SIEM Application Developer (ElasticStack) - Clearance Required
Indexed description
Job Description:
Cydecor is seeking a SIEM Engineer (ElasticStack) to provide Security Information and Event Management (SIEM) engineering and operational support in a dynamic enterprise environment. This role is responsible for designing, implementing, and maintaining ElasticStack-based SIEM capabilities to deliver correlated and consolidated views of security events across multiple networks.
The SIEM Engineer will enable security analysts to develop a comprehensive understanding of the security posture from a centralized platform by integrating data feeds from diverse technology domains. Using ElasticSearch, the selected candidate will support network forensics investigations, conduct post-incident analysis, and develop trend analysis to inform defensive planning and infrastructure protection strategies.
The ElasticStack platform operates on Linux-based servers and systems within both military command and control (C2) and enterprise LAN/WAN communication environments.
Responsibilities include:
- Provide Security Information Event Management (SIEM) engineering and operational support using ElasticStack and other SIEM tools.
- Provide security analysts with correlated and consolidated views of security events from across the network, enabling SIEM users to develop a comprehensive understanding of the security environment from a single point.
- Using ElasticSearch, provide a network forensics capability to support post-mortems on previous attacks and provide trend analysis capability to assist the security analysts in the development of plans to protect the infrastructure from future attacks.
- Design, implement, and monitor data feeds from various technology areas on multiple networks. The ElasticStack product is used on Linux-based servers and systems.
- One of the following Residential Certifications, GDSA, ElasticStack Certified, Splunk Certified Admin, Splunk Enterprise Architect, Microsoft Certified Cybersecurity Architect Expert, or ArcSight ESM Advanced Administrator Certified Expert.
- Minimum of 6+ years of overall IT experience
- 1 year experience with ElasticSearch
- 2 years direct experience with U.S. military C2 or commercial LAN/WAN communication systems (experience may be concurrent)
- 1 year experience with the UNIX operating system
- ElasticSearch Administrator/Engineer certification
- Active Secret Clearance
- Bachelor of Science/Arts Degree in Engineering, Computer Science, Business Administration or Mathematics and a minimum of 2 years IT experience
- Associate degree with 4 years IT experience
- 6+ years IT experience with no degree
- Onsite: Monday - Friday, 8 hours each day
What We Believe
We have an unwavering commitment to diversity with the aim that every one of our people has a full sense of belonging within our organization. As a business imperative, every person at Cydecor has the responsibility to create and sustain an inclusive environment.
Equal Employment Opportunity Statement
Cydecor is an Equal Employment Opportunity/Affirmative Action Employer (EEO/AA). All employment and hiring decisions are based on qualifications, merit, and business needs without regard to race, religion, color, sexual orientation, nationality, gender, ethnic origin, disability, age, sex, gender identity & expression, veteran status, marital status, or any other characteristic protected by applicable law.
If you are a qualified individual with a disability and/or a disabled veteran, you may request a reasonable accommodation if you are unable or limited in your ability to access job openings or apply for a job on this site because of your disability. You can request assistance by contacting [email protected] or calling 703-884-2105.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search