Join our talent network

Job #: R-00019127-OTHLOC-PL-2D0945
Location: Fort Meade, MD
Category: Cyber Security
Schedule (FT/PT): Full Time
Travel Required: Yes, 10% of the time
Shift: Day
Potential for Telework: No
Clearance Required: Secret
Referral Eligibility: Eligible
Group: Defense

Share: mail twitter linkedin

This job posting is no longer active.


Job Requisition:

ELK SIEM Engineer

Job Description:

Leidos is seeking a Cyber Network Defense (CND) Elasticsearch, Log stash, and Kibana (ELK) Engineer/Subject Matter Expert (SME) to perform technical work as part of an integrated team of CND SMEs supporting the DoD’s JRSS (Joint Regional Security Stack) deployment activities. JRSS is a multi-year, global effort to improve the DoD’s security posture and provide enhanced security capabilities and analytics by centralizing and virtualizing network security into regional stacks rather than locally distributed appliances. This position is responsible for providing configuration, implementation, configuration and ongoing performance enhancement work for ELK in the JRSS environment.

You will also work as part of a multi-disciplinary team that supports the active and passive Computer Network Defense (CND) tools deployed in stacks. Must be able to integrate with other technical teams, with DISA personnel, with vendor technical support personnel, and with technical representatives from DoD services, working as part of an integrated, cross-platform team that provides CND capability, and military base/post/camp/station migration support services DoD-wide as the JRSS stacks are deployed and used.

Primary Responsibilities:

You will support ELK tool and will assist with configuration, troubleshooting, support and project management of ELK integration. You should also have extensive CND architectural design experience as well as significant hands-on experience with ELK.

To be successful in this role, you will be able to do the following:

  • Provide SME knowledge of Full Packet Capture via Google Stenographer, Protocol Analysis and Metadata via Bro, Signature Based Alerting via Suricata, Recursive File Scanning via FSF,  message queuing via Filebeat, Message Queuing and Distribution via Apache Kafka and Message Transport via Log stash
  • Create viewable Kibana dashboards to provide visibility into ingested log data
  • Resolve ELK infrastructure or system issues
  • Create Suricata security rules (alerts) and Kibana dashboards that trigger on anomalous activities or threat detections 
  • Create alerts that trigger/activate on configured setting to deploy or sends email to a particulate destination email or groups
  • Troubleshoot and tune signature based alerting via Suricata, recursive file scanning via FSF, message queuing and distribution via Apache Kafka and message transport via Log stash
  • Strong knowledge of Ansible or Python scripting, Linux CENTOS/ Red Hat operating system commands, file data storage, indexing, and searching via Elasticsearch
  • Provide ELK SME support, assisting customers when ingestion of logs are not working properly or with ELK communication issues
  • Experience with Splunk, IDS/IPS technologies, NESSUS, or Demisto

Basic Qualifications:

  • Bachelor’s degree from an accredited college in a related discipline, or equivalent experience/combined education, with 12 or more years’ experience; or 10 years’ experience with a related Master’s degree or equivalent work experience.
  • To be a successful fit to this assignment, you should be well versed in TCP/IP communications.
  • Have a general knowledge of router and firewall functionality on a network.
  • Familiar with the MS Office tool suite.
  • Excellent written and oral communications skills and be able to appropriately present highly technical material to both technical and non-technical audiences
  • Per contract requirements, U.S. citizenship and an active DoD Secret clearance is required. In addition, you must be able to successfully obtain up to Top Secret based on requirements from the customer and program.
  • DoD 8570 IAT2 certification is required

Preferred Qualifications:

  • Prior experience as a network intrusion analyst or Security Operations Center analyst.
  • Experience configuring and maintaining the tool in a multi-tenant environment
  • Experience with one or more of the CND tools:
    • Fidelis DLP and MDE
    • Tipping Point
    • Splunk
    • Firepower
    • Gigamon
    • Opswat
    • Inquest
    • Corelight/Bro
    • ELK tools


External Referral Eligible

External Referral Bonus:


Potential for Telework:


Clearance Level Required:



Yes, 10% of the time

Scheduled Weekly Hours:




Requisition Category:


Job Family:

Cyber Security




Leidos is a Fortune 500® information technology, engineering, and science solutions and services leader working to solve the world's toughest challenges in the defense, intelligence, homeland security, civil, and health markets. The company's 33,000 employees support vital missions for government and commercial customers. Headquartered in Reston, Virginia, Leidos reported annual revenues of approximately $10.19 billion for the fiscal year ended December 28, 2018. For more information, visit

Pay and Benefits

Pay and benefits are fundamental to any career decision. That's why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available here.

Securing Your Data

Leidos will never ask you to provide payment-related information at any part of the employment application process. And Leidos will communicate with you only through emails that are sent from a email address. If you receive an email purporting to be from Leidos that asks for payment-related information or any other personal information, please report the email to

Commitment to Diversity

All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.

This job posting is no longer active.

Talent Community

Join our Talent Community to create a profile, enabling a streamlined application process and to help our recruiters better understand your areas of expertise and interest.

Join our Talent Community