Responsibilities & QualificationsPosition Overview
The Elastic Cyber Defense Platform Engineer will support the migration from Splunk to an enterprise Elastic Security platform and the continued operation and improvement of that environment. The engineer will help design, deploy, secure, integrate, and sustain Elastic capabilities across three network enclaves while preserving continuous cyber defense operations. This hands-on engineering role requires close coordination with customer stakeholders, cybersecurity analysts, infrastructure teams, and program leadership.
Key Responsibilities
- Design, deploy, configure, upgrade, and sustain self-managed Elastic Stack environments, including Elasticsearch, Kibana, Fleet, Elastic Agents, Beats, Logstash, and related integrations.
- Support the phased migration of priority data sources, searches, dashboards, detections, alerts, and analyst workflows from Splunk to Elastic Security.
- Build and troubleshoot ingest pipelines, parsers, index templates, data streams, mappings, and Index Lifecycle Management policies for high-volume security telemetry.
- Monitor and tune cluster health, capacity, performance, availability, shard allocation, retention, snapshots, and recovery processes.
- Implement secure access and data protection controls, including TLS or mTLS, certificate management, CAC or enterprise identity integration, role-based access control, Kibana spaces, and data segregation.
- Develop and refine dashboards, detection rules, alerting, and threat-hunting content aligned to mission use cases and MITRE ATT&CK.
- Integrate Elastic with endpoint, network, vulnerability, identity, ticketing, and security automation technologies used by the Agency CSSP.
- Support deployment and troubleshooting in disconnected, air-gapped, and classified environments, including offline repositories and controlled software transfer processes.
- Participate in customer workshops, testing, dual-run validation, cutover, and post-migration optimization at Fort Belvoir and other approved locations.
- Produce architecture, configuration, test, operating, troubleshooting, and knowledge-transfer documentation; train government and contractor personnel as required.
Required Qualifications
- Five or more years of experience in cybersecurity, systems engineering, network engineering, or a closely related technical field.
- Two or more years of hands-on experience engineering or operating Elastic Stack environments, or equivalent experience demonstrating the ability to perform the responsibilities of this role.
- Practical experience with Elasticsearch cluster architecture, Kibana, Fleet, Elastic Agents, ingest pipelines, data lifecycle management, monitoring, and troubleshooting.
- Experience securing enterprise platforms with TLS, certificates, identity integration, role-based access, and logical data separation.
- Linux administration experience, preferably Red Hat Enterprise Linux, and working knowledge of platform tuning such as vm.max_map_count, ulimits, memory, storage, and swap settings.
- Experience supporting DoD, federal, classified, or otherwise highly regulated environments and applying RMF, STIG, and NIST security controls.
- Experience supporting DoD CSSP or comparable SOC operations across multiple network enclaves.
- Ability to communicate technical issues clearly, work directly with customers, document solutions, and operate effectively during time-sensitive migration and cutover activities.
- Active Secret clearance and ability to maintain required access. Candidates supporting JWICS activities must be eligible for the applicable TS/SCI access.
- Ability to travel regularly to Fort Belvoir, Virginia, including on short notice when required for customer access, classified work, testing, or operational milestones.
Certification and Training Qualifications
- Elastic Certified Engineer is strongly preferred at the time of hire.
- Candidates who have completed official Elasticsearch Engineer training and possess substantial hands-on Elastic engineering experience may be considered in lieu of the certification, provided they can obtain Elastic Certified Engineer within 90 days of hire or assignment.
- Elastic Certified Analyst and Elastic Certified Observability Engineer are preferred and may be obtained after assignment based on program needs.
- DoD 8140 or 8570-aligned baseline certification, such as Security+ or an approved higher-level certification, is preferred or must be obtained as required by the assigned position category.
Preferred Qualifications
- Residence within commuting distance of Fort Belvoir or the National Capital Region.
- Active TS/SCI clearance and prior work on SIPRNet or JWICS.
- Experience with Elastic self-managed, bare metal, Elastic Cloud Enterprise, Elastic Cloud on Kubernetes, Docker, Kubernetes, or hybrid on-premises and cloud deployments.
- Experience migrating SIEM content or security operations from Splunk to Elastic, including SPL analysis, field normalization, ECS mapping, dashboards, detections, and SOAR workflows.
- Experience with high-volume security data, searchable snapshots, object storage, backup and recovery, and multi-site resilience.
- Defensive cyber operations, incident response, network security analytics, threat hunting, memory or network forensics, and detection engineering experience.
- Python, PowerShell, shell scripting, API integration, or infrastructure automation experience.
- Experience delivering technical instruction, operational briefings, and knowledge transfer to government teams.
Expected Outcomes
- Operational, secure, and supportable Elastic Security capabilities across authorized Agency environments.
- Reliable ingestion and normalized security telemetry with validated dashboards, detections, alerts, and analyst workflows.
- Documented configuration, testing, troubleshooting, operating procedures, and knowledge transfer supporting migration, cutover, and sustainment.
Overview
We are seeking an Elastic SIEM Platform Engineer to join our Prime Contract with the Defense Threat Reduction Agency.
Additional Job Information
WORK ENVIRONMENT AND PHYSICAL DEMANDS
The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of the job. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions.
- Location: Fort Belvoir, VA
- Type of environment: Professional office Environment
- Noise level: Medium
- Work schedule: Schedule is Monday 6 Friday (0800 - 1600)
- Amount of Travel: 1-2 weeks/annually (rare deployment occasions and training attendance)
PHYSICAL DEMANDS
The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
While performing the duties of this job, the employee is regularly required to use hands to handle, feel, touch; reach with hands and arms; talk and hear. The employee is regularly required to stand; walk; sit; climb or balance; and stoop, kneel, crouch, or crawl. The employee is regularly required to lift up to 10 pounds. The employee is frequently required to lift up to 25 pounds; and up to 50 pounds. The vision requirements include close vision, distance vision, peripheral vision, depth perception, and ability to adjust focus.
WORK AUTHORIZATION/SECURITY CLEARANCE
- Active United States Citizenship is required.
- Must possess a minimum of a DOD Secret Clearance.
WAGE INFORMATION
Target salary range: $170,000.00 - $210,000.00. The salary range displayed is an estimate only and is not a guarantee of compensation or salary, and will be determined on several factors regarding the individuals particular combination of education, knowledge, skills, competencies and experience, as well as contract parameters and organizational requirements. The displayed salary is one component of the total compensation package for employees.
OTHER DUTIES
Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities and activities may change at any time with or without notice.
TekSynap is a drug-free workplace. We reserve the right to conduct drug testing in accordance with federal, state, and local laws. All employees and candidates may be subject to drug screening if deemed necessary to ensure a safe and compliant working environment.
Many positions require specific certifications and/or the ability to obtain a security clearance. Security clearances may only be granted to U.S. citizens. Applicants who accept an offer of employment may be subject to investigations performed by TekSynap and/or the Government to verify the candidate meets the required qualifications and other eligibility requirements.