About the job
As a SIEM/Elastic Specialist, your responsibilities will include:
• Designing and implementing the ingestion of diverse customer data flows, ensuring pre-processing into a usable format with proper parsing and indexing.
• Collaborating with cross-functional teams to design and integrate Elastic with various data sources, developing vital knowledge objects including queries, dashboards, reports, and alerts for effective monitoring and analytics.
• Transforming data utilizing Elastic query language.
• Monitoring the health of the Elastic environment, optimizing performance, and troubleshooting issues related to security, performance, data indexing, and searches.
• Serving as a watch officer, which includes:
○ Monitoring, detecting, investigating, and responding to cybersecurity threats and events using Elastic/SIEM Platform.
○ Reviewing correlated alerts and logs to identify compromise scenarios.
○ Performing triage on security alerts to prioritize responses.
○ Identifying false positives.
○ Investigating security incidents to determine root causes.
○ Collecting and preserving logs for analysis.
○ Escalating confirmed incidents to leadership or SOC teams.
○ Coordinating with IT or DevOps teams for containment and remediation.
○ Creating after-action reports (AAR) post-incident.
• Assisting with monitoring Vulnerability Management tools such as ACAS and ePO as needed.

