Cyber Data Analysis Engineer (Elasticsearch)

CACISpringfield, VA
$82,100 - $172,400Onsite

About The Position

An Elasticsearch Engineer designs, builds, and maintains the enterprise environment for collecting, storing, and displaying data that supports cybersecurity efforts. In this role, you'll work with on-premise and cloud systems, as well as various software products, to collect log data from multiple government agencies in compliance with policies, ensuring it is stored for easy retrieval. You should be motivated, detail-oriented, teachable, willing to share knowledge, manage time well, and understand the importance of documentation. Strong listening, speaking, note-taking skills, and the ability to work with a team are essential.

Requirements

  • Active Top Secret/SCI Clearance with experience working on US Government contracts with a Polygraph, or the ability to pass a Polygraph
  • Bachelor's Degree in Computer Science, Information Technology, or a related field with 6 years of relevant experience; or relevant experience in lieu of a degree
  • DOD 8570 IAT Level II Certification
  • Ability to obtain a CSSP Infrastructure Support Certification within 90 days of hire
  • 3 or more years of Unix/Linux Server Administration or similar experience
  • 2 or more years of Windows Server Administration or similar experience
  • 2 or more years of SIEM administration (Elasticsearch, Splunk, Sentinel, ArcSight, et c.)
  • Good oral and written communications
  • Good listening and comprehension

Nice To Haves

  • 1+ years of experience, in one or more of the following areas: LAN/WAN networking, Kafka, Kubernetes, Cribl, Ansible, AWS (EC2, S3, NLB/ALB), Regular Expressions (RegEx)
  • Experience with one or more scripting languages: YAML, Python, JavaScript, Bash, and/or Ruby
  • Experience using version control tools such as Git

Responsibilities

  • Help customers send their log data through one or more enterprise networks to a specific destination
  • Design, build, and maintain log data collection pipelines consisting of products like Cribl, ArcSight, Kafka, various AWS products, Linux servers, and Microsoft servers
  • Design, build, and maintain log data management environments using products such as Elasticsearch or Sentinel
  • Research and identify the physical or cloud resources needed to optimize support for specific Linux systems or hosted products
  • Troubleshoot any data flow issues from the SIEM data collection point to the SIEM or designated long-term storage destination
  • Troubleshoot any data display or data storage issues within the SIEM environment
  • Perform root cause analysis for complex issues
  • Design and develop key indicators of system health to enable maximum uptime and proactively monitor overall health across the platform.
  • Maintain appropriate application, system, and product versions according to applicable agency enterprise policies
  • Develop or improve processes using tools like scripts, Ansible, or AWS products
  • Document tasks, processes, changes, and product statuses
  • Provide team training regarding tasks and products
  • Interact with internal and external customers during all project phases
  • Be aware of customer needs
  • Respond to customer inquiries in a timely manner
  • Demonstrate attention to detail
  • Some on-call, including nights/weekends (very rare)

Benefits

  • flexible time off benefit
  • robust learning resources
  • healthcare
  • wellness
  • financial
  • retirement
  • family support
  • continuing education
  • time off benefits
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service