Quick Overview
Seniority
Mid Senior
Work mode
Hybrid
Location
Lexington, MA, United States
Posted
19 hours ago
AWSLogstashScikit-learnAgileKibanaKubernetesPyTorchPython
Job Description
The Opportunity Designs, implements, integrates, and maintains systems and tools to automate complex cyber activities. Applies leading-edge principles, theories, and concepts. Contributes to the development of new principles and concepts. Works on unusually complex problems and provides highly innovative solutions. Operates with substantial latitude for unreviewed action or decision. Mentors or supervises employees in both company and technical competencies. Qualifications
- 5+ years of experience administering Elastic Stack, including Elasticsearch, Kibana, Logstash, Beats, or Fleet
- Experience managing Elasticsearch index lifecycle policies, index templates, and data streams at scale, and building Kibana dashboards, visualizations, and lens-based analytics for security operations
- Experience with Elastic Security detection rules, alerts, and case management workflows
- Experience with log ingestion pipeline design, including parsing, enrichment, and normalization across heterogeneous log sources such as network, endpoint, identity, and cloud
- Experience with Elastic Common Schema (ECS) and mapping non-standard log sources into ECS-compliant fields
- Experience working in government cybersecurity environments such as SOC, SIEM operations, or defensive cyber
- Experience optimizing log collections from AWS platform, endpoints, and network devices
- Knowledge of AI/ML concepts as applied to security analytics such as anomaly detection, behavioral baselining, or threat scoring
- Ability to obtain a Secret clearance
- Bachelor's degree Nice to Have Skills
- Experience working in an agile working environment
- Experience working with DoD clients
- Experience with Elastic's ML jobs, including for User and Entity Behavior Analytics (UEBA), rare process detection, or anomalous login patterns
- Experience with Elastic AI Assistant or integration of LLMs into Elastic Security workflows such as natural language querying and alert triage assistance
- Experience building or fine-tuning ML models outside Elastic, including Python, scikit-learn, and PyTorch, for security use cases such as threat detection or lateral movement scoring
- Experience with Elastic Agent fleet management at scale, including custom integrations and policy management
- Experience with cross-domain data flows and working in multi-classification environments such as IL4, IL5, or IL6
- Experience with ES|QL or EQL for advanced threat hunting and detection-as-code workflows
- Kubernetes Certification such as Kubernetes and Cloud Native Certification or Kubernetes Application Developer Certification
Similar jobs
- OS
Network Engineer with Security Clearance
NewOpen Systems Technologies Corporation
Huntsville, AL🇺🇸Hybrid19 hours agoTCP/IPTechnology - SY
Cloud Architect - National Capital Region (NCR); Must have an ac with Security Clearance
NewSynertex
Washington, DC🇺🇸On-site19 hours agoGCPAWSAzure+3Technology - CO
AWS IAM Engineer/Cloud Identity Engineer
NewCollabera LLC
Chicago, IL🇺🇸$83/hrOn-site19 hours agoAWSSSOTechnology - TT
Cloud & DevSecOps Engineer with Security Clearance
NewTorch Technologies Inc.
Huntsville, AL🇺🇸$135k - $155k/yrOn-site19 hours agoAdministrative - AD
Network Infrastructure Engineer I, Amazon Dedicated Cloud (NIDD) with Security Clearance
NewAmazon Data Services, Inc.
Jessup, MD🇺🇸$96k - $166.3k/yrHybrid19 hours agoAWSTechnology - ST
Oracle ERP Cloud Finance Functional Architect
NewSRI Tech Solutions
United States🇺🇸Hybrid19 hours agoERPFinance