Sr. Elastic Engineer

vor 2 Monaten


Wiesbaden, Deutschland ECS Vollzeit

ECS is seeking a Sr. Elastic Engineer to work in our Clay Kaserne (RCC-E), Germany location + some travel.

Job Description:

As a leading provider of managed cybersecurity services, ECS provides a highly tailored and customized offering to each customer. Our team is responsible for protecting both our customers and corporate environment at ECS. Our mission is very broad, and our team is agile.We will look toward your unique skills to approach and solve problems in your own way.Whether engineering a system to address a technical hurdle, protecting customers data or consulting on a wide range of security topics.You are empowered to engage and lead across multiple groups.

This role of Senior Elastic Engineer will support ECS's Army Endpoint Security Solution (AESS) program. This is a technical hands-on role to which you will be responsible for working within a multi-disciplined team to design, build, secure, maintain, optimize, and document multiple Elastic deployed globally in a Federal DoD environment. These deployments leverage the full Elastic Stack of capabilities such as Elasticsearch, Logstash, Kibana, Beats, Machine Learning, SIEM, and Fleet. Along with third-party technologies like Confluent Kafka. You will provide continuous data normalization support functions and support the delivery of written technical deliverables such as SOPs and/or process workflows to optimize tool usage and contribute to new capabilities.

Responsibilities:

Design, deploy, configure, and maintain Elastic stack and Confluent Kafka deployments. Manage, patch, and upgrade Elasticsearch, Confluent and other related systems. Tune and optimize Elastic stack deployments based on application/customer needs. Design and configure ETL data pipelines to ingest customer defined data sets such as application logs, metrics, and or threat events. Create custom visualizations and dashboards using Kibana. Configure and maintain index templates and information lifecycle management (ILM) policies. Develop Elastic alerting solutions using Watcher and/or Kibana Rules and Connectors with integrations to ticketing systems, email, and messaging apps as required. Develop Machine Learning (ML) jobs to dynamically monitor and alert on identified metrics, KPIs, and/or data anomalies. Follow ITIL based change management processes to move solutions from Dev to Test and into Production

Required Skills:

BS/BA with 4+ years or 7+ years experience without degree. Minimum Top-Secret clearance is required, can start with Secret. Compliance with DoD 8140 / 8570 IAT Level II certification prior to start date. Certified Elastic Engineer or willingness to gain certification within 90 days of hire. At least 4 years’ hands-on experience in deployment, configuration, and solution development using the Elastic Stack for security and logging use-cases. Specific experience with Elastic SIEM is plus. Demonstrated experience with the full Elastic Stack - Elasticsearch, Logstash, Kibana, Beats, Machine Learning, and REST API integration.

Desired Skills:

Experience integrating Elasticsearch with external systems (e.g. SOAR tools, Threat Intel Platforms) Experience with data management: hot/warm/cold architectures, shard allocation/re-allocation, snapshots & restoration Strong experience with evaluating existing Elastic clusters, configuration parameters, indexing, search and query performance tuning, security, and cluster administration. Experience integrating Elasticsearch with alternate authentication mechanisms such as SAML, LDAP, and PKI. Experience with supporting the Elastic Stack in on-prem and SaaS environments including system monitoring and tuning. Experience securing the Elastic stack and hardening hosting environments. Experience with developing in multiple languages (Python, Bash, PowerShell, Painless, etc.). Experience with the design and implement of highly scalable solutions using the Elastic Stack. Experience in developing data structures, data mapping from various sources to achieve data normalization using Elastic Common Schema. Experience developing Logstash and/or Elastic Ingest Pipelines. Experience developing custom visualizations and dashboards using Kibana. Developing custom reporting solutions using APIs that leverage Elasticsearch and Kibana Experience in end-to-end Low-level design, development, administration, and delivery of Elasticsearch based reporting solutions. Strong technical foundation in building reliable, scalable, and supportable systems. Experienced in Red Hat Enterprise Linux deployment and administration. Experience using and developing Ansible playbooks for automation of system deployment and/or configuration.



  • Wiesbaden, Deutschland SOSi Vollzeit

    Overview SOS International LLC (SOSi) is seeking a highly qualified Elastic SIEM Administrator to support our customer in Weisbaden Germany. **Responsibilities**: - Responsible for administering the ElasticStack cluster, which includes pipeline services, to maintain and develop its future capabilities. - Responsible for developing and maintaining...

  • Cloud Engineer

    vor 2 Monaten


    Wiesbaden, Deutschland R+V Vollzeit

    Aufgaben Zusammen im Team konzentrieren Sie sich auf die Bereitstellung von Elastic Stacks in der Public Cloud (Azure) Als Elastic Engineer wirken Sie dabei aktiv und beratend im Themenfeld rund um den Elastic Stack (Search, Observability, Security, Analytics) mit Sie entwickeln im Team Lösungskonzepte, um vollautomatisch Elastic Stacks mittels...

  • Cloud Engineer

    vor 3 Wochen


    Wiesbaden, Deutschland R+V Vollzeit

    Aufgaben Zusammen im Team konzentrieren Sie sich auf die Bereitstellung von Elastic Stacks in der Public Cloud (Azure) Als Elastic Engineer wirken Sie dabei aktiv und beratend im Themenfeld rund um den Elastic Stack (Search, Observability, Security, Analytics) mit Sie entwickeln im Team Lösungskonzepte, um vollautomatisch Elastic Stacks mittels...

  • Cloud Engineer

    Vor 5 Tagen


    Wiesbaden, Hessen, Deutschland R+V Vollzeit

    Job Title: Elastic Engineer at R+V Allgemeine Versicherung AG Job Description: Concentrate on providing Elastic Stacks in the Public Cloud (Azure) as a team Actively consult on Elastic Stack topics (Search, Observability, Security, Analytics) as an Elastic Engineer Develop solution concepts in the team to automatically provide Elastic Stacks via CI/CD...

  • Siem Administrator

    vor 4 Wochen


    Wiesbaden, Deutschland SOSi Vollzeit

    **Overview**: - SOS International LLC (SOSi) is seeking a highly qualified **SIEM Administrator** to support our customer in Weisbaden Germany.**Responsibilities**: - Responsible for administering the ElasticStack cluster, which includes pipeline services, to maintain and develop its future capabilities. - Responsible for developing and maintaining...

  • Siem Administrator

    Vor 5 Tagen


    Wiesbaden, Deutschland Peraton Vollzeit

    **Responsibilities**: Peraton is seeking a talented and experienced **SIEM Administrator** to join our team in support of the **U.S. Army Europe Regional Cyber Center (RCC-E).** **Location: on-site in Wiesbaden, Germany.** **As an SIEM Administrator, you will be**: - Responsible for administering the ElasticStack cluster, which includes pipeline...


  • Wiesbaden, Deutschland R+V Vollzeit

    Aufgaben Gestaltung architektureller Zielbilder und Rahmenbedingungen für die Software-Entwicklung und den Betrieb im Agile Release Train (ART Operations) Verantwortung für den Einsatz moderner Architektur-Prinzipien und Methoden z.B. Micro Services, Domain Driven Design und APIfizierung Arbeit im dreiköpfigen Architekten-Team unter...