USIEM Elastic Engineer
Listed on 2026-06-13
-
IT/Tech
Systems Engineer, Data Engineering, Cybersecurity, Cloud Computing
Overview
Job Title: USIEM Elastic Engineer (Everforth ECS)
Location preferences:
Schofield Barracks (USAG), HI;
Augusta, GA; or Sierra Vista, AZ. Depending on location, approximately 25% in-office/onsite work may be required to meet customer requirements and operational needs.
As a leading provider of managed cybersecurity services, ECS delivers a highly tailored offering to each customer. Our team protects both customer and corporate environments. The role is technical and hands-on, with opportunities to engage and lead across multiple groups to address technical hurdles, protect data, and consult on security topics. This position supports ECS's AESS program and requires working within a multi-disciplined team to design, build, secure, maintain, optimize, and document multiple Elastic Stack Enterprise solutions deployed globally in a Federal DoD environment, including support using Ansible playbooks.
You will perform continuous data normalization and contribute to written deliverables such as SOPs and process workflows. Your infrastructure, data pipelines, and reporting automation will support internal engineering personnel and external customer requirements.
Salary Range: $110,000 - $150,000
Responsibilities- Design, build, secure, maintain, optimize, and document Elastic Stack Enterprise solutions (Elasticsearch, Logstash, Kibana, Beats, ML, SIEM) deployed globally in a Federal DoD environment.
- Support ECS's AESS program and work within a multi-disciplined team; contribute to continuous improvement and tool usage optimization.
- Work with Ansible playbooks for deployment and operational support.
- Perform continuous data normalization and deliver written technical deliverables such as SOPs and process workflows.
- Develop infrastructure, data pipelines, and reporting automation to meet internal and external requirements.
Required Skills
- Minimum Secret Clearance is required
- Compliance with DoD 8140 / 8570 IAT Level II certification prior to start date
- At least 4 years of hands-on experience in deployment, configuration, and solution development using the Elastic Stack for security and logging use-cases (Elastic SIEM experience is a plus)
- Demonstrated experience with the full Elastic Stack – Elasticsearch, Logstash, Kibana, Beats, Machine Learning, and REST API integration
- Demonstrated ability to utilize Ansible Playbook
- Experience integrating Elasticsearch with external systems (e.g., SOAR tools, Threat Intel Platforms)
- Experience with data management: hot/warm/cold architectures, shard allocation/re-allocation, snapshots & restoration
- Strong experience evaluating Elastic clusters, configuration, indexing, search and query performance tuning, security, and cluster administration
- Experience integrating Elasticsearch with authentication mechanisms such as SAML, LDAP, and PKI
- Experience with on-prem and SaaS Elastic Stack environments, including monitoring and tuning
- Experience securing and hardening Elastic Stack hosting environments
- Experience with development in multiple languages (Python, Bash, Power Shell, Painless, etc.)
- Experience designing and implementing highly scalable Elastic Stack solutions
- Experience mapping data to Elastic Common Schema and data normalization
- Experience developing Logstash and/or Ingest Pipelines
- Experience creating custom visualizations and dashboards in Kibana
- Experience developing custom reporting solutions using APIs that leverage Elasticsearch and Elasti Cache
- Experience in end-to-end low-level design, development, administration, and delivery of Elasticsearch-based reporting solutions
- Strong technical foundation for building reliable, scalable, and supportable systems
- Experience with Red Hat Enterprise Linux deployment and administration
Everforth ECS is an equal opportunity employer and does not discriminate or allow discrimination on the basis of any characteristic protected by law. All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, or local jurisdiction law.
Everforth ECS is the federal segment of Everforth, a $4B global organization with over 10,000 employees. Our nearly 3,500 professionals deliver advanced technology solutions in data and AI, cybersecurity, and enterprise transformation, serving defense, intelligence, and federal civilian agencies. We value attracting and developing top talent and high-performing teams, and fostering a culture that is engaging, accountable, and mission-driven.
How to ApplyMeet the challenge. Make a difference with Everforth ECS.
#J-18808-Ljbffr(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).