Stand out for this role — generate a tailored resume and cover letter in about a minute.
ASRC Federal is seeking an Elastic SIEM Engineer to maintain and enhance enterprise-scale Elastic Stack security solutions in support of the DCSA program. The role involves designing detection rules, data ingestion pipelines across cloud and on‑prem sources, and creating dashboards to empower SOC analysts.
Required five years of Elastic experience, active Secret clearance, and DoD IAM/IAT Level II certifications.
ASRC Federal is a leading government contractor furthering missions in space, public health and defense. As an Alaska Native owned corporation, our work helps secure an enduring future for our shareholders. Join our team and discover why we are a top veteran employer and Certified Great Place to Work.
ASRC Federal is actively hiring an Elastic SIEM Engineer in support of our Defense Counterintelligence Security Agency (DCSA) program based out of Hanover MD.
Remote flexibility available! Telework offered with a requirement to be onsite up to one day a week at Hanover, MD.
We invest in the lives of our employees, both in and out of the workplace, by providing competitive pay and benefit packages. This position is offering a pay range of $150,000.00 - $165,450.00 depending on experience, seniority, geographic locations, and factors permitted by law. Benefits offered may include health care, dental, vision, life insurance; 401k; education assistance; paid time off including Paid Time Off, holidays and any other paid leave required by law.
As an Elastic SIEM Engineer, your primary duty is to maintain enterprise-scale Elastic Stack security solutions that safeguard our national security systems. You will design and implement advanced detection rules, correlation searches, and analytics pipelines using Elasticsearch, Logstash, Kibana, and Elastic Security to identify sophisticated threats and adversary activity. A key part of your role involves optimizing data ingestion pipelines from diverse sources including cloud platforms (AWS, Azure, GCP), network devices, endpoints, and security tools, ensuring high availability, performance, and scalability of the SIEM infrastructure. You will develop custom dashboards, visualizations, and threat hunting workbenches that empower SOC analysts to detect and respond to incidents effectively, while collaborating with security operations, engineering teams, and government stakeholders to enhance detection capabilities. Additionally, you will be responsible for tuning detection logic to reduce false positives, automating security workflows, integrating threat intelligence feeds, and ensuring all activities align with critical compliance standards like NIST 800-53 and RMF through comprehensive documentation and technical leadership.
We invest in the lives of our employees, both in and out of the workplace, by providing competitive pay and benefits packages. Benefits offered may include health care, dental, vision, life insurance; 401(k); education assistance; paid time off including PTO, holidays, and any other paid leave required by law. The salary offered will depend on several factors including, but not limited to, relevant experience, skills, education, geographic location, internal equity, business needs, and other factors permitted by law. Posted pay ranges are a general guideline only and are not a guarantee of compensation or salary.
ASRC Federal and its Subsidiaries are Equal Opportunity employers. All qualified applicants will receive consideration for employment without regard to race, gender, color, age, sexual orientation, gender identification, national origin, religion, marital status, ancestry, citizenship, disability, protected veteran status, or any other factor prohibited by applicable law.