Cyber Security Incident and Event Management/Elastic Specialist Job at Diligent Consulting, Washington DC

ZVlxajZscklPZDJiOWF6ZnhWMXhOdm9O
  • Diligent Consulting
  • Washington DC

Job Description


US CITIZEN ONLY. SECRET CLEARANCE REQUIRED. MUST HAVE IT-II CERT (IE SECURITY+)

SIEM/Elastic Specialist will:

• Be responsible for designing & setting up the ingestion of various customer data flows to include pre-processing data into a useable format, ensuring proper parsing and indexing
• Collaborate with cross-functional teams and responsible for designing & integrating Elastic with a wide variety of data sources and developing associated knowledge objects such as queries, dashboards, reports, alerts for monitoring and analytics
• Perform data transformation using Elastic query language 
• Track the health of the Elastic environment and optimize its performance. Troubleshoot and resolve issues related to security, performance, data indexing, and searches
• Perform watch-officer monitoring duties, including:
○ monitoring, detecting, investigating, and responding to cybersecurity threats and events using Elastic /SIEM Platform
○ Reviewing correlated alerts and logs for compromise scenarios
○ Performing triage of security alerts to prioritize response
○ Identifying false positives
○ Investigating security incidents and determining root cause
○ Collecting and preserving logs for analysis
○ Escalating confirmed incidents to leadership or SOC teams
○ Coordinating with IT or DevOps for containment and remediation
○ Creating after-action reports (AAR) post-incident
• In addition, the role may include assistance with monitoring Vulnerability Management tools, such as ACAS and ePO.

QUALIFICATIONS:

• Have at least three years of working knowledge and hands-on experience with Elastic/Splunk query languages, monitoring SIEM dashboards and real-time alerts, fine-tuning SIEM rules to reduce noise, and NIST 800-53 & DevSecOps frameworks

Job Tags

Full time,

Similar Jobs

MCI

Entry Level Remote Customer Service Representative (Saskatchewan) Job at MCI

 ...Entry-Level Remote Customer Service Representative (Saskatchewan) We are looking for full...  ...to support inbound customer service, help desk, and back-office processing representatives...  ..., and ensure best in class customer experience. In addition to being the best in the... 

Soil Testing, Inc

Drill Rig Operator - Test Borings Job at Soil Testing, Inc

 ...Experienced Drill Rig Operator for Test Borings. Job Details: The ideal candidate MUST be experienced in all phases of test borings with at least 5 years of drill rig operation . Including experience in: hollow stem auger, rock coring, mud rotary drilling... 

NewRez LLC

Home Loan Advisor Job at NewRez LLC

 ...direct seller/servicer. NewRez originates loans through various channels and transaction...  ...Sales and Customer Service. The Embedded agent has the opportunity to work a large selection...  ...are met in include LE documentation is signed at time of application or has been mailed... 

HCRC Staffing

Chiropractor Waynesboro GA Job at HCRC Staffing

Chiropractor Waynesboro GA (45 min S of Augusta) Urgently Hiring No Weekends Built-In Professional Growth We are looking for a self-starting, motivated Chiropractor to join our practice full time in Waynesboro, GA. Come join our team in our state-of-the-art facility located... 

Nesfield Performance

Massage Therapist Job at Nesfield Performance

 ...Job Description Licensed Massage Therapist (Full-Time) Location: Bethesda, MD Salary: $55,000+ base per year + bonus (minimum...  ...integrative services across physical training, movement therapy, nutrition, and recovery. We are looking for a passionate, highly...