Summary
SERVISS is a provider of cutting-edge cybersecurity and IT solutions, and they are seeking an Elastic Security Engineer to support a Federal DoD SIEM program. This hands-on role involves designing, building, and maintaining Elastic Stack solutions while ensuring data security and compliance in a multi-disciplined team environment.
Responsibilities
- Design, build, secure, maintain, optimize, and document multiple Elastic Stack enterprise solutions (Elasticsearch, Logstash, Kibana, Beats, Machine Learning, and SIEM) deployed globally in a Federal DoD environment
- Automate deployment and configuration using Ansible playbooks
- Perform continuous data-normalization functions across diverse data sources
- Build data pipelines and reporting automation that directly support internal engineering personnel and external customer requirements
- Author written technical deliverables such as SOPs and process workflows to optimize tool usage and contribute to new capabilities
- Support a Federal DoD SIEM program as part of a multi-disciplined engineering team
- Maintain, optimize, and secure enterprise Elastic Stack solutions deployed globally
- Contribute to new capabilities and the continuous improvement of tool usage
- Engage and collaborate across engineering teams and customer stakeholders
Skills
- Active Top Secret security clearance
- US citizenship
- Compliance with DoD 8140 / 8570 IAT Level II certification prior to start date
- At least 4 years of hands-on experience in deployment, configuration, and solution development using the Elastic Stack for security and logging use cases (Elastic SIEM experience a plus)
- Demonstrated experience with the full Elastic Stack: Elasticsearch, Logstash, Kibana, Beats, Machine Learning, and REST API integration
- Demonstrated ability to use Ansible playbooks
- Experience integrating Elasticsearch with external systems (e.g., SOAR tools, threat intelligence platforms)
- Experience with data management: hot/warm/cold architectures, shard allocation and re-allocation, snapshots and restoration
- Strong experience evaluating existing Elastic clusters, configuration parameters, indexing, search and query performance tuning, security, and cluster administration
- Experience integrating Elasticsearch with authentication mechanisms such as SAML, LDAP, and PKI
- Experience supporting the Elastic Stack in on-prem and SaaS environments, including system monitoring and tuning
- Experience securing the Elastic Stack and hardening hosting environments
- Development experience in multiple languages (Python, Bash, PowerShell, Painless, etc.)
- Experience designing and implementing highly scalable Elastic Stack solutions
- Experience developing data structures and data mappings from various sources to achieve data normalization using Elastic Common Schema (ECS)
- Experience developing Logstash and/or ingest pipelines
- Experience developing custom Kibana visualizations and dashboards
- Experience developing custom reporting solutions using APIs that leverage Elasticsearch and ElastiCache
- Experience with end-to-end low-level design, development, administration, and delivery of Elasticsearch-based reporting solutions
- Strong technical foundation in building reliable, scalable, and supportable systems
- Experience with Red Hat Enterprise Linux deployment and administration
Qualifications
Must Haves
- Active Top Secret security clearance
- US citizenship
- Compliance with DoD 8140 / 8570 IAT Level II certification prior to start date
- At least 4 years of hands-on experience in deployment, configuration, and solution development using the Elastic Stack for security and logging use cases (Elastic SIEM experience a plus)
- Demonstrated experience with the full Elastic Stack: Elasticsearch, Logstash, Kibana, Beats, Machine Learning, and REST API integration
- Demonstrated ability to use Ansible playbooks
Nice to Haves
- Experience integrating Elasticsearch with external systems (e.g., SOAR tools, threat intelligence platforms)
- Experience with data management: hot/warm/cold architectures, shard allocation and re-allocation, snapshots and restoration
- Strong experience evaluating existing Elastic clusters, configuration parameters, indexing, search and query performance tuning, security, and cluster administration
- Experience integrating Elasticsearch with authentication mechanisms such as SAML, LDAP, and PKI
- Experience supporting the Elastic Stack in on-prem and SaaS environments, including system monitoring and tuning
- Experience securing the Elastic Stack and hardening hosting environments
- Development experience in multiple languages (Python, Bash, PowerShell, Painless, etc.)
- Experience designing and implementing highly scalable Elastic Stack solutions
- Experience developing data structures and data mappings from various sources to achieve data normalization using Elastic Common Schema (ECS)
- Experience developing Logstash and/or ingest pipelines
- Experience developing custom Kibana visualizations and dashboards
- Experience developing custom reporting solutions using APIs that leverage Elasticsearch and ElastiCache
- Experience with end-to-end low-level design, development, administration, and delivery of Elasticsearch-based reporting solutions
- Strong technical foundation in building reliable, scalable, and supportable systems
- Experience with Red Hat Enterprise Linux deployment and administration
Benefits
- Highly competitive compensation and best in class benefits
- 100% of medical, vision, dental, and life insurance premiums paid for by SERVISS
- Be part of an exciting company with ground floor opportunities in the Equity Participation Program
- Opportunities for annual performance bonuses and growth incentives
- 401(k) retirement plan with 6% dollar for dollar match