Cyber Security Incident and Event Management/Elastic Specialist Job at Diligent Consulting Inc, Washington DC

Yk1tWHc5TVVmZG1jQlRlNU13MUpEbkY1TGc9PQ==
  • Diligent Consulting Inc
  • Washington DC

Job Description

US CITIZEN ONLY. SECRET CLEARANCE REQUIRED.  MUST HAVE IT-II CERT (IE SECURITY+)

SIEM/Elastic Specialist will:

• Be responsible for designing & setting up the ingestion of various customer data flows to include pre-processing data into a useable format, ensuring proper parsing and indexing
• Collaborate with cross-functional teams and responsible for designing & integrating Elastic with a wide variety of data sources and developing associated knowledge objects such as queries, dashboards, reports, alerts for monitoring and analytics
• Perform data transformation using Elastic query language 
• Track the health of the Elastic environment and optimize its performance. Troubleshoot and resolve issues related to security, performance, data indexing, and searches
• Perform watch-officer monitoring duties, including:
○ monitoring, detecting, investigating, and responding to cybersecurity threats and events using Elastic /SIEM Platform
○ Reviewing correlated alerts and logs for compromise scenarios
○ Performing triage of security alerts to prioritize response
○ Identifying false positives
○ Investigating security incidents and determining root cause
○ Collecting and preserving logs for analysis
○ Escalating confirmed incidents to leadership or SOC teams
○ Coordinating with IT or DevOps for containment and remediation
○ Creating after-action reports (AAR) post-incident
• In addition, the role may include assistance with monitoring Vulnerability Management tools, such as ACAS and ePO.

QUALIFICATIONS:

• Have at least three years of working knowledge and hands-on experience with Elastic/Splunk query languages, monitoring SIEM dashboards and real-time alerts, fine-tuning SIEM rules to reduce noise, and NIST 800-53 & DevSecOps frameworks

 

Job Tags

Full time,

Similar Jobs

Forvis Mazars, LLP

Firm Support Specialist Job at Forvis Mazars, LLP

The Firm Support Specialist I role is responsible for providing assistance to employees and partners of Forvis Mazars by assisting in various administrative and operational tasks. This is a highly visible position that serves as the first point of contact for clients,... 

SelfMade

Creative Strategist Job at SelfMade

 ...job and more exclusive features.Direct message the job poster from SelfMadeCreative StrategistRemote or Hybrid | Part-Time to StartAbout SelfMadeSelfMade is a performance creative agency specializing in Meta advertising for DTC brands. Our portfolio work includes... 

Providence

Radiation Therapist Job at Providence

 ...Job Description Description Radiation Therapist at Providence St Vincent Medical Center in Portland, Oregon Per Diem/Day Shift To perform simulations and deliver therapeutic ionizing radiation to the patient as prescribed by the Radiation Oncologist. Assists... 

Keplr Vision

Patient Care Team Lead - Advanced Eyecare Job at Keplr Vision

 ...Patient Care Team Lead - Advanced Eyecare General Job Description & Responsibilities This is a customer-facing position that...  ...position reports to the Practice Manager, or their designee. Status: Full-time (FT) Exemption: Non-exempt Department: Business Office

Robert Half

C# Full Stack Engineer Job at Robert Half

 ...collaborative environment. Responsibilities: Build and maintain server-side functionality to support business operations. Develop user-facing features and interfaces using modern web technologies. Write clean, maintainable, and testable code following industry...