Junior Cybersecurity Engineer – Elastic SIEM

Maximus
•$90,000 - $110,000•Onsite

About The Position

Maximus is seeking a Junior Cybersecurity Engineer specializing in Elastic SIEM. This role involves performing routine tasks under guidance, assisting with the administration and operation of the Elastic SIEM platform across various secure environments (NIPRNet, SIPRNet, JWICS), monitoring SIEM health, and troubleshooting platform issues. The engineer will also help develop and maintain detection rules, alerts, dashboards, and visualizations, ingest and validate log data, and collaborate with cyber operators and analysts to support threat detection and incident investigation. The position requires identifying opportunities for SIEM improvement, supporting Cyber Security Service Provider (CSSP) activities, updating technical documentation, and participating in Agile/SAFe planning. Adherence to Air Force cybersecurity standards and DoD, IC, and USAF policies is mandatory.

Requirements

  • Active Top Secret / SCI (TS/SCI) security clearance.
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field (or equivalent experience).
  • 3+ years of hands-on cybersecurity engineering experience.
  • Basic proficiency level: ability to perform routine Elastic SIEM tasks using established procedures, with supervision and review.
  • Demonstrated hands-on experience with Elastic Stack (Elasticsearch, Kibana, Logstash, Beats/Elastic Agent) in an operational SIEM environment.
  • Experience supporting threat detection, alert triage, and/or cyber incident investigation.
  • Familiarity with DCO concepts, CSSP operations, and defensive cyber frameworks.
  • Experience working across multiple network security domains (NIPR, SIPR, or JWICS).
  • Meet applicable DoD 8140 requirements for the assigned work role. DCWF 521, Cyber Defense Infrastructure Support Specialist, Basic Proficiency; specific required certifications pending contract confirmation.

Nice To Haves

  • Experience with SIEM/SOAR integrations (e.g., Elastic, Palo Alto Cortex XSOAR, or similar).
  • Familiarity with Elastic's Fleet/Agent management and integration development.
  • Experience with AWS GovCloud environments (IL4/IL5/IL6).
  • Knowledge of MITRE ATT&CK framework and its application to detection engineering.
  • Experience with scripting/automation (Python, Bash, KQL/EQL) for SIEM rule development and data pipeline management.
  • Familiarity with container-based deployments (Kubernetes/EKS) in classified environments.
  • Prior experience supporting USAF or DoD DCO programs.
  • One or more of the following certifications preferred: Elastic Certified Engineer, CompTIA CySA+, GCIA, or GCIH.

Responsibilities

  • Perform routine tasks under the guidance and review of experienced engineers, following established procedures.
  • Assist with administering, operating, and sustaining the Elastic SIEM platform (Elasticsearch, Kibana, Logstash, Beats/Elastic Agent) across NIPRNet, SIPRNet, and JWICS environments.
  • Monitor SIEM health, support capacity planning, and troubleshoot routine platform issues using runbooks; escalate outages and complex degradations in accordance with defined SLAs.
  • Assist with developing, tuning, and maintaining detection rules, alerts, dashboards, and visualizations in Elastic to support DCO mission requirements.
  • Assist with ingesting, normalizing, and validating log data from diverse sources including endpoint, network, cloud, and application telemetry.
  • Collaborate with cyber operators and analysts to support threat detection, alert triage, and cyber incident investigation workflows.
  • Identify opportunities to improve SIEM coverage, data quality, and detection fidelity; support implementation of approved improvements in coordination with the Government PMO.
  • Support Cyber Security Service Provider (CSSP) activities including continuous monitoring and security event analysis.
  • Update technical documentation under review including runbooks, standard operating procedures (SOPs), and knowledge base articles.
  • Participate in Agile/SAFe Program Increment (PI) planning and sprint execution in support of platform delivery.
  • Adhere to Air Force cybersecurity standards and all applicable DoD, IC, and USAF policy and directives across all enclaves.

Benefits

  • health insurance coverage
  • life and disability insurance
  • a retirement savings plan
  • paid holidays
  • paid time off
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service