Cyber Security Incident and Event Management/Elastic Specialist
Job in
Washington, District of Columbia, 20022, USA
Listed on 2026-08-06
Listing for:
Diligent Consulting Inc
Full Time
position Listed on 2026-08-06
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below
Cyber Security Incident and Event Management/Elastic Specialist
US CITIZEN ONLY. SECRET CLEARANCE REQUIRED. MUST HAVE IT-II CERT (IE SECURITY+)
SIEM/Elastic Specialist will:
- Be responsible for designing & setting up the ingestion of various customer data flows to include pre-processing data into a usable format, ensuring proper parsing and indexing
- Collaborate with cross-functional teams and responsible for designing & integrating Elastic with a wide variety of data sources and developing associated knowledge objects such as queries, dashboards, reports, alerts for monitoring and analytics
- Perform data transformation using Elastic query language
- Track the health of the Elastic environment and optimize its performance. Troubleshoot and resolve issues related to security, performance, data indexing, and searches
- Perform watch-officer monitoring duties, including:
- Monitoring, detecting, investigating, and responding to cybersecurity threats and events using Elastic /SIEM Platform
- Reviewing correlated alerts and logs for compromise scenarios
- Performing triage of security alerts to prioritize response
- Identifying false positives
- Investigating security incidents and determining root cause
- Collecting and preserving logs for analysis
- Escalating confirmed incidents to leadership or SOC teams
- Coordinating with IT or Dev Ops for containment and remediation
- Creating after‑action reports (AAR) post‑incident
- In addition, the role may include assistance with monitoring Vulnerability Management tools, such as ACAS and ePO.
- Have at least three years of working knowledge and hands‑on experience with Elastic/Splunk query languages, monitoring SIEM dashboards and real‑time alerts, fine‑tuning SIEM rules to reduce noise, and NIST 800‑53 & Dev Sec Ops frameworks
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×