- Company Name
- Seneca Resources
- Job Title
- SIEM Engineer
- Job Description
-
**Job title**
Sr. SIEM Engineer (Elastic + Confluent)
**Role Summary**
Senior engineer responsible for designing, deploying, configuring, and maintaining a consolidated SIEM platform built on Elastic Stack and Confluent. Oversees end‑to‑end lifecycle from architecture to production, ensuring optimal performance, security, and integration with SOAR and threat intelligence tools. Drives incident response and SOC operations while providing automated and ML‑based alerting.
**Expectations**
- Deliver a unified SIEM solution for ≈40 legacy platforms.
- Maintain security posture with zero‑day patching and hardening.
- Operate daily SOC functions and lead incident investigations.
- Provide dashboards, alerts, and reporting to meet executive and stakeholder needs.
- Follow ITIL change management and secure clearance protocols.
**Key Responsibilities**
- Design, deploy, and upgrade Elastic Stack & Confluent environments.
- Configure indexing, ILM, hot/warm/cold tiers, shard allocation, snapshots, and restores.
- Develop Logstash/Elasticsearch ingest pipelines and data mappings (ECS).
- Build Kibana visualizations, dashboards, and custom reports via APIs.
- Create alerting with Watcher/Kibana Rules, connectors, and ticketing integrations.
- Develop ML jobs for anomaly detection and KPI monitoring.
- Integrate Elastic with external systems (SOAR, Threat Intel, LDAP, SAML, PKI).
- Automate deployment/maintenance using Ansible, shell, Python, PowerShell.
- Conduct performance tuning, security hardening, and scalability design.
- Lead incident response, forensic investigations, and executive briefings.
- Manage day‑to‑day SOC operations and incident investigations.
**Required Skills**
- 5+ years hands‑on Elastic Stack (Elasticsearch, Logstash, Kibana, Beats, ML) and SOAR experience.
- Proficiency with HL/WM architecture, ILM, query tuning, cluster security, and authentication mechanisms.
- Experience building pipelines, dashboards, alerting, ML, and data normalization (ECS).
- System administration on Red Hat Enterprise Linux.
- Secret clearance; DoD 8140/8570 IAT Level II.
- Security+ certification.
**Required Education & Certifications**
- Security+ (mandatory).
- DoD 8140 / 8570 IAT Level II (mandatory).
- Secret clearance (required).
- Elastic Certified Engineer (preferred; attainment within 90 days acceptable).
Fort belvoir, United states
On site
Mid level
31-10-2025