washington DC

Job Description

US CITIZEN ONLY. SECRET CLEARANCE REQUIRED.  MUST HAVE IT-II CERT (IE SECURITY+)

SIEM/Elastic Specialist will:

• Be responsible for designing & setting up the ingestion of various customer data flows to include pre-processing data into a useable format, ensuring proper parsing and indexing
• Collaborate with cross-functional teams and responsible for designing & integrating Elastic with a wide variety of data sources and developing associated knowledge objects such as queries, dashboards, reports, alerts for monitoring and analytics
• Perform data transformation using Elastic query language 
• Track the health of the Elastic environment and optimize its performance. Troubleshoot and resolve issues related to security, performance, data indexing, and searches
• Perform watch-officer monitoring duties, including:
○ monitoring, detecting, investigating, and responding to cybersecurity threats and events using Elastic /SIEM Platform
○ Reviewing correlated alerts and logs for compromise scenarios
○ Performing triage of security alerts to prioritize response
○ Identifying false positives
○ Investigating security incidents and determining root cause
○ Collecting and preserving logs for analysis
○ Escalating confirmed incidents to leadership or SOC teams
○ Coordinating with IT or DevOps for containment and remediation
○ Creating after-action reports (AAR) post-incident
• In addition, the role may include assistance with monitoring Vulnerability Management tools, such as ACAS and ePO.

QUALIFICATIONS:

• Have at least three years of working knowledge and hands-on experience with Elastic/Splunk query languages, monitoring SIEM dashboards and real-time alerts, fine-tuning SIEM rules to reduce noise, and NIST 800-53 & DevSecOps frameworks

 

Job Tags

Full time,

Similar Jobs

Physician Assistant Solutions

Physician Assistant - Interventional Radiology Job at Physician Assistant Solutions

 ...INTERVENTIONAL RADIOLOGY PHYSICIAN ASSISTANT Syracuse, New York Currently seeking a Interventional Radiology Physician Assistant/Nurse Practitioner for a full time opportunity in Syracuse area. Interested candidates should hold RT certification. Experience in... 

Falcon Construction

Social Media & Content Manager Job at Falcon Construction

 ...Presence Make periodic edits and updates to the company website Keep content fresh and relevant to current work Advertising & SEO Adjust Google AdWords settings to improve searchability Apply basic SEO best practices Autonomy & Innovation Work... 

Always Best Care Senior Services - Atlanta/Buckhead

Experienced Caregiver 16HRs a Week must be OK with Pets in Lithonia Job at Always Best Care Senior Services - Atlanta/Buckhead

 ...quality care for seniors in the Lithonia area. This is a part-time position (16 hours per week), ideal for someone who is dependable, patient, and passionate...  ...transportation preferredBenefits:* Competitive pay: $14.00 - $16.00 per hour, paid weekly* Flexible part-... 

Outlaw Trucking Group

CDL A Driver Lease A Pete Train Drivers 1.50 all miles Job at Outlaw Trucking Group

 ...New program for drivers who want to train drivers while leasing their truck We lease a Pete 579 Cummins engine Zero down No credit check...  ...get paid 1.50 for all the miles you drive plus what your trainee drives That's right all miles go to you Plus you get... 

Performance Sealing & Striping

Small Engine Mechanic Job at Performance Sealing & Striping

 ..., higher depending on level of mechanic experience. Local candidates only. The Small Engine Mechanic will be able to inspect and troubleshoot equipment and perform necessary repairs after diagnosis. Primary job focus includes inspection, diagnosis, and repair of small...