Cybersecurity Engineer (Elastic)

Georgia Institute of Technology

Atlanta (GA)

On-site

USD 112,000 - 114,000

Full time

10 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Georgia Tech is seeking a Cybersecurity Engineer (Elastic) to design and implement secure network architectures, maintain security systems, and lead security operations on campus. You will analyze requirements, develop security protocols, and collaborate with IT teams to deploy defenses effectively.

Ideal candidates have 6–7 years of experience, a CS/IT degree, and strong Elastic Security and SIEM skills, with on-site presence in Atlanta.

Qualifications

  • Bachelor's degree in Computer Science or related field or equivalent experience.
  • Overnight travel required; on-site daily service delivery hours.
  • Six to seven years of job-related experience.

Responsibilities

  • Develop and implement secure network architectures and security policies.
  • Perform risk analysis, vulnerability scanning, and testing; respond accordingly.
  • Identify and mitigate vulnerabilities affecting information assets.
  • Evaluate and recommend information security tech acquisitions.
  • Develop and conduct security training and instruction.
  • Maintain security systems in compliance with regulations.
  • Perform other duties as assigned.

Skills

Elastic Security
SIEM
Threat Detection
Endpoint Security
Security Operations
Incident Response
Detection Rules
Machine Learning
Elastic Agent
Fleet Server
Elasticsearch
Kibana
Logstash
Beats
NIST CSF/800-53/CIS
Security Integrations
SOAR
Python
PowerShell
REST APIs
Terraform
CI/CD
Infrastructure as Code
Threat Intelligence
MITRE ATT&CK
Cloud Security

Education

Bachelor's Degree in CS/IT or related
Master's Degree (preferred)

Tools

Terraform
CI/CD
REST APIs

Job description

Job Title: Cybersecurity Engineer (Elastic)

Location: Atlanta, Georgia

Regular/Temporary: Regular

Full/Part Time: Full-Time

Job ID: 303485

Georgia Tech prides itself on its technological resources, collaborations, high-quality student body, and its commitment to building an outstanding and diverse community of learning, discovery, and creation. We strongly encourage applicants whose values align with our institutional values, as outlined in our strategic plan. These values include academic excellence, diversity of thought and experience, inquiry and innovation, collaboration and community, and ethical behavior and stewardship. Georgia Tech has policies to promote a healthy work-life balance and is aware that attracting faculty may require meeting the needs of two careers.

About Georgia Tech

Georgia Tech is a top-ranked public research university situated in the heart of Atlanta, a diverse and vibrant city with numerous economic and cultural strengths. The Institute serves more than 45,000 students through top-ranked undergraduate, graduate, and executive programs in engineering, computing, science, business, design, and liberal arts. Georgia Tech's faculty attracted more than $1.4 billion in research awards this past year in fields ranging from biomedical technology to artificial intelligence, energy, sustainability, semiconductors, neuroscience, and national security. Georgia Tech ranks among the nation's top 20 universities for research and development spending and No. 1 among institutions without a medical school.

Georgia Tech's Mission and Values

Georgia Tech's mission is to develop leaders who advance technology and improve the human condition. The Institute has nine key values that are foundational to everything we do:

  1. Students are our top priority.
  2. We strive for excellence.
  3. We thrive on diversity.
  4. We celebrate collaboration.
  5. We champion innovation.
  6. We safeguard freedom of inquiry and expression.
  7. We nurture the wellbeing of our community.
  8. We act ethically.
  9. We are responsible stewards.

Over the next decade, Georgia Tech will become an example of inclusive innovation, a leading technological research university of unmatched scale, relentlessly committed to serving the public good; breaking new ground in addressing the biggest local, national, and global challenges and opportunities of our time; making technology broadly accessible; and developing exceptional, principled leaders from all backgrounds ready to produce novel ideas and create solutions with real human impact.

Location

Atlanta, Georgia (In-Person Work - In the office)

Job Summary

Cybersecurity Engineers design and implement secure network architectures and solutions to protect the institution's digital assets against cyber threats. This role involves analyzing security requirements, developing security protocols, and collaborating with IT teams to ensure the effective deployment of security technologies.

Responsibilities
  • Develop and recommend information security policies, standards and best practices within assigned campus area or organization.
  • Perform periodic risk analysis, vulnerability scanning and testing; responding as appropriate.
  • Identify and mitigate vulnerabilities posing threats to information assets of assigned units.
  • Evaluate and, as appropriate, recommend acquisition of new and improved information security technology.
  • Develop and conduct training and instruction on information security related areas.
  • Maintain security systems in compliance with applicable regulations.
  • Perform other duties as assigned
Required Qualifications

Educational Requirements

Bachelor's Degree in Computer Science, Information Technology or related field or equivalent combination of education and experience

Other Required Qualifications

Overnight travel required for project delivery; flexibility in on-site daily service delivery hours (due to client shift schedules, project requirements).

Required Experience

Six to seven years of job related experience

Preferred Qualifications

Additional Preferred Qualifications

Certified Information Systems Security Professional (CISSP); Global Information Assurance Certification (GIAC)

Preferred Educational Qualifications

Master's Degree

Preferred Skills & Qualifications

  • Advanced experience administering and supporting Elastic Cloud Enterprise Security deployments, including SIEM, threat detection, and endpoint security capabilities.
  • Strong knowledge of security operations, threat detection engineering, incident response, and security monitoring methodologies.
  • Experience developing and tuning detection rules, machine learning jobs, alerts, dashboards, and security use cases within Elastic Security.
  • Experience managing Elastic Agent, Fleet Server, endpoint telemetry collection, and large-scale agent deployments.
  • Proficiency with Elasticsearch, Kibana, Logstash, Beats, data streams, index lifecycle management, and data onboarding processes.
  • Knowledge of security frameworks and compliance standards including NIST CSF, NIST 800-53, CIS Controls, FERPA, HIPAA, and PCI-DSS.
  • Experience integrating security platforms with enterprise systems such as ServiceNow, Microsoft Defender, Azure, AWS, Active Directory, Entra ID, VPN, firewall, identity, and cloud security platforms.
  • Experience with SOAR workflow development, orchestration, automation, and response playbooks.
  • Strong scripting and automation skills using Python, PowerShell, REST APIs, or similar technologies.
  • Experience with Terraform, CI/CD pipelines, and Infrastructure as Code
  • Experience building metrics, dashboards, executive reporting, and operational performance measurements.
  • Knowledge of threat intelligence integration, MITRE ATT&CK mapping, threat hunting, and adversary emulation techniques.
  • Experience supporting highly available cloud-based security platforms in complex enterprise environments.
  • Ability to lead technical projects and mentor junior engineers while serving as a technical escalation point.
  • CISSP (Certified Information Systems Security Professional)
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Continuous Monitoring Certification (GMON)
  • GIAC Certified Enterprise Defender (GCED)
  • GIAC Certified Intrusion Analyst (GCIA)
  • CompTIA Security+
  • CompTIA CySA+
  • Certified SOC Analyst (CSA)
Proposed Salary

$112,410 - $113,527, depending on experience and preferred skills

Knowledge, Skills, & Abilities

SKILLS This position requires advanced knowledge of information security concepts, technology and practices and working knowledge of pertinent regulations. Skills in developing architecture for and implementing various information security tools and products and managing and promoting security programs within an organization is required as are skills in organization, project/team leadership and customer service.

USG Core Values

The University System of Georgia is comprised of our 25 institutions of higher education and learning as well as the System Office. Our USG Statement of Core Values are Integrity, Excellence, Accountability, and Respect. These values serve as the foundation for all that we do as an organization, and each USG community member is responsible for demonstrating and upholding these standards. More details on the USG Statement of Core Values and Code of Conduct are available in USG Board Policy 8.2.18.1.2 and can be found online at https://www.usg.edu/policymanual/section8/C224/#p8.2.18_personnel_conduct.

Additionally, USG supports Freedom of Expression as stated in Board Policy 6.5 Freedom of Expression and Academic Freedom found online at https://www.usg.edu/policymanual/section6/C2653.

Equal Employment Opportunity

The Georgia Institute of Technology (Georgia Tech) is an Equal Employment Opportunity Employer. The Institute is committed to maintaining a fair and respectful environment for all. To that end, and in accordance with federal and state law, Board of Regents policy, and Institute policy, Georgia Tech provides equal opportunity to all faculty, staff, students, and all other members of the Georgia Tech community, including applicants for admission and/or employment, contractors, volunteers, and participants in institutional programs, activities, and services. Georgia Tech complies with all applicable laws and regulations governing equal opportunity in the workplace and in educational activities.

Equal opportunity and decisions based on merit are fundamental values of the University System of Georgia ("USG") and Georgia Tech. Georgia Tech prohibits discrimination, including discriminatory harassment, on the basis of an individual's race, ethnicity, ancestry, color, religion, sex (including pregnancy), national origin, age, disability, genetics, or veteran status in its programs, activities, employment, and admissions. Further, Georgia Tech prohibits citizenship status, immigration status, and national origin discrimination in hiring, firing, and recruitment, except where such restrictions are required in order to comply with law, regulation, executive order, or Attorney General directive, or where they are required by Federal, State, or local government contract.

Other Information

This is not a supervisory position.

This position does not have any financial responsibilities.

This position will not be required to drive.

This role is not considered a position of trust.

This position does not require a purchasing card (P-Card).

This position will not travel.

This position does not require security clearance.

Other Information Other Requirements
  • Ability to respond to high-priority cybersecurity incidents outside normal business hours when necessary.
  • Demonstrated ability to balance operational support, platform engineering, and strategic improvement initiatives.
  • Ability to communicate highly technical concepts to both technical and non-technical audiences.
  • Ability to work effectively in a collaborative environment involving security operations, infrastructure, networking, cloud services, application development, and business stakeholders.
  • Commitment to maintaining current knowledge of emerging threats, attack techniques, and security technologies.
  • Capability to handle sensitive and confidential information with discretion and professionalism.
  • Successful completion of all background and security screening requirements established by Georgia Tech.
What a Strong Candidate Should Demonstrate
  • Deep technical expertise in Elastic Security and modern Security Operations Center (SOC) practices.
  • The ability to transform large volumes of security data into actionable detections, alerts, and intelligence.
  • Proven experience designing and implementing scalable SIEM and security analytics solutions.
  • Strong analytical and investigative skills, including threat hunting and root-cause analysis.
  • A proactive approach to improving security visibility, operational efficiency, and incident response capabilities through automation.
  • Experience reducing alert fatigue through effective detection engineering and tuning methodologies.
  • Leadership qualities that enable them to guide technical direction, influence stakeholders, and mentor peers.
  • Strong ownership and accountability for critical security platforms and services.
  • Exceptional written and verbal communication skills.
  • A continuous improvement mindset focused on operational excellence, risk reduction, and measurable security outcomes.
  • The ability to align security engineering decisions with institutional objectives, compliance requirements, and business priorities.
  • Experience with Terraform, CI/CD pipelines, and Infrastructure as Code
Background Check

Successful candidate must be able to pass a background check. Please visit https://usg.policystat.com/policy/19298143/latest/

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Engineer (Elastic)
Cybersecurity Engineer (Elastic)

Georgia Tech • Atlanta (GA)

On-site
USD 112,000 - 114,000
Manager- Information Systems Security (Network)
Manager- Information Systems Security (Network)

Georgia Tech • Atlanta (GA)

On-site
USD 129,000 - 150,000
Information Technology Project Manager (Governance, Risk, and Compliance)
Information Technology Project Manager (Governance, Risk, and Compliance)

Georgia Institute of Technology • Atlanta (GA)

On-site
USD 112,000 - 130,000
Research Security Specialist (SAP/SCI)
Research Security Specialist (SAP/SCI)

Georgia Institute of Technology • Georgia

On-site
USD 72,000 - 122,000
Governance Risk & Compliance Manager
Governance Risk & Compliance Manager

Inside Higher Ed • Atlanta (GA)

On-site
Security Operations Center (SOC) Lead
Security Operations Center (SOC) Lead

Georgia Gwinnett College • Lawrenceville (GA)

On-site
USD 71,700 - 91,400
Cybersecurity Engineer
Cybersecurity Engineer

CFS • Atlanta (GA)

On-site
USD 125,000 - 135,000
Security Operations Engineer (Levels III - V)
Security Operations Engineer (Levels III - V)

Gasoc • Tucker (GA)

On-site
USD 99,360 - 173,900
Medical
Dental
Vision
+6
Secure Computing Engineer (Level 3, 4) - HAC - Colorado Springs, CO - Open Rank
Secure Computing Engineer (Level 3, 4) - HAC - Colorado Springs, CO - Open Rank

Georgia Tech Research Institute (GTRI) • Colorado Springs (CO)

On-site
USD 120,000 - 166,000
Elastic Security Engineer: SIEM & Threat Detection (Onsite)
Elastic Security Engineer: SIEM & Threat Detection (Onsite)

Georgia Institute of Technology • Atlanta (GA)

On-site
USD 112,000 - 114,000