ALQIMI is a global information technology solutions company with offices around the world. For more than 20 years, ALQIMI has operated in demanding government agency and commercial environments delivering a wide range of cutting-edge IT solutions enabling these organizations to surpass their missions and goals. ALQIMI’s domain expertise includes large-scale enterprise computing, healthcare IT, big data software development and artificial intelligence. Join us as we continue to bring insights through innovation and help solve some of the world’s most complex problems.

Job Openings >> ELK SIEM Engineer
ELK SIEM Engineer
Summary
Title:ELK SIEM Engineer
ID:37714
Locations:N/A
Description

ALQIMI is seeking a Cyber Network Defense (CND) Elasticsearch, Log stash, and Kibana (ELK) Engineer/Subject Matter Expert (SME) to perform technical work as part of an integrated team of CND SMEs supporting the DoD’s JRSS (Joint Regional Security Stack) deployment activities. JRSS is a multi-year, global effort to improve the DoD’s security posture and provide enhanced security capabilities and analytics by centralizing and virtualizing network security into regional stacks rather than locally distributed appliances. This position is responsible for providing configuration, implementation, configuration and ongoing performance enhancement work for ELK in the JRSS environment.

You will also work as part of a multi-disciplinary team that supports the active and passive Computer Network Defense (CND) tools deployed in stacks. Must be able to integrate with other technical teams, with DISA personnel, with vendor technical support personnel, and with technical representatives from DoD services, working as part of an integrated, cross-platform team that provides CND capability, and military base/post/camp/station migration support services DoD-wide as the JRSS stacks are deployed and used.

Primary Responsibilities:

You will support ELK tool and will assist with configuration, troubleshooting, support and project management of ELK integration. You should also have extensive CND architectural design experience as well as significant hands-on experience with ELK.

To be successful in this role, you will be able to do the following:

  • Provide SME knowledge of Full Packet Capture via Google Stenographer, Protocol Analysis and Metadata via Bro, Signature Based Alerting via Suricata, Recursive File Scanning via FSF, message queuing via Filebeat, Message Queuing and Distribution via Apache Kafka and Message Transport via Log stash
  • Create viewable Kibana dashboards to provide visibility into ingested log data
  • Resolve ELK infrastructure or system issues
  • Create Suricata security rules (alerts) and Kibana dashboards that trigger on anomalous activities or threat detections
  • Create alerts that trigger/activate on configured setting to deploy or sends email to a particulate destination email or groups
  • Troubleshoot and tune signature based alerting via Suricata, recursive file scanning via FSF, message queuing and distribution via Apache Kafka and message transport via Log stash
  • Strong knowledge of Ansible or Python scripting, Linux CENTOS/ Red Hat operating system commands, file data storage, indexing, and searching via Elasticsearch
  • Provide ELK SME support, assisting customers when ingestion of logs are not working properly or with ELK communication issues
  • Experience with Splunk, IDS/IPS technologies, NESSUS, or Demisto

Basic Qualifications:

  • Bachelor’s degree from an accredited college in a related discipline, or equivalent experience/combined education, with 12 or more years’ experience; or 10 years’ experience with a related Master’s degree or equivalent work experience.
  • To be a successful fit to this assignment, you should be well versed in TCP/IP communications.
  • Have a general knowledge of router and firewall functionality on a network.
  • Familiar with the MS Office tool suite.
  • Excellent written and oral communications skills and be able to appropriately present highly technical material to both technical and non-technical audiences
  • Per contract requirements, U.S. citizenship and an active DoD Secret clearance is required. In addition, you must be able to successfully obtain up to Top Secret based on requirements from the customer and program.
  • DoD 8570 IAT2 certification is required


Preferred Qualifications:

  • Prior experience as a network intrusion analyst or Security Operations Center analyst.
  • Experience configuring and maintaining the tool in a multi-tenant environment

Experience with one or more of the CND tools:

    • Fidelis DLP and MDE
    • Tipping Point
    • Splunk
    • Firepower
    • Gigamon
    • Opswat
    • Inquest
    • Corelight/Bro
    • ELK tools

Who are we?

Headquartered in Rockville, MD, ALQIMI has developed an outstanding track record of designing, integrating, and managing complex technological solutions for customers around the world. Our IT services group is our founding heritage and services the intelligence and commercial communities with technologically sophisticated services including cybersecurity, big data and software development. We take pride in using our demonstrated ability to build profitable businesses, subject matter expertise and ecosystems to incubate new ideas. We have established new businesses in the data analytics, military facilities construction management and energy industries and intend to incubate additional opportunities.

What makes ALQIMI unique is that we offer challenging projects, excellent benefits, work/life balance, and a fair and ethical executive team.

ALQIMI provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, sex, sexual orientation, national origin, marital status, age, disability (including disability due to pregnancy) or genetics, protected veteran status, or any other characteristic protected by law. ALQIMI complies with applicable state and local laws governing nondiscrimination in employment in every location in which the company has facilities. This policy applies to all terms and conditions of employment.

Company Benefits

  • Competitive salary
  • Comprehensive health insurance plan
  • Employee Referral Bonus Program
  • 401(k) retirement plan with company paid contribution
  • Paid Time Off + holidays

We truly believe the right work-life balance can exist, and it's here at ALQIMI. Our work is extremely important, but your job is just a part of who you are.

When you enjoy your life outside of our walls, you're at your best the next time you walk through our doors. We do all we can to assure that happens every day.

 

This opening is closed and is no longer accepting applications
ApplicantStack powered by Swipeclock