Cyber Security Incident and Event Management/Elastic Specialist Job at Diligent Consulting Inc, Washington DC

M29rOEVHU01lT255ZS9HTGo1bkRDOSt5SEE9PQ==
  • Diligent Consulting Inc
  • Washington DC

Job Description

US CITIZEN ONLY. SECRET CLEARANCE REQUIRED.  MUST HAVE IT-II CERT (IE SECURITY+)

SIEM/Elastic Specialist will:

• Be responsible for designing & setting up the ingestion of various customer data flows to include pre-processing data into a useable format, ensuring proper parsing and indexing
• Collaborate with cross-functional teams and responsible for designing & integrating Elastic with a wide variety of data sources and developing associated knowledge objects such as queries, dashboards, reports, alerts for monitoring and analytics
• Perform data transformation using Elastic query language 
• Track the health of the Elastic environment and optimize its performance. Troubleshoot and resolve issues related to security, performance, data indexing, and searches
• Perform watch-officer monitoring duties, including:
○ monitoring, detecting, investigating, and responding to cybersecurity threats and events using Elastic /SIEM Platform
○ Reviewing correlated alerts and logs for compromise scenarios
○ Performing triage of security alerts to prioritize response
○ Identifying false positives
○ Investigating security incidents and determining root cause
○ Collecting and preserving logs for analysis
○ Escalating confirmed incidents to leadership or SOC teams
○ Coordinating with IT or DevOps for containment and remediation
○ Creating after-action reports (AAR) post-incident
• In addition, the role may include assistance with monitoring Vulnerability Management tools, such as ACAS and ePO.

QUALIFICATIONS:

• Have at least three years of working knowledge and hands-on experience with Elastic/Splunk query languages, monitoring SIEM dashboards and real-time alerts, fine-tuning SIEM rules to reduce noise, and NIST 800-53 & DevSecOps frameworks

 

Job Tags

Full time,

Similar Jobs

Serco

Air Traffic Control Specialist - King Salmon, AK (AKN) Job at Serco

 ...Position Description & Qualifications Position Description & Qualifications Are you an Air Traffic Controller looking for a challenging and exciting career? Serco has a great opportunity for you located in King Salmon, AK! Serco is one of the largest non... 

Our Billing Co LLC

Payer Credentialing Specialist Job at Our Billing Co LLC

 ...Our Billing Co. is seeking a full time Payer Credentialing Specialist to join our team! The Payer Credentialing Specialist is an important...  ..., Outlook, Access, Project). This job will be fully remote. Our Billing Co. offers a competitive benefits package... 

KeyBank

Key Private Bank Senior Relationship Manager Job at KeyBank

 ...Location: 726 Exchange Street, Buffalo New York Job Summary Key Private Bank (KPB) is dedicated to serving our clients' financial needs through expert advice and personalized banking, borrowing, and investment solutions. The Sr. KPB Relationship Manager (RM) is... 

Writer

CISO (Chief Information Security Officer) Job at Writer

 ...join us on our journey to create a better future of work. &##128208; About this role As the Chief Information Security Officer (CISO), you'll be at the forefront of developing and implementing a robust information security strategy to safeguard our data, systems,... 

804 Technology

Teamcenter Administrator Job at 804 Technology

 ...customer service skills. JOB RESPONSIBILITIES: Own Teamcenter Administration for the Bell enterprise, consulting with business leaders and...  ...with development, collaboration, and testing tools (e.g., JIRA, Git, SVN, etc.) Exposure to Logistics Systems and/or...