Cybersecurity Engineer – Elastic SIEM SME

Maximus
•$190,000 - $220,000•Onsite

About The Position

Maximus is seeking a Cybersecurity Engineer – Elastic SIEM SME. This role is on-site in San Antonio, TX and requires an active TS/SCI security clearance. This position is classified under Maximus TCS Internal Job Profile Code: TCS059, T5, Band 8.

Requirements

  • Active Top Secret / SCI (TS/SCI) security clearance.
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field.
  • 10+ years of hands-on cybersecurity engineering experience.
  • Advanced proficiency level: demonstrated expertise in Elastic SIEM architecture, technical standards, complex troubleshooting, and advising technical teams and customers.
  • Demonstrated hands-on experience with Elastic Stack (Elasticsearch, Kibana, Logstash, Beats/Elastic Agent) in an operational SIEM environment.
  • Experience supporting threat detection, alert triage, and/or cyber incident investigation.
  • Familiarity with DCO concepts, CSSP operations, and defensive cyber frameworks.
  • Experience working across multiple network security domains (NIPR, SIPR, or JWICS).
  • Meet applicable DoD 8140 requirements for the assigned work role. DCWF 521, Cyber Defense Infrastructure Support Specialist, Advanced Proficiency.

Nice To Haves

  • Experience with SIEM/SOAR integrations (e.g., Elastic, Palo Alto Cortex XSOAR, or similar).
  • Familiarity with Elastic's Fleet/Agent management and integration development.
  • Experience with AWS GovCloud environments (IL4/IL5/IL6).
  • Knowledge of MITRE ATT&CK framework and its application to detection engineering.
  • Experience with scripting/automation (Python, Bash, KQL/EQL) for SIEM rule development and data pipeline management.
  • Familiarity with container-based deployments (Kubernetes/EKS) in classified environments.
  • Prior experience supporting USAF or DoD DCO programs.
  • One or more of the following certifications preferred: Elastic Certified Engineer, CompTIA CySA+, GCIA, or GCIH.

Responsibilities

  • Serve as the Elastic SIEM subject matter expert, exercising independent technical judgment and advising the team and customer.
  • Provide expert technical direction for the architecture, operation, and sustainment of the Elastic SIEM platform (Elasticsearch, Kibana, Logstash, Beats/Elastic Agent) across NIPRNet, SIPRNet, and JWICS environments.
  • Monitor SIEM health, perform capacity planning, and lead resolution of the most complex platform outages and degradations in accordance with defined SLAs.
  • Guide the design and review of detection rules, alerts, dashboards, and visualizations in Elastic to support DCO mission requirements.
  • Ingest, normalize, and validate log data from diverse sources including endpoint, network, cloud, and application telemetry.
  • Collaborate with cyber operators and analysts to support threat detection, alert triage, and cyber incident investigation workflows.
  • Identify opportunities to improve SIEM coverage, data quality, and detection fidelity; lead implementation of improvements in coordination with the Government PMO.
  • Support Cyber Security Service Provider (CSSP) activities including continuous monitoring and security event analysis.
  • Create and maintain technical documentation including runbooks, standard operating procedures (SOPs), and knowledge base articles.
  • Advise the customer and mentor senior and journeyman engineers; establish technical standards and review complex SIEM designs.
  • Participate in Agile/SAFe Program Increment (PI) planning and sprint execution in support of platform delivery.
  • Adhere to Air Force cybersecurity standards and all applicable DoD, IC, and USAF policy and directives across all enclaves.

Benefits

  • health insurance coverage
  • life and disability insurance
  • a retirement savings plan
  • paid holidays
  • paid time off
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service