Elastic Cloud Security Engineer
Listed on 2026-09-14
-
IT/Tech
Cybersecurity
Join a culture of empowerment and connectivity.
Develop your craftLearn the skills you need to accelerate your career.
Discover benefits that your life and work.
Innovate with intentionBuild mission-ready tech that protects the nation.
Designs, implements, integrates, and maintains systems and tools to automate complex cyber activities. Applies leading-edge principles, theories, and concepts. Contributes to the development of new principles and concepts. Works on unusually complex problems and provides highly innovative solutions. Operates with substantial latitude for unreviewed action or decision. Mentors or supervises employees in both company and technical competencies.
Join us. The world can't wait.
You Have:- 5+ years of experience administering Elastic Stack, including Elasticsearch, Kibana, Logstash, Beats, or Fleet
- Experience managing Elasticsearch index lifecycle policies, index templates, and data streams at scale, and building Kibana dashboards, visualizations, and lens-based analytics for security operations
- Experience with Elastic Security detection rules, alerts, and case management workflows
- Experience with log ingestion pipeline design, including parsing, enrichment, and normalization across heterogeneous log sources such as network, endpoint, identity, and cloud
- Experience with Elastic Common Schema (ECS) and mapping non-standard log sources into ECS-compliant fields
- Experience working in government cybersecurity environments such as SOC, SIEM operations, or defensive cyber
- Experience optimizing log collections from AWS platform, endpoints, and network devices
- Knowledge of AI/ML concepts as applied to security analytics such as anomaly detection, behavioral baselining, or threat scoring
- Experience working in an agile working environment
- Experience working with DoD clients
- Experience with Elastic's ML jobs, including for User and Entity Behavior Analytics (UEBA), rare process detection, or anomalous login patterns
- Experience with Elastic AI Assistant or integration of LLMs into Elastic Security workflows such as natural language querying and alert triage assistance
- Experience building or fine-tuning ML models outside Elastic, including Python, scikit-learn, and PyTorch, for security use cases such as threat detection or lateral movement scoring
- Experience with Elastic Agent fleet management at scale, including custom integrations and policy management
- Experience with cross-domain data flows and working in multi-classification environments such as IL4, IL5, or IL6
- Experience with ES|QL or EQL for advanced threat hunting and detection-as-code workflows
- Kubernetes Certification such as Kubernetes and Cloud Native Certification or Kubernetes Application Developer Certification
Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information;
Secret clearance is required.
At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen’s benefit programs.
Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).