
Cybersecurity Engineer – Elastic SIEM SME
San Antonio, TXJob$190–220K/yrSeen 3 days agoSeen in employer's feed 3 days ago
Most applications go out cold — see where you stand first. No sign-up to start.
Watch jobs like this. New roles like this one near San Antonio, TX, by email.
Don't just apply. Show up ready.
Olive works from this exact posting.
At a glance
Olive lists jobs from US employers, including remote roles you can work from the United States.
Requirements
Credentials this posting asks for.
Job overview
Maximus is seeking a Cybersecurity Engineer – Elastic SIEM SME for an on‑site role in San Antonio, Texas. The position requires an active TS/SCI clearance, a bachelor’s degree in a related field, and ten or more years of hands‑on cybersecurity engineering experience, focusing on Elastic SIEM architecture, operation, and advanced threat detection.
Skills & qualifications
Skills
Qualifications
Full job description
Maximus is seeking a Cybersecurity Engineer - Elastic SIEM SME.
This role is on-site in San Antonio, TX and requires an active TS/SCI security clearance.
Maximus TCS (Technology and Consulting Services) Internal Job Profile Code: TCS059, T5, Band 8
Job-Specific Essential Duties and Responsibilities:
-
Serve as the Elastic SIEM subject matter expert, exercising independent technical judgment and advising the team and customer.
-
Provide expert technical direction for the architecture, operation, and sustainment of the Elastic SIEM platform (Elasticsearch, Kibana, Logstash, Beats/Elastic Agent) across NIPRNet, SIPRNet, and JWICS environments.
-
Monitor SIEM health, perform capacity planning, and lead resolution of the most complex platform outages and degradations in accordance with defined SLAs.
-
Guide the design and review of detection rules, alerts, dashboards, and visualizations in Elastic to support DCO mission requirements.
-
Ingest, normalize, and validate log data from diverse sources including endpoint, network, cloud, and application telemetry.
-
Collaborate with cyber operators and analysts to support threat detection, alert triage, and cyber incident investigation workflows.
-
Identify opportunities to improve SIEM coverage, data quality, and detection fidelity; lead implementation of improvements in coordination with the Government PMO.
-
Support Cyber Security Service Provider (CSSP) activities including continuous monitoring and security event analysis.
-
Create and maintain technical documentation including runbooks, standard operating procedures (SOPs), and knowledge base articles.
-
Advise the customer and mentor senior and journeyman engineers; establish technical standards and review complex SIEM designs.
-
Participate in Agile/SAFe Program Increment (PI) planning and sprint execution in support of platform delivery.
-
Adhere to Air Force cybersecurity standards and all applicable DoD, IC, and USAF policy and directives across all enclaves.
Job-Specific Minimum Requirements:
-
Active Top Secret / SCI (TS/SCI) security clearance.
-
Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field.
-
10+ years of hands-on cybersecurity engineering experience.
-
Advanced proficiency level: demonstrated expertise in Elastic SIEM architecture, technical standards, complex troubleshooting, and advising technical teams and customers.
-
Demonstrated hands-on experience with Elastic Stack (Elasticsearch, Kibana, Logstash, Beats/Elastic Agent) in an operational SIEM environment.
-
Experience supporting threat detection, alert triage, and/or cyber incident investigation.
-
Familiarity with DCO concepts, CSSP operations, and defensive cyber frameworks.
-
Experience working across multiple network security domains (NIPR, SIPR, or JWICS).
-
Meet applicable DoD 8140 requirements for the assigned work role. DCWF 521, Cyber Defense Infrastructure Support Specialist, Advanced Proficiency.
Preferred Skills and Qualifications:
-
Experience with SIEM/SOAR integrations (e.g., Elastic, Palo Alto Cortex XSOAR, or similar).
-
Familiarity with Elastic's Fleet/Agent management and integration development.
-
Experience with AWS GovCloud environments (IL4/IL5/IL6).
-
Knowledge of MITRE ATT&CK framework and its application to detection engineering.
-
Experience with scripting/automation (Python, Bash, KQL/EQL) for SIEM rule development and data pipeline management.
-
Familiarity with container-based deployments (Kubernetes/EKS) in classified environments.
-
Prior experience supporting USAF or DoD DCO programs.
-
One or more of the following certifications preferred: Elastic Certified Engineer, CompTIA CySA+, GCIA, or GCIH.
#techjobs #clearance #veteransPage
Minimum Requirements
TCS059, T5, Band 8
Maximus is an equal opportunity employer. We evaluate qualified applicants without regard to race, color, religion, sex, age, national origin, disability, veteran status, genetic information and other legally protected characteristics.
Minimum Salary
$190,000
Maximum Salary
$220,000
Similar jobs, posted recently
Open roles like this one, listed in the last 30 days.
Software Engineer - Mid to Experienced Level (MD/TX)National Security Agency/Central Security Service · Fort Meade, MD · $105–193K/yrPosted 1w agoPosted 1w ago
Software Engineer - Entry Level (MD TX CO)National Security Agency/Central Security Service · Denver, CO · $87–123K/yrPosted 1 day agoPosted 1 day ago
Engineer (Palace Acquire Intern)Air Force Civilian Career Training · Maxwell AFB, AL · $50–110K/yrPosted 2 days agoPosted 2 days ago
IT CYBERSECURITY SPECIALIST (CUSTSPT/INFOSEC)Defense Information Systems Agency · Montgomery, AL · $90–133K/yrPosted 2 days agoPosted 2 days ago
SUPV IT CYBERSECURITY SPECIALIST (PLCYPLN/INFOSEC)Defense Information Systems Agency · Montgomery, AL · $148–197K/yrPosted 1w agoPosted 1w ago
You've read the whole posting — now see how you match it.