Cyber Security Incident and Event Management/Elastic Specialist Job at Diligent Consulting Inc, Washington DC

L2RmMnZybytWVWgvTkltTWFadS8zbi9jb1E9PQ==
  • Diligent Consulting Inc
  • Washington DC

Job Description

US CITIZEN ONLY. SECRET CLEARANCE REQUIRED.  MUST HAVE IT-II CERT (IE SECURITY+)

SIEM/Elastic Specialist will:

• Be responsible for designing & setting up the ingestion of various customer data flows to include pre-processing data into a useable format, ensuring proper parsing and indexing
• Collaborate with cross-functional teams and responsible for designing & integrating Elastic with a wide variety of data sources and developing associated knowledge objects such as queries, dashboards, reports, alerts for monitoring and analytics
• Perform data transformation using Elastic query language 
• Track the health of the Elastic environment and optimize its performance. Troubleshoot and resolve issues related to security, performance, data indexing, and searches
• Perform watch-officer monitoring duties, including:
○ monitoring, detecting, investigating, and responding to cybersecurity threats and events using Elastic /SIEM Platform
○ Reviewing correlated alerts and logs for compromise scenarios
○ Performing triage of security alerts to prioritize response
○ Identifying false positives
○ Investigating security incidents and determining root cause
○ Collecting and preserving logs for analysis
○ Escalating confirmed incidents to leadership or SOC teams
○ Coordinating with IT or DevOps for containment and remediation
○ Creating after-action reports (AAR) post-incident
• In addition, the role may include assistance with monitoring Vulnerability Management tools, such as ACAS and ePO.

QUALIFICATIONS:

• Have at least three years of working knowledge and hands-on experience with Elastic/Splunk query languages, monitoring SIEM dashboards and real-time alerts, fine-tuning SIEM rules to reduce noise, and NIST 800-53 & DevSecOps frameworks

 

Job Tags

Full time,

Similar Jobs

Trokr Delivery Services LLC

Delivery Driver Role - Trokr Delivery Services LLC (an Amazon DSP) Job at Trokr Delivery Services LLC

 ...Trokr Delivery Services LLC is a locally owned and operated Amazon DSP dedicated to providing exceptional delivery service to our community. Location Address: WMS4 at 279 Jamie Whitton Drive, Saltillo, MS 38866 Drive with us Apply Today! Job Description... 

Partners In Care

Grant Writer and Administrator Job at Partners In Care

 ...Grant Writer and Administrator About Partners in Care: Partners In Care Maryland, Inc. (PIC) is a 501c3 non-profit organization whose...  ...requirements of each funding opportunity. Funder relationships: Assist in cultivating and stewarding relationships with grant funders... 

Liberty Personnel Services, Inc.

Construction Business Development Associate Job at Liberty Personnel Services, Inc.

 ...Job Details: Business Development - Account Manager - Environmental Construction - Civil Construction Salary -Depends on experience My client a well respected HVAC equipment supplier that does business throughout New Jersey is seeking to add a Account Manager... 

Washington Adventist University

Adjunct Faculty - Chemistry (Multiple positions) Job at Washington Adventist University

 ...Job Title: Adjunct Faculty, Chemistry Department: Biology and Chemistry Reports to: Chair Salary : $3120/4 credit course...  ...an accredited college or university. Academic coursework in organic chemistry, biochemistry, or inorganic chemistry is preferred.... 

NTT DATA, Inc.

Desktop Support Technician Job at NTT DATA, Inc.

 ...If you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now. We are currently seeking a Desktop Support Technician to join our team in Mississauga, Ontario (CA-ON), Canada (CA). The Desktop Support Technician will be responsible...