Seneca Resources

Sr. SIEM Engineer (Elastic + Confluent)

⭐ - Featured Role | Apply direct with Data Freelance Hub
This role is for a Sr. SIEM Engineer (Elastic + Confluent) in Fort Belvoir, VA, with a contract-to-hire status. Requires an active Secret Clearance, 5+ years of Elastic Stack experience, DoD 8140/8570 IAT Level II certification, and strong skills in data analytics and SOAR integration.
🌎 - Country
United States
πŸ’± - Currency
$ USD
-
πŸ’° - Day rate
Unknown
-
πŸ—“οΈ - Date
October 21, 2025
πŸ•’ - Duration
Unknown
-
🏝️ - Location
On-site
-
πŸ“„ - Contract
Unknown
-
πŸ”’ - Security
Yes
-
πŸ“ - Location detailed
Fort Belvoir, VA
-
🧠 - Skills detailed
#Elasticsearch #Consulting #AWS (Amazon Web Services) #Data Modeling #LDAP (Lightweight Directory Access Protocol) #Deployment #Indexing #Logstash #REST API #SAML (Security Assertion Markup Language) #API (Application Programming Interface) #ML (Machine Learning) #Cloud #Data Lifecycle #Visualization #Automation #GCP (Google Cloud Platform) #Scripting #Security #Linux #Monitoring #Bash #Python #REST (Representational State Transfer) #Programming #"ETL (Extract #Transform #Load)" #Azure #Cybersecurity #Data Pipeline #Elastic Stack #Ansible
Role description
Position Title: Sr. SIEM Engineer (Elastic + Confluent) Location: Fort Belvoir, VA (100% Onsite) Clearance Requirements: Active Secret Clearance Position Status: Contract to Hire Position Description: We are seeking an experienced Sr. SIEM Engineer with deep expertise in the Elastic Stack (ELK) and Confluent to support a large-scale SIEM consolidation and cyber defense initiative. This role will focus on integrating and optimizing multiple existing SIEM solutions into a unified enterprise platform to enhance visibility, automation, and cyber resilience across the organization. The ideal candidate brings a proven track record in Elastic Stack deployment, tuning, and scaling, along with hands-on experience in SOAR development, ETL pipelines, and data analytics for security operations. Key Responsibilities β€’ Design, deploy, configure, and maintain Elastic Stack and Confluent solutions in enterprise environments. β€’ Manage upgrades, patching, and optimization of Elasticsearch, Logstash, Kibana, and Beats components. β€’ Develop and configure ETL data pipelines for ingesting logs, metrics, and threat data from diverse sources. β€’ Create advanced Kibana dashboards and custom visualizations for real-time monitoring and reporting. β€’ Implement and maintain index templates, ILM policies, and Elastic alerting solutions using Watcher or Kibana Rules. β€’ Integrate alerting with ticketing systems, messaging platforms, and SOAR tools. β€’ Develop Machine Learning jobs within Elastic to identify anomalies and support proactive threat detection. β€’ Apply ITIL-based change management processes for solution lifecycle management (Dev β†’ Test β†’ Prod). β€’ Support day-to-day Security Operations Center (SOC) activities, including incident investigation and response. Required Skills & Qualifications β€’ Active Secret Clearance (required to maintain this position). β€’ DoD 8140 / 8570 IAT Level II certification (must be obtained prior to start). β€’ 5+ years of hands-on experience designing, deploying, and managing the Elastic Stack for SIEM or security analytics use cases. β€’ Strong understanding of Elasticsearch architecture, indexing, query performance tuning, and cluster administration. β€’ Experience with data lifecycle management, snapshots/restoration, and security hardening. β€’ Demonstrated experience integrating Elastic Stack with SOAR platforms, Threat Intel feeds, and external authentication (SAML, LDAP, PKI). β€’ Skilled in Red Hat Enterprise Linux (RHEL) administration and deployment. β€’ Experience developing Logstash or Elastic ingest pipelines and custom Kibana dashboards. β€’ Proficiency with REST API integration and Elastic Common Schema (ECS) data modeling. Desired Skills β€’ Experience with Ansible automation for deployment and configuration management. β€’ Scripting or programming experience in Python, Bash, PowerShell, or Painless. β€’ Familiarity with the MITRE ATT&CK framework. β€’ Elastic Certified Engineer or willingness to obtain certification within 90 days of hire. β€’ Experience in cloud security architecture (AWS, Azure, or GCP). β€’ Proven ability to consolidate complex SIEM environments into a single pane of glass. β€’ Experience leading incident response or forensic investigations. β€’ Familiarity with Army or DoD cybersecurity policies and processes. About Seneca Resources At Seneca Resources, we are more than just a staffing and consulting firm β€” we’re a trusted career partner. With offices across the U.S. and clients ranging from Fortune 500 companies to federal agencies, we connect talented professionals with meaningful, impactful work. When you join Seneca, you’ll experience: β€’ A supportive team that invests in your success. β€’ Competitive pay and benefits including health, dental, and vision insurance, 401(k), and more. β€’ Career opportunities that align with your professional goals. We celebrate diversity and are committed to fostering an inclusive environment where all qualified individuals are encouraged to apply.