This position will be fully remote and can be hired anywhere in the continental U.S.
The primary focus for this role is to act as a Subject Matter Expert for the ELK Stack and be able to configure, manage, operate and administrate the platform for managed SIEM. The Principal Elastic Engineer as a member of the Advanced Fusion Center (AFC) team. This individual will be responsible for following Optiv AFC processes & procedures, as well as managing and maintaining security systems across internal and client environments. The Principal Elastic Engineer will work closely with Management, Solution Architects, Principal Security Engineers from other internal teams and clients to complete high profile, critical services to existing AFC clients. They will serve as a primary responder for AFC customer systems, taking ownership of client configuration issues, and tracking through resolution.
Applicants should have a comprehensive understanding of security technologies, including cloud technologies (e.g. Amazon Web Services, Google Cloud Platform, Azure), have extensive experience interacting with customers and have a solid understanding of information security and networking. Providing SIEM management solutions tailored to the needs of clients. Additionally, this position acts as an escalation point for critical and complex client issues, performs configuration and testing of products, assists with the development of work processes, and trains other team members.
How you’ll make an impact
- Maintain Elasticsearch clusters in a cloud-based environment across multiple availability zones.
- Ensure the Elasticsearch clusters continue to run under optimalconditions
- Evaluate existing Elasticsearch clusters, configuration parameters, indexing, search and query performance tuning, security and administration
- Maintain appropriate infrastructure to maintain performance and data integrity
- Keep Elasticsearch clusters upgraded (as permitted by the applications reliant on them)
- Spin up/customize clusters to meet various development and/or business needs
- Optimize indexes to meet business needs (e.g. logging, enterprise search)
- Troubleshoot various issues with the clusters (from small errors like unassigned shards, to automation issues, to node/cluster failures)
- Work closely with architecture, engineering and development and operations teams and jointly work on key deliverables ensuring production scalability and stability
- Ensure security of Elasticsearch cluster
- Follow and implement Elastic best practices
- Ensure appropriate monitoring & alerting of Elasticsearch
What we’re hiring for
- In-Depth knowledge of ELK Stack and Cloud operations, and a detailed understanding of computer and network security
- 6+ year experience with Elasticsearch Administration
- Direct experience maintaining and integrating Elasticsearch within an operational enterprise information system
- 6+ years of experience with deploying and using Elasticsearch in Commercial Cloud Platform (ex, AWS, Google Cloud, Azure)
- Proficiency with MS Office and Internet Navigation required.
- Excellent written and verbal communication skills required.
- Outstanding time management and organizational skills required.
- Previous experience in a professional services or SOC environment required.
- Experience related to security/infrastructure design, IAM, risk analysis and mitigation, disaster/contingency planning, certification/compliance testing, data loss prevention, Network Security Strategies, Technical Documentation, industry standards such as ITIL, COBIT, ISO standards, PCI, SOX, Rollout/Implementation and User Training/Support preferred.
- Ability to read, analyze and interpret common scientific and technical journals.
- Ability to respond to common inquiries or complaints from customers, regulatory agencies, or members of the business community.
- Ability to write speeches and articles for publication that conform to prescribed style and format.
- Ability to effectively present information to top management, public groups, and/or boards of directors.
- Ability to sit for extended periods of time.
- Ability to input data into computer utilizing hands to finger to tab to different fields to input data.
- Ability to answer telephone and talk and hear other party.