Senior Cybersecurity Engineer – Elastic SIEM

Cybersecurity Jobs

San Antonio (TX)

Vor Ort

USD 145.000 - 180.000

Vollzeit

14 Tage+
Bewerbungsgenerator

Schick keinen Standard-Lebenslauf — erstelle einen Lebenslauf und ein Anschreiben, die genau auf diese Rolle zugeschnitten sind.

Schaffe es an den ATS-Filtern vorbei

Benefits dieser Stelle

Health insurance
Life insurance
Disability insurance
Retirement plan
Paid holidays
Paid time off

Zusammenfassung

Maximus is seeking a senior SIEM engineer to support defense operations using Elastic SIEM across classified enclaves. This on-site role in San Antonio, TX, requires TS/SCI clearance and delivers comprehensive insurance, retirement, and PTO benefits.

You will engineer, operate, and sustain SIEM capabilities, mentor engineers, and collaborate with cyber operators on detection and incident workflows in DoD-adjacent environments.

Qualifikationen

  • Active TS/SCI clearance required or eligible.
  • 7+ years hands-on cybersecurity engineering experience.
  • Elastic SIEM integrations and troubleshooting in operational environments.

Aufgaben

  • Lead complex SIEM engineering tasks with minimal supervision.
  • Operate and sustain Elastic SIEM across multiple enclaves.
  • Monitor SIEM health, capacity, and outages per SLAs.
  • Develop detection rules, alerts, and dashboards in Elastic.
  • Ingest and normalize logs from endpoint, network, cloud, and applications.

Kenntnisse

TS/SCI clearance
Cybersecurity engineering
Leadership
Mentoring engineers
Threat detection

Ausbildung

Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or related field

Tools

Elastic Stack
Kubernetes/EKS
AWS GovCloud

Jobbeschreibung

Maximus offers a mission-focused role supporting defensive cyber operations from the Elastic SIEM stack across multiple classified enclaves. This on-site position in San Antonio, TX supports health insurance coverage, life and disability insurance, a retirement savings plan, paid holidays, and paid time off. If you hold an active TS/SCI clearance, you can help engineer, operate, and sustain SIEM capabilities used for continuous monitoring and security event analysis.

Responsibilities
  • Lead complex SIEM engineering tasks with minimal supervision while providing technical guidance to the team.
  • Administer, operate, and sustain the Elastic SIEM platform using Elasticsearch, Kibana, Logstash, and Beats/Elastic Agent across NIPRNet, SIPRNet, and JWICS environments.
  • Monitor SIEM health, perform capacity planning, and resolve complex platform outages and degradations in accordance with defined SLAs.
  • Develop, tune, and maintain detection rules, alerts, dashboards, and visualizations in Elastic to support DCO mission requirements.
  • Ingest, normalize, and validate log data from diverse sources including endpoint, network, cloud, and application telemetry.
  • Collaborate with cyber operators and analysts to support threat detection, alert triage, and cyber incident investigation workflows.
  • Identify opportunities to improve SIEM coverage, data quality, and detection fidelity, and lead implementation of improvements in coordination with the Government PMO.
  • Support CSSP activities, including continuous monitoring and security event analysis.
  • Create and maintain technical documentation such as runbooks, standard operating procedures (SOPs), and knowledge base articles.
  • Provide technical guidance and mentoring to journeyman engineers, and review SIEM configurations and detection rules.
  • Participate in Agile/SAFe Program Increment (PI) planning and sprint execution in support of platform delivery.
  • Adhere to Air Force cybersecurity standards and all applicable DoD, IC, and USAF policy and directives across all enclaves.
Requirements
  • Active Top Secret / SCI (TS/SCI) security clearance.
  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or related field (or equivalent experience).
  • 7+ years of hands-on cybersecurity engineering experience.
  • Advanced proficiency demonstrating experience leading complex Elastic SIEM integrations and troubleshooting, reviewing technical work, and mentoring engineers.
  • Demonstrated hands-on experience with Elastic Stack (Elasticsearch, Kibana, Logstash, Beats/Elastic Agent) in an operational SIEM environment.
  • Experience supporting threat detection, alert triage, and/or cyber incident investigation.
  • Familiarity with DCO concepts, CSSP operations, and defensive cyber frameworks.
  • Experience working across multiple network security domains (NIPR, SIPR, or JWICS).
  • Meet applicable DoD 8140 requirements for the assigned work role: DCWF 521, Cyber Defense Infrastructure Support Specialist, Advanced Proficiency (specific required certifications pending contract confirmation).
Preferred Skills and Qualifications
  • Experience with SIEM/SOAR integrations (e.g., Elastic, Palo Alto Cortex XSOAR, or similar).
  • Familiarity with Elastic Fleet/Agent management and integration development.
  • Experience with AWS GovCloud environments (IL4/IL5/IL6).
  • Knowledge of MITRE ATT&CK framework and its application to detection engineering.
  • Experience with scripting/automation (Python, Bash, KQL/EQL) for SIEM rule development and data pipeline management.
  • Familiarity with container-based deployments (Kubernetes/EKS) in classified environments.
  • Prior experience supporting USAF or DoD DCO programs.
  • One or more certifications preferred: Elastic Certified Engineer, CompTIA CySA+, GCIA, or GCIH.
Compensation and Location

Salary range: USD 145,000 - 180,000 per year.
Location: San Antonio, TX, United States (onsite).

Accommodations

Maximus provides reasonable accommodations to individuals requiring assistance during any phase of the employment process due to a disability, medical condition, or physical or mental impairment. If you require assistance at any stage of the employment process, including accessing job postings, completing assessments, or participating in interviews, contact People Operations at applicantaccom@maximus.com.

Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.

oder ziehe deine Datei hierhin.

Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Senior Cybersecurity Engineer âEUR\" Elastic SIEM
Senior Cybersecurity Engineer âEUR\" Elastic SIEM

Maximus • San Antonio (TX)

Vor Ort
USD 120.000 - 190.000
Senior Cybersecurity Engineer - Elastic SIEM
Senior Cybersecurity Engineer - Elastic SIEM

Maximus • San Antonio (TX)

Vor Ort
USD 140.000 - 180.000
Senior Cybersecurity Engineer – Elastic SIEM
Senior Cybersecurity Engineer – Elastic SIEM

Maximus • San Antonio (TX)

Hybrid
USD 120.000 - 170.000
Junior Cybersecurity Engineer âEUR\" Elastic SIEM
Junior Cybersecurity Engineer âEUR\" Elastic SIEM

Maximus • San Antonio (TX)

Vor Ort
USD 65.000 - 95.000
Cybersecurity Engineer – Elastic SIEM (Journeyman)
Cybersecurity Engineer – Elastic SIEM (Journeyman)

Maximus, Inc. • San Antonio (TX)

Vor Ort
USD 120.000 - 140.000
Cybersecurity Engineer - Elastic SIEM SME
Cybersecurity Engineer - Elastic SIEM SME

Maximus • San Antonio (TX)

Vor Ort
USD 130.000 - 180.000
Junior Cybersecurity Engineer – Elastic SIEM
Junior Cybersecurity Engineer – Elastic SIEM

Maximus, Inc. • San Antonio (TX)

Vor Ort
USD 90.000 - 110.000
Cybersecurity Engineer âEUR\" Elastic SIEM SME
Cybersecurity Engineer âEUR\" Elastic SIEM SME

Maximus • San Antonio (TX)

Vor Ort
USD 150.000 - 190.000
Cybersecurity Engineer - Elastic SIEM (Journeyman)
Cybersecurity Engineer - Elastic SIEM (Journeyman)

Maximus • San Antonio (TX)

Vor Ort
USD 130.000 - 185.000
Junior Cybersecurity Engineer - Elastic SIEM
Junior Cybersecurity Engineer - Elastic SIEM

Maximus • San Antonio (TX)

Vor Ort
USD 70.000 - 90.000