Cyber Security Incident and Event Management/Elastic Specialist Job at Diligent Consulting Inc, Washington DC

V0pZa2xvb0hJY2RlTFR4cExCd0M5SHh4dlE9PQ==
  • Diligent Consulting Inc
  • Washington DC

Job Description

US CITIZEN ONLY. SECRET CLEARANCE REQUIRED.  MUST HAVE IT-II CERT (IE SECURITY+)

SIEM/Elastic Specialist will:

• Be responsible for designing & setting up the ingestion of various customer data flows to include pre-processing data into a useable format, ensuring proper parsing and indexing
• Collaborate with cross-functional teams and responsible for designing & integrating Elastic with a wide variety of data sources and developing associated knowledge objects such as queries, dashboards, reports, alerts for monitoring and analytics
• Perform data transformation using Elastic query language 
• Track the health of the Elastic environment and optimize its performance. Troubleshoot and resolve issues related to security, performance, data indexing, and searches
• Perform watch-officer monitoring duties, including:
○ monitoring, detecting, investigating, and responding to cybersecurity threats and events using Elastic /SIEM Platform
○ Reviewing correlated alerts and logs for compromise scenarios
○ Performing triage of security alerts to prioritize response
○ Identifying false positives
○ Investigating security incidents and determining root cause
○ Collecting and preserving logs for analysis
○ Escalating confirmed incidents to leadership or SOC teams
○ Coordinating with IT or DevOps for containment and remediation
○ Creating after-action reports (AAR) post-incident
• In addition, the role may include assistance with monitoring Vulnerability Management tools, such as ACAS and ePO.

QUALIFICATIONS:

• Have at least three years of working knowledge and hands-on experience with Elastic/Splunk query languages, monitoring SIEM dashboards and real-time alerts, fine-tuning SIEM rules to reduce noise, and NIST 800-53 & DevSecOps frameworks

 

Job Tags

Full time,

Similar Jobs

Alliance for Justice

Outreach and Membership Associate Job at Alliance for Justice

 ...Job title Outreach and Membership Associate Reports to Director of Outreach and Membership FLSA Status Non-exempt Position Job Purpose The Outreach Associate supports the goals and priorities of the Outreach and Membership team, largely through assisting... 

Insight Global

Member Support Representative- Remote (PST) Job at Insight Global

 ...this mission. You will be at the front lines, working directly with members who call in to help...  ...able to effectively communicate via email/chat in a clear and concise way with...  ...analytical thinkingDedicated work from home space that supports secure handling of sensitive... 

Flying Biscuit Cafe

Food Quality Inspector Job at Flying Biscuit Cafe

 ...Maintains organization of tickets to guide BOH in flow of service Inspects meals for food quality and plate presentation of all menu items Communicates with FOH Manager regarding any delay in food delivery Ensures ticket time standards and communicates any... 

duvari group

Lead C# Software Engineer Job at duvari group

 ...solutions Multiple years of hands-on experience with Visual Studio Hands-on experience with relational databases, preferably Microsoft SQL Server Several years of web development experience using the Microsoft Stack or Angular Key Responsibilities... 

Gpac

Architectural Sign Installer Job at Gpac

Relocation Candidates Welcome to Apply! Relocation Assistance Provided! Installers needed in UTAH! We are an experienced and dedicated sign company based in Salt Lake City with over 30 years in the industry. We are known for our commitment to excellence and innovative...