Accenture federal services

Sr. SIEM Engineer (Elastic + Confluent)

Fort Belvoir, VA Full Time
 
At Accenture Federal Services, nothing matters more than helping the US federal government make the nation stronger and safer and life better for people. Our 13,000+ people are united in a shared purpose to pursue the limitless potential of technology and ingenuity for clients across defense, national security, public safety, civilian, and military health organizations.
 
Join Accenture Federal Services, a technology company and part of global Accenture, to do work that matters in a collaborative and caring community, where you feel like you belong and are empowered to grow, learn and thrive through hands-on experience, certifications, industry training and more.
 
Join us to drive positive, lasting change that moves missions and the government forward!
 

We are:

Accenture Federal Services, bringing together commercial innovation with the latest technology to unleash the potential for our federal clients. Every day we bring bold thinking and diverse disciplines to solve problems in new ways. Ready to learn as much as you can We’ll give you numerous opportunities from informal training sessions to courses and certifications to keep your tech smarts sharp.

You are:

AFS is seeking a Sr. SIEM Engineer specializing in Elastic Stack and Confluent in support of the PEO Enterprise SIEM Consolidation / Cyber Defense effort. This effort is focused on the consolidation of PEO Enterprise multiple SIEM solutions (approx. 40) into one consolidated SIEM. This individual should have extensive experience with Security Information and Event Management (SIEM) deployment and tuning as well as Security Orchestration Automation and Response (SOAR) development and implementation.

Responsibilities:

  • Design, deploy, configure, and maintain Elastic stack and Confluent deployments
  • Manage, patch, and upgrade Elasticsearch, Confluent, and other related systems
  • Tune and optimize Elastic stack deployments based on application/customer needs
  • Design and configure ETL data pipelines to ingest customer defined data sets such as application logs, metrics, and or threat events
  • Create custom visualizations and dashboards using Kibana
  • Configure and maintain index templates and information lifecycle management (ILM) policies
  • Develop Elastic alerting solutions using Watcher and/or Kibana Rules and Connectors with integrations to ticketing systems, email, and messaging apps as required
  • Develop Machine Learning (ML) jobs to dynamically monitor and alert on identified metrics, KPIs, and/or data anomalies
  • Follow ITIL based change management processes to move solutions from Dev to Test and into Production
  • Run the day-to-day operations of the security operations center
  • Investigate incidents and lead response efforts as applicable

Required Skills:

  • Secret clearance is required to maintain this position
  • Compliance with DoD 8140 / 8570 IAT Level II certification prior to start date
  • 3+ years of hands-on experience in deployment, configuration, and solution development using the Elastic Stack for security and logging use-cases
  • Demonstrated experience with the full Elastic Stack: Elasticsearch, Logstash, Kibana, Beats, Machine Learning, and REST API integration
  • Experience in developing data structures and data mapping from various sources to achieve data normalization using Elastic Common Schema
  • Experience developing Logstash and/or Elastic Ingest Pipelines
  • Experience developing custom visualizations and dashboards using Kibana, including creating specialized reporting solutions through Elasticsearch and Kibana APIs to meet complex stakeholder requirements
  • Certified Elastic Engineer or willingness to gain certification within 90 days of hire

Desired Skills:

  • Experience using and developing Ansible playbooks for automation of system deployment and/or configuration
  • Experience with developing in multiple languages (Python, Bash, PowerShell, Painless, etc.)
  • Understanding of the MITRE ATT&CK framework
  • Experience with cloud environments (e.g., Azure, AWS, GCP, etc.) and cloud security architecture
  • Experience integrating Elasticsearch with external systems (e.g., SOAR tools, Threat Intel Platforms) and alternate authentication mechanisms such as SAML, LDAP, and PKI
  • Experience with data management: hot/warm/cold architectures, shared allocation/re-allocation, snapshots & restoration
  • Strong experience with evaluating existing Elastic clusters, configuration parameters, indexing, search and query performance tuning, security, and cluster administration
  • Experience supporting the Elastic Stack in on-prem and SaaS environments, including system monitoring and tuning, securing the Elastic Stack, and hardening hosting environments
  • Experience with the design and implementation of highly scalable solutions using the Elastic Stack
  • Experience in end-to-end low-level design, development, administration, and delivery of Elasticsearch-based reporting solutions
  • Strong technical foundation in building reliable, scalable, and supportable systems
  • Experience in Red Hat Enterprise Linux deployment and administration

 

Eligibility Requirements:

US Citizen

 

As required by local law, Accenture Federal Services provides reasonable ranges of compensation for hired roles based on labor costs in the states of California, Colorado, Hawaii, Illinois, Maryland, Massachusetts, Minnesota, New Jersey, New York, Washington, Vermont, the District of Columbia, and the city of Cleveland. The base pay range for this position in these locations is shown below. Compensation for roles at Accenture Federal Services varies depending on a wide array of factors, including but not limited to office location, role, skill set, and level of experience. Accenture Federal Services offers a wide variety of benefits. You can find more information on benefits here. We accept applications on an on-going basis and there is no fixed deadline to apply.

 

The pay range for the states of California, Colorado, Hawaii, Illinois, Maryland, Massachusetts, Minnesota, New Jersey, New York, Washington, Vermont, the District of Columbia, and the city of Cleveland is:
$160,700$306,500 USD
 
What We Believe
As a company wholly dedicated to serving the US federal government, we bring together the best talent to help reinvent how federal agencies operate and deliver greater value for their mission and the American people. We have an unwavering commitment to creating a culture in which all our people are respected, feel a sense of belonging, and have equal opportunity. As a business imperative, every person at Accenture Federal Services has the responsibility to create and sustain a culture where everyone feels welcomed and included. This is grounded in our core values and our experience that hiring and developing great people who reflect different perspectives, experiences, and backgrounds is key to driving innovation and delivering the results that our clients and the country count on.
 
Equal Employment Opportunity Statement
We believe that no one should be discriminated against because of their differences. All employment decisions shall be made without regard to age, race, creed, color, religion, sex, national origin, ancestry, disability status, veteran status, sexual orientation, gender identity or expression, genetic information, marital status, citizenship status or any other basis as protected by federal, state, or local law. Our rich diversity makes us more innovative, more competitive, and more creative, which helps us better serve our clients and our communities. For details, view a copy of the Accenture Federal Services Equal Opportunity Policy Statement.
 
Accenture Federal Services is an Equal Employment Opportunity employer. Additionally, as an Affirmative Action Employer for Veterans and Individuals with Disabilities, Accenture Federal Services is committed to providing veteran employment opportunities to our service men and women.
 
Requesting An Accommodation 
Accenture Federal Services is committed to providing equal employment opportunities for persons with disabilities or religious observances, including reasonable accommodation when needed. If you are hired by Accenture Federal Services and require accommodation to perform the essential functions of your role, you will be asked to participate in our reasonable accommodation process. Accommodations made to facilitate the recruiting process are not a guarantee of future or continued accommodations once hired.
 
If youare being considered for employment opportunities with Accenture Federal Services and need an accommodation for a disability or religious observance during the interview process or for the job you are interviewing for, please speak with your recruiter.
 
Other Employment Statements 
Applicants for employment in the US must have work authorization that does not now or in the future require sponsorship of a visa for employment authorization in the United States.
 
Candidates who are currently employed by a client of Accenture Federal Services or an affiliated Accenture business may not be eligible for consideration.
 
Job candidates will not be obligated to disclose sealed or expunged records of conviction or arrest as part of the hiring process.
 
The Company will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. Additionally, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with the Company's legal duty to furnish information.
 
California requires additional notifications for applicants and employees. If you are a California resident, live in or plan to work from Los Angeles County upon being hired for this position, please click here for additional important information.