Cybersecurity Engineer – Elastic SIEM SME

Maximus

San Antonio (TX)

Hybrid

USD 120,000 - 180,000

Full time

6 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Maximus is seeking a Cybersecurity Engineer specialized in Elastic SIEM to serve as a subject matter expert. The role demands hands-on engineering across Elastic Stack components in classified DoD environments and the ability to guide a team and customers.

You will ensure SIEM health, design detection rules, and support incident investigations across multiple networks. This on-site position requires an active TS/SCI clearance and a strong background in cybersecurity engineering within DoD/CSSP

Qualifications

  • Active TS/SCI security clearance.
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field.
  • 10+ years of hands-on cybersecurity engineering experience.
  • Advanced proficiency in Elastic SIEM architecture, standards, troubleshooting, and mentoring teams.
  • Hands-on experience with Elastic Stack in operational SIEM environments.
  • Experience supporting threat detection, alert triage, and cyber incident investigation.
  • Familiarity with DCO concepts, CSSP operations, and defensive cyber frameworks.
  • Experience across NIPR, SIPR, or JWICS networks.

Responsibilities

  • Serve as Elastic SIEM SME, providing independent technical judgment and guidance to the team and customer.
  • Direct architecture, operation, and sustainment of Elastic SIEM across NIPRNet, SIPRNet, and JWICS.
  • Monitor SIEM health, plan capacity, and lead resolution of outages per SLAs.
  • Design and review detection rules, alerts, dashboards, and visualizations in Elastic for DCO requirements.
  • Ingest and normalize log data from endpoint, network, cloud, and app telemetry.
  • Collaborate with cyber operators to support threat detection and incident investigation workflows.
  • Identify opportunities to improve SIEM coverage and data quality; lead improvement efforts with Government PMO.
  • Support CSSP activities including continuous monitoring and security event analysis.
  • Create and maintain runbooks, SOPs, and knowledge base articles.
  • Mentor engineers and establish technical standards; participate in Agile/SAFe PI planning and sprint cycles.

Skills

Elastic SIEM
Threat detection
Incident investigation
Security architecture

Education

Bachelor's degree in Cybersecurity, Computer Science, Information Technology

Tools

Elasticsearch
Kibana
Logstash
Beats/Elastic Agent

Job description

Cybersecurity Engineer – Elastic SIEM SME

General information

Date

Friday, September 25, 2026

City

San Antonio

State

TX

Country

United States

Working time

Full-time

Description & Requirements

Maximus is seeking aCybersecurity Engineer – Elastic SIEM SME.

This role is on-site in San Antonio, TX and requires an active TS/SCI security clearance.

Maximus TCS (Technology and Consulting Services) Internal Job Profile Code: TCS059, T5, Band 8

Job-Specific Essential Duties and Responsibilities:
  • Serve as the Elastic SIEM subject matter expert, exercising independent technical judgment and advising the team and customer.
  • Provide expert technical direction for the architecture, operation, and sustainment of the Elastic SIEM platform (Elasticsearch, Kibana, Logstash, Beats/Elastic Agent) across NIPRNet, SIPRNet, and JWICS environments.
  • Monitor SIEM health, perform capacity planning, and lead resolution of the most complex platform outages and degradations in accordance with defined SLAs.
  • Guide the design and review of detection rules, alerts, dashboards, and visualizations in Elastic to support DCO mission requirements.
  • Ingest, normalize, and validate log data from diverse sources including endpoint, network, cloud, and application telemetry.
  • Collaborate with cyber operators and analysts to support threat detection, alert triage, and cyber incident investigation workflows.
  • Identify opportunities to improve SIEM coverage, data quality, and detection fidelity; lead implementation of improvements in coordination with the Government PMO.
  • Support Cyber Security Service Provider (CSSP) activities including continuous monitoring and security event analysis.
  • Create and maintain technical documentation including runbooks, standard operating procedures (SOPs), and knowledge base articles.
  • Advise the customer and mentor senior and journeyman engineers; establish technical standards and review complex SIEM designs.
  • Participate in Agile/SAFe Program Increment (PI) planning and sprint execution in support of platform delivery.
  • Adhere to Air Force cybersecurity standards and all applicable DoD, IC, and USAF policy and directives across all enclaves.
Job-Specific Minimum Requirements:
  • Active Top Secret / SCI (TS/SCI) security clearance.
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field.
  • 10+ years of hands‑on cybersecurity engineering experience.
  • Advanced proficiency level: demonstrated expertise in Elastic SIEM architecture, technical standards, complex troubleshooting, and advising technical teams and customers.
  • Demonstrated hands‑on experience with Elastic Stack (Elasticsearch, Kibana, Logstash, Beats/Elastic Agent) in an operational SIEM environment.
  • Experience supporting threat detection, alert triage, and/or cyber incident investigation.
  • Familiarity with DCO concepts, CSSP operations, and defensive cyber frameworks.
  • Experience working across multiple network security domains (NIPR, SIPR, or JWICS).
  • Meet applicable DoD 8140 requirements for the assigned work role. DCWF 521, Cyber Defense Infrastructure Support Specialist, Advanced Proficiency.
Preferred Skills and Qualifications:
  • Experience with SIEM/SOAR integrations (e.g., Elastic, Palo Alto Cortex XSOAR, or similar).
  • Familiarity with Elastic's Fleet/Agent management and integration development.
  • Experience with AWS GovCloud environments (IL4/IL5/IL6).
  • Knowledge of MITRE ATT&CK framework and its application to detection engineering.
  • Experience with scripting/automation (Python, Bash, KQL/EQL) for SIEM rule development and data pipeline management.
  • Familiarity with container‑based deployments (Kubernetes/EKS) in classified environments.
  • Prior experience supporting USAF or DoD DCO programs.
  • One or more of the following certifications preferred: Elastic Certified Engineer, CompTIA CySA+, GCIA, or GCIH.

#techjobs #clearance #veteransPage

TCS059, T5, Band 8

EEO Statement

Maximus is an equal opportunity employer. We evaluate qualified applicants without regard to race, color, religion, sex, age, national origin, disability, veteran status, genetic information and other legally protected characteristics.

Pay Transparency

Maximus compensation is based on various factors including but not limited to job location, a candidate's education, training, experience, expected quality and quantity of work, required travel (if any), external market and internal value analysis including seniority and merit systems, as well as internal pay alignment. Annual salary is just one component of Maximus's total compensation package. Other rewards may include short- and long-term incentives as well as program-specific awards. Additionally, Maximus provides a variety of benefits to employees, including health insurance coverage, life and disability insurance, a retirement savings plan, paid holidays and paid time off. Compensation ranges may differ based on contract value but will be commensurate with job duties and relevant work experience. An applicant's salary history will not be used in determining compensation. Maximus will comply with regulatory minimum wage rates and exempt salary thresholds in all instances.

Accommodations

Maximus provides reasonable accommodations to individuals requiring assistance during any phase of the employment process due to a disability, medical condition, or physical or mental impairment. If you require assistance at any stage of the employment process—including accessing job postings, completing assessments, or participating in interviews,—please contact People Operations at applicantaccom@maximus.com

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Cybersecurity Engineer - Elastic SIEM
Senior Cybersecurity Engineer - Elastic SIEM

Maximus • San Antonio (TX)

On-site
USD 140,000 - 180,000
Senior Cybersecurity Engineer âEUR\" Elastic SIEM
Senior Cybersecurity Engineer âEUR\" Elastic SIEM

Maximus • San Antonio (TX)

On-site
USD 120,000 - 190,000
Junior Cybersecurity Engineer – Elastic SIEM
Junior Cybersecurity Engineer – Elastic SIEM

Maximus • San Antonio (TX)

Hybrid
USD 70,000 - 90,000
Cybersecurity Engineer – Elastic SIEM (Journeyman)
Cybersecurity Engineer – Elastic SIEM (Journeyman)

Maximus • San Antonio (TX)

Hybrid
USD 140,000 - 180,000
Cybersecurity Engineer - Elastic SIEM SME
Cybersecurity Engineer - Elastic SIEM SME

Maximus • San Antonio (TX)

On-site
USD 130,000 - 180,000
Junior Cybersecurity Engineer âEUR\" Elastic SIEM
Junior Cybersecurity Engineer âEUR\" Elastic SIEM

Maximus • San Antonio (TX)

On-site
USD 65,000 - 95,000
Cybersecurity Engineer âEUR\" Elastic SIEM SME
Cybersecurity Engineer âEUR\" Elastic SIEM SME

Maximus • San Antonio (TX)

On-site
USD 150,000 - 190,000
Cybersecurity Engineer âEUR\" Elastic SIEM (Journeyman)
Cybersecurity Engineer âEUR\" Elastic SIEM (Journeyman)

Maximus • San Antonio (TX)

On-site
USD 140,000 - 190,000
Cybersecurity Engineer - Elastic SIEM (Journeyman)
Cybersecurity Engineer - Elastic SIEM (Journeyman)

Maximus • San Antonio (TX)

On-site
USD 130,000 - 185,000
Senior Cybersecurity Engineer – Elastic SIEM
Senior Cybersecurity Engineer – Elastic SIEM

Maximus • San Antonio (TX)

Hybrid
USD 120,000 - 170,000