Description & Requirements
Maximus is currently seeking a Cybersecurity Engineer - Elastic SIEM (Journeyman).
This role is onsite, 5 days a week, in San Antonio, TX and requires an active Top Secret / SCI (TS/SCI) security clearance.
Maximus TCS (Technology and Consulting Services) Internal Job Profile Code: TCS057, T3, Band 6
Job-Specific Essential Duties and Responsibilities:
- Independently perform standard SIEM engineering tasks with limited supervision; escalate complex issues to senior engineers.
- Administer, operate, and sustain the Elastic SIEM platform (Elasticsearch, Kibana, Logstash, Beats/Elastic Agent) across NIPRNet, SIPRNet, and JWICS environments.
- Monitor SIEM health, perform capacity planning, and resolve platform outages and degradations in accordance with defined SLAs.
- Develop, tune, and maintain detection rules, alerts, dashboards, and visualizations in Elastic to support DCO mission requirements.
- Ingest, normalize, and validate log data from diverse sources including endpoint, network, cloud, and application telemetry..
- Collaborate with cyber operators and analysts to support threat detection, alert triage, and cyber incident investigation workflows.
- Identify opportunities to improve SIEM coverage, data quality, and detection fidelity; implement improvements in coordination with the Government PMO.
- Support Cyber Security Service Provider (CSSP) activities including continuous monitoring and security event analysis.
- Create and maintain technical documentation including runbooks, standard operating procedures (SOPs), and knowledge base articles.
- Participate in Agile/SAFe Program Increment (PI) planning and sprint execution in support of platform delivery.
- Adhere to Air Force cybersecurity standards and all applicable DoD, IC, and USAF policy and directives across all enclaves.
Job-Specific Minimum Requirements:
- Active Top Secret / SCI (TS/SCI) security clearance.
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field (or equivalent experience).
- 5+ years of hands-on cybersecurity engineering experience.
- Intermediate proficiency level: ability to independently administer and troubleshoot standard Elastic SIEM operations and escalate complex issues.
- Demonstrated hands-on experience with Elastic Stack (Elasticsearch, Kibana, Logstash, Beats/Elastic Agent) in an operational SIEM environment.
- Experience supporting threat detection, alert triage, and/or cyber incident investigation.
- Familiarity with DCO concepts, CSSP operations, and defensive cyber frameworks.
- Experience working across multiple network security domains (NIPR, SIPR, or JWICS).
- Meet applicable DoD 8140 requirements for the assigned work role. DCWF 521, Cyber Defense Infrastructure Support Specialist, Intermediate Proficiency; specific required certifications pending contract confirmation.
Preferred Skills and Qualifications:
- Experience with SIEM/SOAR integrations (e.g., Elastic, Palo Alto Cortex XSOAR, or similar).
- Familiarity with Elastic's Fleet/Agent management and integration development.
- Experience with AWS GovCloud environments (IL4/IL5/IL6).
- Knowledge of MITRE ATT&CK framework and its application to detection engineering.
- Experience with scripting/automation (Python, Bash, KQL/EQL) for SIEM rule development and data pipeline management.
- Familiarity with container-based deployments (Kubernetes/EKS) in classified environments.
- Prior experience supporting USAF or DoD DCO programs.
- One or more of the following certifications preferred: Elastic Certified Engineer, CompTIA CySA+, GCIA, or GCIH.
#techjobs #clearance #veteransPage
Minimum Requirements
TCS057, T3, Band 6
Minimum Salary
$
120,000.00
Maximum Salary
$
140,000.00