All jobs

[Remote] SIEM Platform Engineer

100% Remote Full-time Open now

Note: The job is a remote job and is open to candidates in USA. Booz Allen Hamilton is seeking a SIEM Platform Engineer to build high-performing systems using Elastic for log aggregation and analysis. The role involves creating visualizations and alerts for threat hunting, maintaining infrastructure, and ensuring compliance with security requirements.

Responsibilities

  • Work with clients and peers to build a high-performing system using Elastic to aggregate logs from many systems into a single common schema
  • Use Elastic Common Schema (ECS) formatted fields, create quality visualizations and alerts that analysts can use for threat hunting, maintain infrastructure, and identify problems or anomalous behavior before they become a larger issue and can be actioned on
  • Work with the vendor to determine best practices for deployment and maintenance of system architecture and deploy within designated security requirements

Skills

  • 1+ years of experience with SIEM platforms such as Splunk Enterprise Security, Elastic Security, Kibana, Sentinel, or Chronicle
  • Experience designing data pipeline architectures for security operations, including log collection, normalization, enrichment, and routing
  • Experience with Elastic Stack, Logstash, Elasticsearch, Kibana, and Beats, including installing, configuring, maintaining, upgrading, and troubleshooting these products
  • Knowledge of architecting detection engineering pipelines, threat hunting workflows, or automated response capabilities
  • Knowledge of EDR, NDR, or full-packet capture solutions such as CrowdStrike, Corelight, or Trellix
  • Knowledge of deploying platforms across cloud, on-premises, and disconnected environments using Kubernetes or OpenShift
  • Knowledge of working in classified or compartmented environments with strict access enforcement
  • Knowledge of Elastic Index Lifecycle Management (ILM)
  • TS/SCI clearance
  • HS diploma or GED
  • Experience with stream processing or data brokering platforms such as Cribl, Kafka, Logstash, or Fluentd
  • Experience working with Docker, Kubernetes, and cloud containerization solutions such as Elastic Cloud on Kubernetes (ECK)
  • Experience with DevSecOps CI/CD pipelines in IL5, IL6, IL7 environments
  • Experience with Python or scripting languages for security automation
  • Security+, CISSP, CISSP-ISSEP, or CASP+ Certifications

Benefits

  • Health, life, disability, financial, and retirement benefits
  • Paid leave
  • Professional development
  • Tuition assistance
  • Work-life programs
  • Dependent care
  • Recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values

Company Overview

  • Booz Allen Hamilton is a consulting firm that specializes in analytics, technology, and engineering. It was founded in 1914, and is headquartered in Mclean, Virginia, USA, with a workforce of 10001+ employees. Its website is http://www.boozallen.com.
  • Apply To This Job

    You might also like

    Enterprise Solutions Associate I

    100% Remote Full-time

    Audit Associate - Sacramento, CA - Class of 2026

    100% Remote Full-time

    Human Health and Ecological Risk Assessor

    100% Remote Full-time

    Entry Level Traffic Engineer

    100% Remote Full-time

    [Remote] Early Career Trial Attorney (Remote - Los Angeles, CA)

    100% Remote Full-time

    Financial Consultant

    100% Remote Full-time

    [Remote] Sales Support and Data Coordinator

    100% Remote Full-time

    [Remote] Program Finance Analyst- Early Career

    100% Remote Full-time

    [Remote] Call Center - Member Contact Center Rep 1 - Full Time - Remote (AK,AZ NV,TX,WA,WY)

    100% Remote Full-time

    Biologist New Graduate (Ontario) (2026)

    100% Remote Full-time

    Experienced Overnight IT Service Technician - Hybrid Remote Support Specialist (Entry Level)

    100% Remote Full-time

    Experienced Remote Customer Service Representative – Thrive in a Dynamic Arenaflex Team

    100% Remote Full-time

    Experienced Full Stack Data Entry Specialist – Revenue Technology and Data Analytics

    100% Remote Full-time

    Job Title: American Airlines Verification Specialist - Remote Opportunity ($30/Hour)

    100% Remote Full-time

    Apply Now: Box Truck Freedom Program: $25K?? While We Do All The

    100% Remote Full-time

    BCBA – Maryland | Up to $90/hr | Flexible Caseloads | Join a Growing ABA Team

    100% Remote Full-time

    Experienced Customer Service Representative - Delivering Exceptional Service from Home at blithequark

    100% Remote Full-time

    Experienced Customer Service Representative – Remote Support for arenaflex's Sustainable Energy Revolution

    100% Remote Full-time

    Data Entry Clerk- Part Time - Remote

    100% Remote Full-time

    Manager Group Accounting & Reporting (m/w/d)

    100% Remote Full-time