Cyber Security Incident and Event Management/Elastic Specialist Job at Diligent Consulting, Washington DC

Rzk3TnlRK0tFejFkbStaQ25KZVFZcWhJ
  • Diligent Consulting
  • Washington DC

Job Description


US CITIZEN ONLY. SECRET CLEARANCE REQUIRED. MUST HAVE IT-II CERT (IE SECURITY+)

SIEM/Elastic Specialist will:

• Be responsible for designing & setting up the ingestion of various customer data flows to include pre-processing data into a useable format, ensuring proper parsing and indexing
• Collaborate with cross-functional teams and responsible for designing & integrating Elastic with a wide variety of data sources and developing associated knowledge objects such as queries, dashboards, reports, alerts for monitoring and analytics
• Perform data transformation using Elastic query language 
• Track the health of the Elastic environment and optimize its performance. Troubleshoot and resolve issues related to security, performance, data indexing, and searches
• Perform watch-officer monitoring duties, including:
○ monitoring, detecting, investigating, and responding to cybersecurity threats and events using Elastic /SIEM Platform
○ Reviewing correlated alerts and logs for compromise scenarios
○ Performing triage of security alerts to prioritize response
○ Identifying false positives
○ Investigating security incidents and determining root cause
○ Collecting and preserving logs for analysis
○ Escalating confirmed incidents to leadership or SOC teams
○ Coordinating with IT or DevOps for containment and remediation
○ Creating after-action reports (AAR) post-incident
• In addition, the role may include assistance with monitoring Vulnerability Management tools, such as ACAS and ePO.

QUALIFICATIONS:

• Have at least three years of working knowledge and hands-on experience with Elastic/Splunk query languages, monitoring SIEM dashboards and real-time alerts, fine-tuning SIEM rules to reduce noise, and NIST 800-53 & DevSecOps frameworks

Job Tags

Full time,

Similar Jobs

Coast Medical Service

Travel Interim Director of Surgical Services Job at Coast Medical Service

 ...Job Description Coast Medical Service is seeking a travel nurse RN Manager, OR - Operating Room for a travel nursing job in Durango, Colorado. Job Description & Requirements ~ Specialty: OR - Operating Room ~ Discipline: RN ~ Start Date: ASAP ~ Duration... 

Insight Global

Graphic Designer Job at Insight Global

 ...Position: Graphic Designer Location: Hybrid- Monday/ Tuesday/Thursday onsite in Pittsburgh Working Hours: 9-5 PR: $25-30/hr Duration: 3-6 months Must Haves: ~ Bachelors degree or equivalent experience in Graphic Design, Communication Design, or a... 

Sephora

Operations Associate - Full Time Job at Sephora

 ...States (US) Hourly/Salaried: Hourly (Non-Exempt) Full Time/Part Time: Full Time Position Type: Regular Your Role at Sephora: As an Operations Associate , youll be the backbone of the storeensuring smooth, efficient operations that support an exceptional... 

ECU Health

Death Investigator I (DI) - ECU Forensic Pathology Job at ECU Health

Death Investigator I (DI) - ECU Forensic PathologyECU Health is a mission-driven, 1,708-bed academic health care system serving more than 1.4 million people in 29 eastern North Carolina counties. The not-for-profit system is comprised of 13,000 team members, nine hospitals... 

*US AMR-Jones Lang LaSalle Americas, Inc.

Hands-On Chief Engineer Job at *US AMR-Jones Lang LaSalle Americas, Inc.

 ...experience to a new industry, join our team as we help shape a brighter way forward. What this job involves: The Hands-On Chief Engineer is responsible for the operational management and direct maintenance of all building systems while providing effective...