Elastic SIEM Engineer

ASRC Federal
$120,000 - $165,450Hybrid

About The Position

ASRC Federal is actively hiring an Elastic SIEM Engineer in support of our Defense Counterintelligence Security Agency (DCSA) program based out of Hanover MD. Remote flexibility available! Telework offered with a requirement to be onsite up to one (1) day a week at Hanover, MD. We invest in the lives of our employees, both in and out of the workplace, by providing competitive pay and benefit packages. This position is offering a pay range of $150,000.00 - $165,450.00 depending on experience, seniority, geographic locations, and factors permitted by law. Benefits offered may include health care, dental, vision, life insurance; 401k; education assistance; paid time off including Paid Time Off, holidays and any other paid leave required by law.

Requirements

  • At least five (5) Years – Direct Elastic engineering/administration experience
  • Active Secret Clearance REQUIRED, eligible to be upgraded to TS/SCI
  • Bachelor’s degree in information security or related field and/or equivalent combination of experience
  • Must meet DoD 8140/8570 IAM or IAT Level II certifications’ requirements at the time of hire by having one of the following certifications: (CCNA Security, CySA +, GICSP, GSEC, Security+, SSSP, CAP, CASP CE, CISM, CISSP (or Associate) or GSLC)
  • Experience in the support and maintenance of an Elastic infrastructure in a highly available configuration in an AWS Cloud environment
  • Proven experience as an Elastic Engineer or similar role
  • Strong understanding of Elastic architecture in a cloud environment, including data ingestion, indexing, search, and visualization
  • Prior experience customizing and configuring Elastic environments according to client needs, including developing scripts and apps as necessary
  • Proficiency in scripting languages such as Python or Bash for Elastic app and dashboard development
  • Experience with data transformation and normalization to ensure compatibility with Elastic
  • Troubleshoot Elastic indexers, search heads and forwarder problems
  • Familiarity with networking principles and protocols
  • Excellent problem-solving skills and the ability to work under pressure
  • Strong communication and interpersonal skills, with the ability to explain technical concepts to non-technical stakeholders
  • Experience analyzing log files from network traffic logs, firewall logs, IDS logs, DNS logs and ESS to ID possible security threats e.g., determine rogue systems, infected systems, unauthorized system changes and unauthorized hardware connections

Nice To Haves

  • Two (2) plus years of AWS experience

Responsibilities

  • Maintain enterprise-scale Elastic Stack security solutions that safeguard our national security systems.
  • Design and implement advanced detection rules, correlation searches, and analytics pipelines using Elasticsearch, Logstash, Kibana, and Elastic Security to identify sophisticated threats and adversary activity.
  • Optimize data ingestion pipelines from diverse sources including cloud platforms (AWS, Azure, GCP), network devices, endpoints, and security tools, ensuring high availability, performance, and scalability of the SIEM infrastructure.
  • Develop custom dashboards, visualizations, and threat hunting workbenches that empower SOC analysts to detect and respond to incidents effectively.
  • Collaborate with security operations, engineering teams, and government stakeholders to enhance detection capabilities.
  • Tune detection logic to reduce false positives.
  • Automate security workflows.
  • Integrate threat intelligence feeds.
  • Ensure all activities align with critical compliance standards like NIST 800-53 and RMF through comprehensive documentation and technical leadership.

Benefits

  • health care
  • dental
  • vision
  • life insurance
  • 401k
  • education assistance
  • paid time off
  • Paid Time Off
  • holidays
  • any other paid leave required by law
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service