This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
The Senior Elastic Engineer (EDR/Defend Focus) supports the Missile Defense Agency (MDA) on the Integrated Research and Development for Enterprise Solutions (IRES) contract.
Job Responsibility:
Be a key contributor to the design, implementation, and maintenance of our Elastic Stack environment, with a primary focus on leveraging Elastic EDR and Defend capabilities to enhance our cybersecurity posture
Be responsible for ensuring the security, scalability, and performance of our Elastic Stack infrastructure, and will work closely with other teams to integrate it with existing security tools and workflows
Architect, deploy, and maintain a highly available and scalable Elastic Stack environment, specializing in Elastic EDR/ Defend
Configure and optimize Elastic EDR/Defend policies and data pipelines for threat detection, prevention, and security event enrichment
Develop and maintain Kibana dashboards and visualizations for real-time security monitoring, threat identification, and incident response tracking
Perform proactive threat hunting and in-depth security analysis using Elastic EDR/Defend capabilities
Troubleshoot complex Elastic Stack issues, develop comprehensive documentation, and mentor junior engineers to ensure operational excellence
Requirements:
Must have 10, or more, years of general (full-time) work experience
Must have 5, or more, years of experience working with the Elastic Stack (Elasticsearch, Logstash, Kibana)
Must have 3, or more, years of experience specifically implementing and managing Elastic EDR and Defend solutions
Must have 2, or more, years of experience in a lead or senior role, mentoring and guiding other team members
Must have 1, or more, years of experience working in a management or leadership role
Must have a strong understanding of security principles, threat detection, and incident response
Must have experience with data ingestion, processing, and enrichment techniques
Must be proficient in at least one scripting language (e.g., Python, Bash, PowerShell)
Must have a current DoD 8570.01-M IAT Level II certification with Continuing Education (CE) - (CCNA-Security, CySA+, GICSP, GSEC, Security+ CE, CND, SSCP)
Must have an active DoD Secret Security Clearance
Must be able to obtain an active DoD Top Secret Security Clearance
Nice to have:
Have experience with Linux and Windows Server administration
Have experience with containerization technologies (Docker, Kubernetes)
Have experience with automation tools (Ansible, Puppet, Chef)
Have experience with cloud platforms (AWS, Azure, GCP)
Have experience with SIEM technologies and security event management
Have experience with security frameworks and compliance standards (e.g., NIST, FedRAMP)
Have a strong understanding of network protocols and security concepts
Have experience with threat intelligence platforms and data feeds
Have 1, or more, relevant security certifications (e.g., CISSP, CISM, CEH)
Have experience tuning and optimizing Elastic EDR and Defend for specific threat landscapes
What we offer:
medical
dental
vision
life
disability
and other insurance plans
ESPP (employee stock purchase program)
401K program with company match after 12 months
HSA (Health Savings Account on the HDHP plan)
SupportLinc Employee Assistance Program (EAP) with up to 8 free counseling sessions
corporate discount savings program
on-demand training program
access to certification prep and a library of technical and leadership courses/books/seminars after 6+ months