Maximus logo

Cybersecurity Engineer – Elastic SIEM (Journeyman)

Maximus

San Antonio, TXJob$120–140K/yrSeen 4 days agoSeen in employer's feed 4 days ago

Most applications go out cold — see where you stand first. No sign-up to start.

Watch jobs like this.

At a glance

Compensation
$120–140K/yr
Location
San Antonio, TX
Work Authorization
Not specified

Olive lists jobs from US employers, including remote roles you can work from the United States.

Requirements

Credentials this posting asks for.

TS/SCI clearance

Job overview

Maximus is seeking a Cybersecurity Engineer – Elastic SIEM (Journeyman) for an onsite role in San Antonio, Texas. The position requires an active Top Secret/SCI clearance, a bachelor’s degree in a related field, and five or more years of hands‑on cybersecurity engineering experience, focusing on Elastic SIEM platform operations and threat detection.

Skills & qualifications

RequiredNice to have

Skills

Elastic SIEMElasticsearchKibanaLogstashBeats/Elastic AgentNIPRNetSIPRNetJWICSPythonBashKQL/EQLMITRE ATT&CKAWS GovCloudKubernetes/EKSPalo Alto Cortex XSOARAgile/SAFe

Qualifications

Bachelor's Degree in Cybersecurity or Related FieldActive Top Secret / SCI Security Clearance5+ Years Cybersecurity Engineering ExperienceDoD 8140 Requirements Met

Full job description

Maximus is currently seeking a Cybersecurity Engineer - Elastic SIEM (Journeyman).

This role is onsite, 5 days a week, in San Antonio, TX and requires an active Top Secret / SCI (TS/SCI) security clearance.

Maximus TCS (Technology and Consulting Services) Internal Job Profile Code: TCS057, T3, Band 6

Job-Specific Essential Duties and Responsibilities:

  • Independently perform standard SIEM engineering tasks with limited supervision; escalate complex issues to senior engineers.

  • Administer, operate, and sustain the Elastic SIEM platform (Elasticsearch, Kibana, Logstash, Beats/Elastic Agent) across NIPRNet, SIPRNet, and JWICS environments.

  • Monitor SIEM health, perform capacity planning, and resolve platform outages and degradations in accordance with defined SLAs.

  • Develop, tune, and maintain detection rules, alerts, dashboards, and visualizations in Elastic to support DCO mission requirements.

  • Ingest, normalize, and validate log data from diverse sources including endpoint, network, cloud, and application telemetry..

  • Collaborate with cyber operators and analysts to support threat detection, alert triage, and cyber incident investigation workflows.

  • Identify opportunities to improve SIEM coverage, data quality, and detection fidelity; implement improvements in coordination with the Government PMO.

  • Support Cyber Security Service Provider (CSSP) activities including continuous monitoring and security event analysis.

  • Create and maintain technical documentation including runbooks, standard operating procedures (SOPs), and knowledge base articles.

  • Participate in Agile/SAFe Program Increment (PI) planning and sprint execution in support of platform delivery.

  • Adhere to Air Force cybersecurity standards and all applicable DoD, IC, and USAF policy and directives across all enclaves.

Job-Specific Minimum Requirements:

  • Active Top Secret / SCI (TS/SCI) security clearance.- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field (or equivalent experience).

  • 5+ years of hands-on cybersecurity engineering experience.

  • Intermediate proficiency level: ability to independently administer and troubleshoot standard Elastic SIEM operations and escalate complex issues.

  • Demonstrated hands-on experience with Elastic Stack (Elasticsearch, Kibana, Logstash, Beats/Elastic Agent) in an operational SIEM environment.

  • Experience supporting threat detection, alert triage, and/or cyber incident investigation.

  • Familiarity with DCO concepts, CSSP operations, and defensive cyber frameworks.

  • Experience working across multiple network security domains (NIPR, SIPR, or JWICS).

  • Meet applicable DoD 8140 requirements for the assigned work role. DCWF 521, Cyber Defense Infrastructure Support Specialist, Intermediate Proficiency; specific required certifications pending contract confirmation.

Preferred Skills and Qualifications:

  • Experience with SIEM/SOAR integrations (e.g., Elastic, Palo Alto Cortex XSOAR, or similar).- Familiarity with Elastic's Fleet/Agent management and integration development.

  • Experience with AWS GovCloud environments (IL4/IL5/IL6).

  • Knowledge of MITRE ATT&CK framework and its application to detection engineering.

  • Experience with scripting/automation (Python, Bash, KQL/EQL) for SIEM rule development and data pipeline management.

  • Familiarity with container-based deployments (Kubernetes/EKS) in classified environments.

  • Prior experience supporting USAF or DoD DCO programs.

  • One or more of the following certifications preferred: Elastic Certified Engineer, CompTIA CySA+, GCIA, or GCIH.

#techjobs #clearance #veteransPage

Minimum Requirements

TCS057, T3, Band 6

Maximus is an equal opportunity employer. We evaluate qualified applicants without regard to race, color, religion, sex, age, national origin, disability, veteran status, genetic information and other legally protected characteristics.

Minimum Salary

$120,000

Maximum Salary

$140,000

Similar jobs, posted recently

Open roles like this one, listed in the last 30 days.

You've read the whole posting — now see how you match it.