Elastic SIEM Platform Engineer

TekSynap•Fort Belvoir, VA
•$170,000 - $210,000•Onsite

About The Position

The Elastic Cyber Defense Platform Engineer will support the migration from Splunk to an enterprise Elastic Security platform and the continued operation and improvement of that environment. The engineer will help design, deploy, secure, integrate, and sustain Elastic capabilities across three network enclaves while preserving continuous cyber defense operations. This hands-on engineering role requires close coordination with customer stakeholders, cybersecurity analysts, infrastructure teams, and program leadership.

Requirements

  • Five or more years of experience in cybersecurity, systems engineering, network engineering, or a closely related technical field.
  • Two or more years of hands-on experience engineering or operating Elastic Stack environments, or equivalent experience demonstrating the ability to perform the responsibilities of this role.
  • Practical experience with Elasticsearch cluster architecture, Kibana, Fleet, Elastic Agents, ingest pipelines, data lifecycle management, monitoring, and troubleshooting.
  • Experience securing enterprise platforms with TLS, certificates, identity integration, role-based access, and logical data separation.
  • Linux administration experience, preferably Red Hat Enterprise Linux, and working knowledge of platform tuning such as vm.max_map_count, ulimits, memory, storage, and swap settings.
  • Experience supporting DoD, federal, classified, or otherwise highly regulated environments and applying RMF, STIG, and NIST security controls.
  • Experience supporting DoD CSSP or comparable SOC operations across multiple network enclaves.
  • Ability to communicate technical issues clearly, work directly with customers, document solutions, and operate effectively during time-sensitive migration and cutover activities.
  • Active Secret clearance and ability to maintain required access. Candidates supporting JWICS activities must be eligible for the applicable TS/SCI access.
  • Ability to travel regularly to Fort Belvoir, Virginia, including on short notice when required for customer access, classified work, testing, or operational milestones.
  • Active United States Citizenship is required.

Nice To Haves

  • Elastic Certified Engineer is strongly preferred at the time of hire.
  • Candidates who have completed official Elasticsearch Engineer training and possess substantial hands-on Elastic engineering experience may be considered in lieu of the certification, provided they can obtain Elastic Certified Engineer within 90 days of hire or assignment.
  • Elastic Certified Analyst and Elastic Certified Observability Engineer are preferred and may be obtained after assignment based on program needs.
  • DoD 8140 or 8570-aligned baseline certification, such as Security+ or an approved higher-level certification, is preferred or must be obtained as required by the assigned position category.
  • Residence within commuting distance of Fort Belvoir or the National Capital Region.
  • Active TS/SCI clearance and prior work on SIPRNet or JWICS.
  • Experience with Elastic self-managed, bare metal, Elastic Cloud Enterprise, Elastic Cloud on Kubernetes, Docker, Kubernetes, or hybrid on-premises and cloud deployments.
  • Experience migrating SIEM content or security operations from Splunk to Elastic, including SPL analysis, field normalization, ECS mapping, dashboards, detections, and SOAR workflows.
  • Experience with high-volume security data, searchable snapshots, object storage, backup and recovery, and multi-site resilience.
  • Defensive cyber operations, incident response, network security analytics, threat hunting, memory or network forensics, and detection engineering experience.
  • Python, PowerShell, shell scripting, API integration, or infrastructure automation experience.
  • Experience delivering technical instruction, operational briefings, and knowledge transfer to government teams.

Responsibilities

  • Design, deploy, configure, upgrade, and sustain self-managed Elastic Stack environments, including Elasticsearch, Kibana, Fleet, Elastic Agents, Beats, Logstash, and related integrations.
  • Support the phased migration of priority data sources, searches, dashboards, detections, alerts, and analyst workflows from Splunk to Elastic Security.
  • Build and troubleshoot ingest pipelines, parsers, index templates, data streams, mappings, and Index Lifecycle Management policies for high-volume security telemetry.
  • Monitor and tune cluster health, capacity, performance, availability, shard allocation, retention, snapshots, and recovery processes.
  • Implement secure access and data protection controls, including TLS or mTLS, certificate management, CAC or enterprise identity integration, role-based access control, Kibana spaces, and data segregation.
  • Develop and refine dashboards, detection rules, alerting, and threat-hunting content aligned to mission use cases and MITRE ATT&CK.
  • Integrate Elastic with endpoint, network, vulnerability, identity, ticketing, and security automation technologies used by the Agency CSSP.
  • Support deployment and troubleshooting in disconnected, air-gapped, and classified environments, including offline repositories and controlled software transfer processes.
  • Participate in customer workshops, testing, dual-run validation, cutover, and post-migration optimization at Fort Belvoir and other approved locations.
  • Produce architecture, configuration, test, operating, troubleshooting, and knowledge-transfer documentation; train government and contractor personnel as required.

Benefits

  • health
  • dental
  • vision
  • 401K
  • life insurance
  • short-term and long-term disability plans
  • vacation time
  • holidays
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service