Job Closed
This listing is no longer active.
Serving our Country, Clients, & Community -- Providing IT & Cyber Professionals the Freedom to Thrive
Elastic Security Engineer, SIEM
Location
Arizona
Posted
6 days ago
Salary
0
Seniority
Senior
Job Description
Elastic Security Engineer, SIEM
SERVISS - HUBZone Certified
• Design, build, secure, maintain, optimize, and document multiple Elastic Stack enterprise solutions (Elasticsearch, Logstash, Kibana, Beats, Machine Learning, and SIEM) deployed globally in a Federal DoD environment • Automate deployment and configuration using Ansible playbooks • Perform continuous data-normalization functions across diverse data sources • Build data pipelines and reporting automation that directly support internal engineering personnel and external customer requirements • Author written technical deliverables such as SOPs and process workflows to optimize tool usage and contribute to new capabilities
Job Requirements
- Active Top Secret security clearance
- US citizenship
- Compliance with DoD 8140 / 8570 IAT Level II certification prior to start date
- At least 4 years of hands-on experience in deployment, configuration, and solution development using the Elastic Stack for security and logging use cases (Elastic SIEM experience a plus)
- Demonstrated experience with the full Elastic Stack: Elasticsearch, Logstash, Kibana, Beats, Machine Learning, and REST API integration
- Demonstrated ability to use Ansible playbooks
Benefits
- 100% of medical, vision, dental, and life insurance premiums paid for by SERVISS
- Opportunities for annual performance bonuses and growth incentives
- 401(k) retirement plan with 6% dollar for dollar match
- Equity Participation Program
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Maintain, administer, and continuously improve AP&T's cybersecurity program. • Develop, update, and maintain cybersecurity policies, procedures, standards, and supporting documentation. • Track cybersecurity initiatives, remediation efforts, and program objectives. • Support alignment with recognized frameworks and best practices, including NIST Cybersecurity Framework (CSF), CIS Controls, and CISA Cybersecurity Performance Goals. • Prepare reports, metrics, and risk summaries for leadership. • Monitor security alerts, events, and system activity across the organization's technology environment. • Investigate and respond to cybersecurity incidents and suspicious activity. • Maintain secure configurations and cybersecurity tools. • Coordinate with internal teams and external vendors to address identified security concerns. • Support endpoint, network, email, and cloud security initiatives. • Conduct and coordinate vulnerability scanning activities. • Analyze findings and prioritize remediation based on business risk. • Track corrective actions through completion. • Monitor patch management and system hardening efforts. • Participate in external security assessments, penetration testing, and remediation planning. • Administer and oversee access control processes. • Support privileged access management and least-privilege security practices. • Manage multifactor authentication (MFA) and identity security controls. • Conduct user access reviews and ensure appropriate account management practices. • Maintain incident response plans, procedures, and supporting documentation. • Coordinate cybersecurity event response activities. • Facilitate incident response exercises and tabletop simulations. • Support disaster recovery, business continuity, and backup validation activities. • Assist in post-incident reviews and corrective action planning. • Identify, assess, document, and track cybersecurity risks. • Support audits, compliance reviews, and cybersecurity assessments. • Review third-party and vendor cybersecurity practices. • Assist with cyber insurance submissions, questionnaires, and related requirements. • Maintain evidence and documentation supporting compliance activities. • Support cybersecurity practices across information technology, telecommunications, and operational technology environments. • Assist in securing distributed systems supporting utility and broadband operations. • Coordinate security efforts involving critical infrastructure and field operations technologies. • Support cybersecurity requirements for remote and rural operational environments. • Lead employee cybersecurity awareness and education efforts. • Coordinate phishing awareness campaigns and training activities. • Promote cybersecurity best practices throughout the organization. • Foster a culture of shared responsibility for information security.
Security Software Engineer
Evista Ltd.We are Evista: flexible, agile experts, focusing on web applications, custom softwares, UI/UX design and websites.
• Build, deploy, and maintain high-traffic, cloud-hosted applications • Write scalable, testable, and secure code • Collaborate with engineering and security teams • Contribute to site reliability and performance at scale
• Lead and execute a comprehensive information security and IT strategy, including Governance, Risk & Compliance, Security Operations, and Enterprise IT. • Own the design, implementation, and continuous improvement of the company's information security program. • Partner cross-functionally with every aspect of the business to ensure that security is embedded into every layer of the organization. • Oversee IT operations including helpdesk, system administration, and physical network administration, ensuring reliability and security across the environment. • Set the strategy and roadmap for enterprise applications and infrastructure, including identity and access management; evaluate and govern the use of AI-powered productivity and business tools. • Maintain vulnerability management processes including prioritization, remediation tracking, and SLA enforcement; leverage AI tooling to improve detection coverage and triage efficiency. • Lead incident response, coordinating cross-functional teams, managing communications, and driving post-incident reviews. • Own security and IT vendor relationships, contracts, and budgets, including forecasting and investment recommendations. • Deliver regular updates to executive leadership on program status, key risks, and strategic priorities. • Lead, mentor, and develop a team spanning security and IT, managing priorities, workload, and career growth across both operational and strategic work.
• Own strategy and hands-on engineering for Detection and Response platforms; identify, onboard, and normalize all log sources including cloud, containers, endpoints, and SaaS • Build and maintain Security Orchestration, Automation, and Response (SOAR) tooling to reduce response time and analyst toil • Lead incident response for complex threats including developing runbooks, driving post- incident improvements, and designing/running BCP/DR tabletop exercises. • Embed security into the SDLC: threat modeling, secure design reviews, SAST/DAST tooling, and automated security gates in CI/CD pipelines • Own the vulnerability management program at host and application levels; track and drive remediation • Champion "security as code" practices across engineering teams • Build AI-powered security tooling: threat detection and anomaly identification at appropriate confidence thresholds, automated triage and remediation workflows, and AI-assisted post- mortem summarization • Define and implement the security model for LLM-based systems and internal AI tooling • Architect harness patterns to constrain LLM behavior and harden against prompt injection, indirect injection via RAG pipelines, and data exfiltration via model outputs • Evaluate and govern AI tool adoption from a security and data-risk perspective • Own AWS security posture and enforce baselines across Linux/Windows, network devices, and enterprise SaaS (M365, Google Workspace, Azure) • Engineer, configure, and operate EDR, DLP, and endpoint security programs • Provide IAM architecture expertise across identity and access systems • Mentor and actively develop junior and mid-level security engineers through design reviews, pairing, and direct feedback. Growing team capability is a core expectation of this role • Define and drive security engineering standards across the organization • Collaborate closely with IT operations, platform, and software to translate threat intelligence into detection and hardening priorities



