Cybersecurity Engineer – Elastic SIEM (Journeyman)

Maximus
•$120,000 - $140,000•Onsite

About The Position

Maximus is currently seeking a Cybersecurity Engineer – Elastic SIEM (Journeyman). This role is onsite, 5 days a week, in San Antonio, TX and requires an active Top Secret / SCI (TS/SCI) security clearance. Maximus TCS (Technology and Consulting Services) Internal Job Profile Code: TCS057, T3, Band 6.

Requirements

  • Active Top Secret / SCI (TS/SCI) security clearance.
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field (or equivalent experience).
  • 5+ years of hands-on cybersecurity engineering experience.
  • Intermediate proficiency level: ability to independently administer and troubleshoot standard Elastic SIEM operations and escalate complex issues.
  • Demonstrated hands-on experience with Elastic Stack (Elasticsearch, Kibana, Logstash, Beats/Elastic Agent) in an operational SIEM environment.
  • Experience supporting threat detection, alert triage, and/or cyber incident investigation.
  • Familiarity with DCO concepts, CSSP operations, and defensive cyber frameworks.
  • Experience working across multiple network security domains (NIPR, SIPR, or JWICS).
  • Meet applicable DoD 8140 requirements for the assigned work role. DCWF 521, Cyber Defense Infrastructure Support Specialist, Intermediate Proficiency; specific required certifications pending contract confirmation.

Nice To Haves

  • Experience with SIEM/SOAR integrations (e.g., Elastic, Palo Alto Cortex XSOAR, or similar).
  • Familiarity with Elastic's Fleet/Agent management and integration development.
  • Experience with AWS GovCloud environments (IL4/IL5/IL6).
  • Knowledge of MITRE ATT&CK framework and its application to detection engineering.
  • Experience with scripting/automation (Python, Bash, KQL/EQL) for SIEM rule development and data pipeline management.
  • Familiarity with container-based deployments (Kubernetes/EKS) in classified environments.
  • Prior experience supporting USAF or DoD DCO programs.
  • One or more of the following certifications preferred: Elastic Certified Engineer, CompTIA CySA+, GCIA, or GCIH.

Responsibilities

  • Independently perform standard SIEM engineering tasks with limited supervision; escalate complex issues to senior engineers.
  • Administer, operate, and sustain the Elastic SIEM platform (Elasticsearch, Kibana, Logstash, Beats/Elastic Agent) across NIPRNet, SIPRNet, and JWICS environments.
  • Monitor SIEM health, perform capacity planning, and resolve platform outages and degradations in accordance with defined SLAs.
  • Develop, tune, and maintain detection rules, alerts, dashboards, and visualizations in Elastic to support DCO mission requirements.
  • Ingest, normalize, and validate log data from diverse sources including endpoint, network, cloud, and application telemetry.
  • Collaborate with cyber operators and analysts to support threat detection, alert triage, and cyber incident investigation workflows.
  • Identify opportunities to improve SIEM coverage, data quality, and detection fidelity; implement improvements in coordination with the Government PMO.
  • Support Cyber Security Service Provider (CSSP) activities including continuous monitoring and security event analysis.
  • Create and maintain technical documentation including runbooks, standard operating procedures (SOPs), and knowledge base articles.
  • Participate in Agile/SAFe Program Increment (PI) planning and sprint execution in support of platform delivery.
  • Adhere to Air Force cybersecurity standards and all applicable DoD, IC, and USAF policy and directives across all enclaves.

Benefits

  • health insurance coverage
  • life and disability insurance
  • a retirement savings plan
  • paid holidays
  • paid time off
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service